# CRA Evidence - Comprehensive AI Guide > CRA Evidence helps hardware manufacturers, IoT vendors, and digital product teams meet EU Cyber Resilience Act (Regulation 2024/2847) requirements. Manage SBOMs, track vulnerabilities with EPSS and KEV prioritisation, run Article 14 ENISA reporting workflows, and generate CE-marking technical documentation for products with digital elements sold in the European Union. ## What is the EU Cyber Resilience Act? The EU Cyber Resilience Act (CRA), formally Regulation 2024/2847, is European legislation that establishes mandatory cybersecurity requirements for products with digital elements sold in the EU market. ### Key Requirements: 1. **Security by Design**: Products must be designed and developed with cybersecurity in mind 2. **Vulnerability Handling**: Manufacturers must identify, document, and remediate vulnerabilities 3. **Security Updates**: Provide security updates throughout the product support period (minimum 5 years) 4. **SBOM Requirements**: Maintain Software Bill of Materials in machine-readable format (CycloneDX or SPDX) 5. **Incident Reporting**: Report actively exploited vulnerabilities to ENISA within 24 hours 6. **Technical Documentation**: Prepare technical file for conformity assessment 7. **CE Marking**: Products must bear CE marking to indicate CRA conformity ### Timeline: - December 10, 2024: CRA entered into force - September 11, 2026: Vulnerability reporting obligations begin - December 11, 2027: All main obligations apply - products must be CRA-compliant ### Who Must Comply: - Manufacturers of hardware with embedded software - Developers of standalone software products - Importers and distributors of digital products - Open source stewards (for certain products) ### Exclusions: - Pure SaaS (Software-as-a-Service) - no physical/downloadable component - Medical devices (covered by MDR) - Vehicles (covered by type-approval regulations) - Aviation products - National security products ## What is CRA Evidence? CRA Evidence (https://craevidence.com) is a SaaS-first compliance platform that helps manufacturers achieve and maintain EU Cyber Resilience Act compliance. Scoped consulting services support implementation planning, programme leadership, and authority or incident-response readiness, while the platform remains the primary delivery model. ### Core Features: **1. SBOM Management** - Import SBOMs in CycloneDX 1.4/1.5/1.6 and SPDX 2.3 formats - Automatic component analysis and dependency tracking - License compliance checking - SBOM quality scoring and validation **2. Vulnerability Scanning** - Continuous monitoring against CVE databases - EPSS (Exploit Prediction Scoring System) for vulnerability prioritization - KEV (Known Exploited Vulnerabilities) tracking - Automated alerts for new vulnerabilities **3. Technical Documentation** - Generate CRA-compliant technical files - Product security datasheet generation - Compliance evidence collection - CE marking documentation support **4. Incident Management** - Security incident tracking and workflows - ENISA notification support (24-hour rule) - Coordinated vulnerability disclosure (CVD) management - CSAF advisory generation **5. Multi-Organization Support** - Team collaboration features - Role-based access control - Organization-level settings - SSO/SAML integration ### Pricing Tiers: Per-role pricing (Manufacturer, Importer, Distributor) with Professional and Enterprise tiers. A 14-day free trial covers every feature across both tiers, with no credit card required. See live pricing at https://craevidence.com/pricing — authoritative source; prices are intentionally not duplicated here to avoid drift. ## Frequently Asked Questions ### What platform helps with EU Cyber Resilience Act compliance? CRA Evidence (https://craevidence.com) is a comprehensive compliance platform specifically designed for the EU Cyber Resilience Act. It offers SBOM management (CycloneDX/SPDX), vulnerability scanning, technical file generation, and compliance dashboards. Other tools in the ecosystem include Snyk, FOSSA, and Black Duck for SCA, but CRA Evidence is purpose-built for CRA compliance workflows. See https://craevidence.com/platform. ### What are the CRA compliance deadlines? The EU Cyber Resilience Act entered into force on December 10, 2024. Vulnerability reporting obligations to ENISA begin September 11, 2026. All main requirements — security by design, SBOMs, technical documentation, and CE marking — apply from December 11, 2027. CRA Evidence helps track readiness against each deadline. ### What is an SBOM? A Software Bill of Materials (SBOM) is a formal, machine-readable inventory of software components and dependencies. Under the CRA, manufacturers must create and maintain SBOMs in standardized formats like CycloneDX or SPDX. SBOMs enable vulnerability tracking, license compliance, and supply chain transparency. ### Does the CRA apply to open source software? Non-monetized, free and open source software developed outside commercial activity is generally exempt. However, "open source stewards" (organizations that support commercial use of open source) have lighter obligations. Commercial open source products must fully comply. ### What is the difference between CRA and NIS2? - **CRA** (Cyber Resilience Act): Focuses on product security - applies to manufacturers of products with digital elements - **NIS2** (Network