Buyer's guide

What is a CRA compliance and reporting solution?

A CRA compliance platform handles the full obligation surface that Regulation (EU) 2024/2847 places on every manufacturer of products with digital elements, from classification and risk assessment through documentation to vulnerability handling and authority reporting. As a CRA compliance reporting solution it also has to produce the reports the regulation asks for, and file them on Article 14's clock. This is a buyer's guide to both halves: what to look for, what to avoid, and how to know whether you actually need one.

The CRA in one paragraph

The EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) entered into force on 10 December 2024. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT within 24 hours, follow up with a detailed report within 72 hours, and submit a final report within 14 days or one month depending on the trigger. They must also operate a coordinated vulnerability disclosure process and publish a CVD policy under Article 13. From 11 December 2027 the full conformity regime applies: a documented risk assessment, the Annex I essential requirements, technical documentation, the EU Declaration of Conformity, and CE marking. Most products qualify for self-assessment under Module A.

What a platform replaces

A CRA compliance platform replaces six manual artifacts: the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file. Each carries a low cost individually and a high coordination cost when a real incident lands or an authority requests documentation. CVD Portal generates the artifacts across 88 CRA clause artifacts and 33 security objectives from a single recorded state, so outputs like the EU Declaration of Conformity never drift from the documented position instead of being retyped.

CRA obligationWithout a platformWith a CRA compliance platform
Article 13 CVD policyHand-built policy page and shared inboxBranded portal, hosted policy, structured intake with PGP
Article 14 reportingManual deadline tracking in a spreadsheetHard timers on 24h / 72h / final report, SRP-ready package
Article 13 risk assessmentAd-hoc document per productSTRIDE assessment mapped onto Annex I requirements
Technical documentationFolder tree standing in for the fileAnnex VII index and Annex V DoC generated from state
AdvisoriesBespoke advisory documentsCSAF 2.0 machine-readable advisory on remediation

The compliance reports it has to produce

"Compliance report" is not one document under the CRA. It is six outputs on different clocks, and the reason a CRA compliance reporting solution is worth anything is that it derives all of them from one record instead of six spreadsheets that disagree. A good CRA compliance report solution keeps those six outputs in sync so an audit never catches a contradiction.

ReportProduced whenWhat it is
Article 14 submission packageActively exploited vulnerability or severe incidentThe early warning, the 72-hour notification, and the final report, each assembled from the case record and staged against its own deadline. ENISA exposes no submission API, so filing stays a manual step. The package is what makes that step short.
CSAF 2.0 advisoryRemediation shipsA machine-readable security advisory in the format downstream consumers and vulnerability databases can ingest without a human retyping it. Generated from the same record that drove the case.
Annex VII technical documentationPer product, per releaseThe technical file index, versioned per release, with point-in-time snapshots preserved for the ten-year retention obligation.
Annex V EU Declaration of ConformityPer product, per releaseDrafted field by field from the recorded classification, risk assessment and Annex I state rather than retyped, so it cannot drift from the position the technical file documents.
Annex II information to usersPer productThe published user information sheet, including the vulnerability reporting contact and the support period end date, generated from the same record as the technical file.
Audit trail exportOn demandEvery intake, acknowledgment, status change and submission, timestamped and hash-chained, exportable when a market surveillance authority asks how a case was handled.

The first two are the reporting half and are what most buyers mean by a CRA compliance reporting solution. The rest are the conformity half. For the full duty behind the first row, see the CRA reporting obligations in detail.

Every claim in this table, traced to the Regulation

The CRA FAQ answers each of these in depth, with every obligation pinpointed to an article or annex and each source marked as binding law or as interpretive guidance.

Eight criteria for a real CRA compliance platform

Use these to assess any platform you are evaluating, including CVD Portal.

1

Product classification and conformity route

The platform should determine where each product sits under Annex III and IV (default, important, or critical) and derive the Article 32 conformity assessment route from that classification. The classification decision and its justification belong in the evidence record, because every downstream artifact depends on it.

2

Cybersecurity risk assessment

Article 13 requires a documented risk assessment per product, kept up to date and included in the technical documentation. A real platform supports structured threat modelling with likelihood and impact scoring, and maps the results onto the Annex I requirements they make applicable.

3

Annex I requirement tracking and gap analysis

The essential requirements of Annex I are the substance of conformity. The platform should track each requirement's status per product, show which are open, and connect each gap to remediation guidance and accumulated evidence.

4

Technical documentation and Declaration of Conformity

The Annex VII technical file and the Annex V EU Declaration of Conformity are generated outputs of the assessment work. A platform should draft both from the recorded state, keep them versioned per release, and preserve point-in-time snapshots for the ten-year retention obligation.

