Free Templates

CVD Policy Templates

Free, CRA Article 13-compliant vulnerability disclosure policy templates for EU manufacturers. Copy, customise, and deploy — or use CVD Portal to manage the full process automatically.

Article 13Article 32Annex I Part IAnnex VFree

Agricultural IoT gateway CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a field gateway aggregating soil, weather and machinery sensors over LPWAN, with a cloud backhaul and a farm-management app. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Vehicle telematics backend CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a connected-vehicle telematics service and its backend, covering the digital elements an OEM or supplier places on the market outside type approval. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Network management system CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a centralised controller that discovers, configures and monitors switching, routing and wireless infrastructure. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Firewall / IDS-IPS appliance CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a next-generation firewall or intrusion detection and prevention appliance inspecting traffic at a network boundary. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Industrial controller (PLC) CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a programmable logic controller or edge automation controller driving plant equipment, engineered and maintained by an integrator. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Mobile robot controller CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a autonomous mobile robot or cobot controller with fleet management, teleoperation and over-the-air updates. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Smart home security hub CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a consumer hub integrating smart locks, cameras and alarm sensors, paired to a mobile app and a vendor cloud. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Smart meter gateway CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a smart metering gateway aggregating consumption data and mediating access between meters, grid operators and consumers. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Carrier router / CPE CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a customer-premises or carrier-grade routing equipment with a remote management plane and operator-pushed firmware. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →
Article 13Article 32Annex I Part IAnnex VFree

Network camera / NVR CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a iP camera and recorder combination with motion analytics, remote viewing and operator-managed retention. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View →

Need more than a template?

CVD Portal provides a complete vulnerability disclosure programme — public submission portal, 48-hour acknowledgment tracking, audit trail, and CSAF advisory generation. Receiving and tracking reports is free. Article 14 filing is on Reporting (the September 2026 requirement).

Set up your free portal