Statutory Requirements // Essential Clauses

CRA Statutory Clause Explorer

Interactive clause-by-clause analysis of Regulation (EU) 2024/2847. Explore the essential cybersecurity requirements, vulnerability handling duties, and technical documentation mandates governing CE marking.

Regulatory Structure Diagram

Interconnection of Statutory Duties

How design requirements feed vulnerability handling, technical files, and Article 14 reporting triggers.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram
Statutory Articles

Clause-by-Clause Technical Breakdown

Showing 7 statutory sections with technical expectations, evidence standards, and applicable norms.

Manufacturing Outside the EU? (US, UK, Japan, APAC)Article 11 Mandate

Foreign manufacturers must align domestic certifications (US CIRCIA, UK PSTI, Singapore CLS) with EU CRA obligations. Explore cross-border trade corridors across 249 jurisdictions.

Launch Jurisdiction Matrix
Annex I, Part I

Essential Security Requirements (Design & Default)

Essential Security

Products with digital elements must be designed, developed, and produced in a manner that ensures an appropriate level of cybersecurity based on the risks.

Mandatory Technical Expectations:
  • Delivered without known commercially exploitable vulnerabilities
  • Secure by default configuration, including automatic reset mechanisms
  • Protection of data confidentiality and integrity via state-of-the-art cryptography
  • Minimization of attack surface (disabling unused ports, JTAG/SWD debug locks)
  • Protection against memory corruption vulnerabilities in C/C++ native code
Applicable Standards:
IEC 62443-4-2ETSI EN 303 645ISO/IEC 27002
Required Conformity Evidence:

Cryptographic architecture documentation, hardware lock schematics, static/dynamic code analysis reports.

Annex I, Part II

Vulnerability Handling Requirements

Vulnerability Handling

Manufacturers must establish and enforce systematic vulnerability handling processes for the expected product lifetime (minimum 5 years).

Mandatory Technical Expectations:
  • Machine-readable Software Bill of Materials (SBOM) covering top-level and recursive dependencies
  • Coordinated Vulnerability Disclosure (CVD) policy with public intake and RFC 9116 security.txt
  • Timely distribution of security patches free of charge, separated from feature upgrades
  • Automated regression testing and cryptographic signature validation for all update binaries
Applicable Standards:
ISO/IEC 29147 (Vulnerability disclosure)ISO/IEC 30111 (Vulnerability handling)CycloneDX v1.6
Required Conformity Evidence:

Automated SBOM generator logs, public CVD page, secure update server TLS/PKI certificates.

Article 10

Obligations of Manufacturers

Supply Chain & Governance

Primary statutory obligations governing manufacturers who place products with digital elements on the European Union market.

Mandatory Technical Expectations:
  • Carry out comprehensive cybersecurity risk assessment throughout product design
  • Compile and maintain Annex VII Technical Documentation for at least 10 years
  • Draft and sign the official European Union Declaration of Conformity (EU DoC)
  • Affix the CE marking visibly and indelibly to the product packaging or documentation
Applicable Standards:
ISO/IEC 17050-1 (Declaration of conformity)EN ISO 13849 / IEC 62061 (Functional safety overlap)
Required Conformity Evidence:

Formally signed EU Declaration of Conformity, Annex VII technical file archive.

Article 11

Authorised Representatives (Non-EU Manufacturers)

Supply Chain & Governance

Mandatory legal appointment for manufacturers located outside the European Union placing products on the EU market.

Mandatory Technical Expectations:
  • Must designate by written mandate at least one authorised representative established within the European Union
  • Authorised representative must hold the Annex VII technical file and EU Declaration of Conformity for 10 years
  • Must provide market surveillance authorities with all technical documentation and test reports upon reasoned request
  • Must cooperate with competent authorities on any corrective action taken to eliminate cybersecurity risks
Applicable Standards:
ISO/IEC 17050-1EU Blue Guide on Product Rules
Required Conformity Evidence:

Formally executed written mandate, registered EU legal entity address on packaging, technical file repository.

Article 14

Mandatory Reporting of Exploited Vulnerabilities

Incident Response

Statutory early warning and incident reporting requirements active as of September 11, 2026.

Mandatory Technical Expectations:
  • Submit 24-hour Early Warning to ENISA Single Reporting Platform upon detecting active exploitation
  • Submit 72-hour detailed Vulnerability Notification with CVSS scores and indicators of compromise
  • Submit Final Incident Report within 14 days of remediation patch availability
  • Notify impacted users without undue delay if manual mitigation workarounds are required
Applicable Standards:
ENISA Single Reporting Platform API SpecificationCVSS v3.1 / v4.0CWE Taxonomy
Required Conformity Evidence:

ENISA SRP submission receipt, CSIRT communications log, customer advisory bulletins.

Article 13

Open Source Software Stewards

Supply Chain & Governance

Lightweight governance regime for legal entities that provide sustained support for open source software intended for commercial PDE.

Mandatory Technical Expectations:
  • Documented cybersecurity policy ensuring responsible handling of disclosed flaws
  • Coordinated vulnerability reporting mechanisms with upstream maintainers
  • Active cooperation with European national market surveillance authorities
Applicable Standards:
OpenChain ISO/IEC 5230OpenSSF Best Practices Badge
Required Conformity Evidence:

Public open-source security policy, GitHub SECURITY.md file, CVE coordination records.

Annex VII

Technical Documentation Dossier (10-Year Archive)

Supply Chain & Governance

The definitive technical evidentiary dossier proving compliance, which must be retained for at least 10 years after product release.

Mandatory Technical Expectations:
  • General product description, block diagrams, and system operating manuals
  • Cybersecurity risk assessment report identifying threat models and hazard mitigations
  • Software Bill of Materials (SBOM) and complete list of third-party firmware components
  • Test reports from internal laboratories or accredited third-party testing houses
Applicable Standards:
CEN/CENELEC Harmonised StandardsIEC 62443-4-1
Required Conformity Evidence:

Cryptographically hashed archive bundle containing schematics, test telemetry, and source SBOMs.

This Site Uses No Cookies

Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.