CRA guides & how-tos
Practical, worked guides to getting your product CRA-ready — in the meantime, the CRA guide covers the essentials.
- CRA self-assessment for a small IoT manufacturer, step by step
Most small connected-device makers land in the CRA's default category and can self-assess under internal control (Module A) — no notified body required. Here's the sequence, in the order the evidence actually gets built.
- What goes in CRA Annex VII technical documentation? (with a checklist)
CRA Annex VII (Article 31) sets out, item by item, what the technical documentation must contain “as applicable to the relevant product.” Here's that list as a working checklist.
- EU Declaration of Conformity for software — a worked example
CRA Annex V lists, field by field, what the EU Declaration of Conformity must contain. Below is that list, followed by an illustrative (fictional) worked example.
- CRA deadlines: what to do before 11 September 2026 vs 11 December 2027
The Cyber Resilience Act has two dates on the calendar, and they ask for different things. Here's what to have in place before each.
- SBOM for the CRA: formats, requirements, and how to generate one free
An SBOM is the first evidence artifact of CRA compliance — everything else in the vulnerability-handling process depends on having an accurate one.
- Do you need a notified body under the CRA?
Whether you self-assess or need third-party involvement depends entirely on which of the CRA's three tiers your product falls into. Here's what's on the important and critical lists, and what each tier requires (CRA Article 32).