What is a CRA compliance and reporting solution?
A CRA compliance platform handles the full obligation surface that Regulation (EU) 2024/2847 places on every manufacturer of products with digital elements, from classification and risk assessment through documentation to vulnerability handling and authority reporting. As a CRA compliance reporting solution it also has to produce the reports the regulation asks for, and file them on Article 14's clock. This is a buyer's guide to both halves: what to look for, what to avoid, and how to know whether you actually need one.
The CRA in one paragraph
The EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) entered into force on 10 December 2024. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT within 24 hours, follow up with a detailed report within 72 hours, and submit a final report within 14 days or one month depending on the trigger. They must also operate a coordinated vulnerability disclosure process and publish a CVD policy under Article 13. From 11 December 2027 the full conformity regime applies: a documented risk assessment, the Annex I essential requirements, technical documentation, the EU Declaration of Conformity, and CE marking. Most products qualify for self-assessment under Module A.
What a platform replaces
A CRA compliance platform replaces six manual artifacts: the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file. Each carries a low cost individually and a high coordination cost when a real incident lands or an authority requests documentation. CVD Portal generates the artifacts across 88 CRA clause artifacts and 33 security objectives from a single recorded state, so outputs like the EU Declaration of Conformity never drift from the documented position instead of being retyped.
| CRA obligation | Without a platform | With a CRA compliance platform |
|---|---|---|
| Article 13 CVD policy | Hand-built policy page and shared inbox | Branded portal, hosted policy, structured intake with PGP |
| Article 14 reporting | Manual deadline tracking in a spreadsheet | Hard timers on 24h / 72h / final report, SRP-ready package |
| Article 13 risk assessment | Ad-hoc document per product | STRIDE assessment mapped onto Annex I requirements |
| Technical documentation | Folder tree standing in for the file | Annex VII index and Annex V DoC generated from state |
| Advisories | Bespoke advisory documents | CSAF 2.0 machine-readable advisory on remediation |
The compliance reports it has to produce
"Compliance report" is not one document under the CRA. It is six outputs on different clocks, and the reason a CRA compliance reporting solution is worth anything is that it derives all of them from one record instead of six spreadsheets that disagree. A good CRA compliance report solution keeps those six outputs in sync so an audit never catches a contradiction.
| Report | Produced when | What it is |
|---|---|---|
| Article 14 submission package | Actively exploited vulnerability or severe incident | The early warning, the 72-hour notification, and the final report, each assembled from the case record and staged against its own deadline. ENISA exposes no submission API, so filing stays a manual step. The package is what makes that step short. |
| CSAF 2.0 advisory | Remediation ships | A machine-readable security advisory in the format downstream consumers and vulnerability databases can ingest without a human retyping it. Generated from the same record that drove the case. |
| Annex VII technical documentation | Per product, per release | The technical file index, versioned per release, with point-in-time snapshots preserved for the ten-year retention obligation. |
| Annex V EU Declaration of Conformity | Per product, per release | Drafted field by field from the recorded classification, risk assessment and Annex I state rather than retyped, so it cannot drift from the position the technical file documents. |
| Annex II information to users | Per product | The published user information sheet, including the vulnerability reporting contact and the support period end date, generated from the same record as the technical file. |
| Audit trail export | On demand | Every intake, acknowledgment, status change and submission, timestamped and hash-chained, exportable when a market surveillance authority asks how a case was handled. |
The first two are the reporting half and are what most buyers mean by a CRA compliance reporting solution. The rest are the conformity half. For the full duty behind the first row, see the CRA reporting obligations in detail.
Every claim in this table, traced to the Regulation
The CRA FAQ answers each of these in depth, with every obligation pinpointed to an article or annex and each source marked as binding law or as interpretive guidance.
Eight criteria for a real CRA compliance platform
Use these to assess any platform you are evaluating, including CVD Portal.
Product classification and conformity route
The platform should determine where each product sits under Annex III and IV (default, important, or critical) and derive the Article 32 conformity assessment route from that classification. The classification decision and its justification belong in the evidence record, because every downstream artifact depends on it.
Cybersecurity risk assessment
Article 13 requires a documented risk assessment per product, kept up to date and included in the technical documentation. A real platform supports structured threat modelling with likelihood and impact scoring, and maps the results onto the Annex I requirements they make applicable.
Annex I requirement tracking and gap analysis
The essential requirements of Annex I are the substance of conformity. The platform should track each requirement's status per product, show which are open, and connect each gap to remediation guidance and accumulated evidence.
Technical documentation and Declaration of Conformity
The Annex VII technical file and the Annex V EU Declaration of Conformity are generated outputs of the assessment work. A platform should draft both from the recorded state, keep them versioned per release, and preserve point-in-time snapshots for the ten-year retention obligation.
Annex II user information
The information and instructions to users, including the vulnerability reporting contact and the support period end date, should be generated from the same record that produced the technical file, so the published sheet never drifts from the documented position.
Article 13 publication and single point of contact
A published CVD policy under your own brand, plus a contact channel that researchers can actually use. The platform should provide a whitelabel email, a hosted policy page, a structured submission form, PGP support, and safe-harbor language.
Article 14 reporting cascade
Three-stage reporting to ENISA and the relevant national CSIRT: 24h early warning, 72h detailed report, and a final report (+14 days for actively exploited vulnerabilities, +1 month for severe incidents). This is where vulnerability reporting and incident response automation earns its keep. The platform should track these deadlines with hard timers, drive the incident-response workflow from intake to authority filing, and produce an SRP-ready submission package for the ENISA Single Reporting Platform. ENISA provides no submission API at this stage, so the package is filed in one manual step until automated filing becomes possible.
Audit-grade records, CSAF 2.0, and EU data residency
Every intake, acknowledgment, status change, and reporting submission should be timestamped and exportable. When a remediation ships, the platform should generate a CSAF 2.0 machine-readable advisory. And data describing exploited vulnerabilities in EU products belongs in the EU by default, without extra contractual paperwork.
Frequently asked
What is a CRA compliance platform?
When does the CRA take effect?
Who is in scope?
Do I need a paid platform if my product is simple?
What happens if I do not have a CVD policy?
Is CVD Portal a CRA compliance platform?
Does a CRA compliance platform automate vulnerability reporting and incident response?
Is CVD Portal a CRA compliance reporting solution?
Try a CRA-native compliance platform
A CRA-native compliance platform is built around the Cyber Resilience Act rather than retrofitted from a generic GRC tool, so classification, risk assessment, and Article 14 reporting share one record.
Article 13 baseline at €0/month. The full self-assessment suite on a 14-day trial. EU data residency by default. No card required to start.