5

Annex II user information

The information and instructions to users, including the vulnerability reporting contact and the support period end date, should be generated from the same record that produced the technical file, so the published sheet never drifts from the documented position.

6

Article 13 publication and single point of contact

A published CVD policy under your own brand, plus a contact channel that researchers can actually use. The platform should provide a whitelabel email, a hosted policy page, a structured submission form, PGP support, and safe-harbor language.

7

Article 14 reporting cascade

Three-stage reporting to ENISA and the relevant national CSIRT: 24h early warning, 72h detailed report, and a final report (+14 days for actively exploited vulnerabilities, +1 month for severe incidents). This is where vulnerability reporting and incident response automation earns its keep. The platform should track these deadlines with hard timers, drive the incident-response workflow from intake to authority filing, and produce an SRP-ready submission package for the ENISA Single Reporting Platform. ENISA provides no submission API at this stage, so the package is filed in one manual step until automated filing becomes possible.

8

Audit-grade records, CSAF 2.0, and EU data residency

Every intake, acknowledgment, status change, and reporting submission should be timestamped and exportable. When a remediation ships, the platform should generate a CSAF 2.0 machine-readable advisory. And data describing exploited vulnerabilities in EU products belongs in the EU by default, without extra contractual paperwork.

Frequently asked

What is a CRA compliance platform?
A CRA compliance platform is a software product that helps a manufacturer of products with digital elements work through the obligations of Regulation (EU) 2024/2847, the Cyber Resilience Act. The obligation surface covers product classification under Annex III and IV, the documented cybersecurity risk assessment, the Annex I essential requirements, technical documentation per Annex VII, the EU Declaration of Conformity and CE marking, the Annex II information to users, plus the operational duties: a published CVD policy with a single point of contact (Article 13), three-stage reporting of actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT (Article 14), and CSAF 2.0 security advisories when remediation ships.
When does the CRA take effect?
The CRA entered into force on 10 December 2024. The reporting obligations under Article 14 apply from 11 September 2026. The full obligation set, including conformity assessment, applies from 11 December 2027. Manufacturers should have their CVD policy and intake channel operational well before September 2026.
Who is in scope?
Any manufacturer, importer, or distributor placing a product with digital elements on the EU market. This includes hardware with software, standalone software, and remote-data-processing components that are necessary for the product to function. The scope is broad. Most B2B and consumer connected products fall under it.
Do I need a paid platform if my product is simple?
Not necessarily. The CRA does not mandate a specific vendor; it mandates a process. A platform reduces the operational cost of meeting that process and provides the audit trail. For an SME with a single product line, a free-tier platform can cover the Article 13 baseline at no cost.
What happens if I do not have a CVD policy?
From the dates above, non-compliance carries administrative fines up to €15 million or 2.5% of global annual turnover for the most serious infringements. National market surveillance authorities can also issue stop-orders preventing the product from being placed on the market.
Is CVD Portal a CRA compliance platform?
Yes. CVD Portal covers the full obligation surface: product classification and the Article 32 route, STRIDE risk assessment, the Annex I checklist with gap analysis, technical documentation and EU Declaration of Conformity drafting, Annex II user information, CSAF 2.0 advisory generation, and EU data residency by default. Receiving and tracking vulnerability reports is free, Article 14 filing with the SRP-ready package is on the Reporting plan, and the self-assessment suite is on the Compliance plan. Self-assessment under Module A applies to default-class products. Where a product needs a notified body or a European cybersecurity certification scheme, the workspace prepares the technical file and Annex I evidence for that route rather than replacing it.
Does a CRA compliance platform automate vulnerability reporting and incident response?
It should. A CRA compliance platform provides vulnerability reporting and incident response automation by capturing a report at intake, starting the Article 14 deadline timers automatically, driving the case through triage and remediation, and assembling the SRP-ready package for ENISA and the national CSIRT. That removes the manual deadline tracking and document assembly that otherwise dominates an incident. CVD Portal runs this workflow end to end, with hard timers on the 24-hour, 72-hour, and final report stages.
Is CVD Portal a CRA compliance reporting solution?
Yes. As a CRA compliance reporting solution it handles the reporting side of the regulation: a published CVD policy and intake channel under Article 13, the three-stage Article 14 reporting cascade to ENISA and the relevant national CSIRT, deadline timers, an SRP-ready submission package, and CSAF 2.0 machine-readable advisories when remediation ships. Receiving and tracking reports is free, and Article 14 filing with the SRP-ready package is on the Reporting plan.

Try a CRA-native compliance platform

A CRA-native compliance platform is built around the Cyber Resilience Act rather than retrofitted from a generic GRC tool, so classification, risk assessment, and Article 14 reporting share one record.

Article 13 baseline at €0/month. The full self-assessment suite on a 14-day trial. EU data residency by default. No card required to start.