CRA Statutory Clause Explorer
Interactive clause-by-clause analysis of Regulation (EU) 2024/2847. Explore the essential cybersecurity requirements, vulnerability handling duties, and technical documentation mandates governing CE marking.
Interconnection of Statutory Duties
How design requirements feed vulnerability handling, technical files, and Article 14 reporting triggers.
Clause-by-Clause Technical Breakdown
Showing 7 statutory sections with technical expectations, evidence standards, and applicable norms.
Foreign manufacturers must align domestic certifications (US CIRCIA, UK PSTI, Singapore CLS) with EU CRA obligations. Explore cross-border trade corridors across 249 jurisdictions.
Essential Security Requirements (Design & Default)
Products with digital elements must be designed, developed, and produced in a manner that ensures an appropriate level of cybersecurity based on the risks.
- Delivered without known commercially exploitable vulnerabilities
- Secure by default configuration, including automatic reset mechanisms
- Protection of data confidentiality and integrity via state-of-the-art cryptography
- Minimization of attack surface (disabling unused ports, JTAG/SWD debug locks)
- Protection against memory corruption vulnerabilities in C/C++ native code
Cryptographic architecture documentation, hardware lock schematics, static/dynamic code analysis reports.
Vulnerability Handling Requirements
Manufacturers must establish and enforce systematic vulnerability handling processes for the expected product lifetime (minimum 5 years).
- Machine-readable Software Bill of Materials (SBOM) covering top-level and recursive dependencies
- Coordinated Vulnerability Disclosure (CVD) policy with public intake and RFC 9116 security.txt
- Timely distribution of security patches free of charge, separated from feature upgrades
- Automated regression testing and cryptographic signature validation for all update binaries
Automated SBOM generator logs, public CVD page, secure update server TLS/PKI certificates.
Obligations of Manufacturers
Primary statutory obligations governing manufacturers who place products with digital elements on the European Union market.
- Carry out comprehensive cybersecurity risk assessment throughout product design
- Compile and maintain Annex VII Technical Documentation for at least 10 years
- Draft and sign the official European Union Declaration of Conformity (EU DoC)
- Affix the CE marking visibly and indelibly to the product packaging or documentation
Formally signed EU Declaration of Conformity, Annex VII technical file archive.
Authorised Representatives (Non-EU Manufacturers)
Mandatory legal appointment for manufacturers located outside the European Union placing products on the EU market.
- Must designate by written mandate at least one authorised representative established within the European Union
- Authorised representative must hold the Annex VII technical file and EU Declaration of Conformity for 10 years
- Must provide market surveillance authorities with all technical documentation and test reports upon reasoned request
- Must cooperate with competent authorities on any corrective action taken to eliminate cybersecurity risks
Formally executed written mandate, registered EU legal entity address on packaging, technical file repository.
Mandatory Reporting of Exploited Vulnerabilities
Statutory early warning and incident reporting requirements active as of September 11, 2026.
- Submit 24-hour Early Warning to ENISA Single Reporting Platform upon detecting active exploitation
- Submit 72-hour detailed Vulnerability Notification with CVSS scores and indicators of compromise
- Submit Final Incident Report within 14 days of remediation patch availability
- Notify impacted users without undue delay if manual mitigation workarounds are required
ENISA SRP submission receipt, CSIRT communications log, customer advisory bulletins.
Open Source Software Stewards
Lightweight governance regime for legal entities that provide sustained support for open source software intended for commercial PDE.
- Documented cybersecurity policy ensuring responsible handling of disclosed flaws
- Coordinated vulnerability reporting mechanisms with upstream maintainers
- Active cooperation with European national market surveillance authorities
Public open-source security policy, GitHub SECURITY.md file, CVE coordination records.
Technical Documentation Dossier (10-Year Archive)
The definitive technical evidentiary dossier proving compliance, which must be retained for at least 10 years after product release.
- General product description, block diagrams, and system operating manuals
- Cybersecurity risk assessment report identifying threat models and hazard mitigations
- Software Bill of Materials (SBOM) and complete list of third-party firmware components
- Test reports from internal laboratories or accredited third-party testing houses
Cryptographically hashed archive bundle containing schematics, test telemetry, and source SBOMs.
This Site Uses No Cookies
Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.