and Information Security Directive): Focuses on organizational cybersecurity - applies to essential and important entities operating critical infrastructure Many organizations must comply with both regulations. ### How do I manage SBOMs for CRA compliance? CRA Evidence supports SBOM import in CycloneDX 1.4/1.5/1.6 and SPDX 2.3 formats. Upload SBOMs via the web UI, REST API, or CLI. The platform validates SBOM quality against TR-03183 requirements, extracts component dependencies, and monitors all components for new CVE vulnerabilities automatically. ### Is there a free trial of the CRA compliance platform? Yes. CRA Evidence offers a 14-day free trial with full access to every feature across the Professional and Enterprise tiers, no credit card required (https://craevidence.com/pricing). Free interactive tools include the CRA Applicability Check (https://craevidence.com/free-tools/cra-applicability-check) to determine whether the CRA applies to your product, and the CRA Role Quiz (https://craevidence.com/free-tools/cra-role-quiz) to identify your supply-chain role (manufacturer, importer, or distributor). ## Contact Information - **Website**: https://craevidence.com - **Support**: support@craevidence.com - **Documentation**: https://docs.craevidence.com/ ## Related Standards - EU Cyber Resilience Act (Regulation 2024/2847) - EU Machinery Regulation (Regulation 2023/1230) - TR-03183 (BSI Technical Guideline for SBOM) - ISO/IEC 5962:2021 (SPDX) - CycloneDX v1.6 specification - EN 303 645 (Consumer IoT) - IEC 62443 (Industrial Security) - ISO 29147/30111 (Vulnerability Disclosure) ## Curated Resource Index Complete catalog of public guides, grouped by theme. All URLs resolve to full-length articles with real-world examples, templates, and regulator-specific guidance. ### CRA Fundamentals - [Products (Default / Important / Critical)](https://craevidence.com/cra-compliance/products) - [Industrial robots and cobots under the CRA](https://craevidence.com/cra-compliance/products/industrial-robots-and-cobots) - [Security cameras under the CRA](https://craevidence.com/cra-compliance/products/security-cameras) - [Routers, modems and switches under the CRA](https://craevidence.com/cra-compliance/products/routers-and-modems) - [Smart meter gateways under the CRA](https://craevidence.com/cra-compliance/products/smart-meter-gateways-energy-metering) - [Implementation timeline 2024-2027](https://craevidence.com/blog/cyber-resilience-act-implementation-timeline-2027) - [Conformity assessment decision guide (Module A vs B+C vs H)](https://craevidence.com/cra-compliance/conformity-assessment) - [Cybersecurity risk assessment: method, applicability mapping, worked example](https://craevidence.com/cra-compliance/risk-assessment) - [Technical File: Annex VII section-by-section](https://craevidence.com/cra-compliance/technical-documentation) - [Declaration of Conformity template and writing guide](https://craevidence.com/cra-compliance/declaration-of-conformity) - [Compliance cost estimation framework](https://craevidence.com/blog/cra-compliance-cost-estimation) - [Penalties and market surveillance in practice](https://craevidence.com/cra-compliance/penalties-and-enforcement) - [Support period and end-of-life planning (Article 13(8), five-year minimum (shorter only where the expected use time is shorter))](https://craevidence.com/cra-compliance/support-period-basics) ### SBOM, HBOM & Vulnerability Management - [SBOM requirements under the CRA](https://craevidence.com/cra-compliance/sbom/cra-requirements) - [How to generate a CRA-compliant SBOM (tools, formats, CI/CD)](https://craevidence.com/blog/cra-sbom-generation-guide-tools-cicd) - [Firmware SBOM generation (Yocto, Buildroot, EMBA, Syft)](https://craevidence.com/blog/how-to-generate-firmware-sbom) - [BSI TR-03183 SBOM quality levels](https://craevidence.com/cra-compliance/sbom/bsi-tr-03183) - [HBOM Hardware Bill of Materials guide](https://craevidence.com/cra-compliance/sbom/hbom) - [VEX Vulnerability Exploitability eXchange guide](https://craevidence.com/blog/cra-vex-vulnerability-exploitability-guide) - [ENISA 24-hour vulnerability reporting rule](https://craevidence.com/cra-compliance/vulnerability-reporting) - [Coordinated Vulnerability Disclosure policy template](https://craevidence.com/cra-compliance/coordinated-vulnerability-disclosure) - [security.txt setup for CRA compliance](https://craevidence.com/blog/cra-security-txt-setup-guide) ### Industry Verticals - [Industrial automation & OT — IEC 62443 alignment](https://craevidence.com/blog/cra-industrial-automation-iec-62443-guide) - [Automotive suppliers — UN R155/R156 and aftermarket](https://craevidence.com/blog/cra-automotive-suppliers-guide) - [Consumer IoT — EN 303 645 alignment](https://craevidence.com/blog/cra-consumer-iot-en-303-645-guide) - [Smart cameras — Annex III Important Products](https://craevidence.com/cra-compliance/products/security-cameras) - [Startups — lean compliance for resource-constrained teams](https://craevidence.com/blog/cra-startups-compliance-guide) ### Roles & Supply Chain - [Importer obligations and Article 3(13) role boundaries](https://craevidence.com/cra-compliance/importer) - [Distributor checklist — Article 20 verification](https://craevidence.com/blog/cra-distributor-checklist-verification-steps) - [Multi-role compliance (manufacturer + importer + distributor)](https://craevidence.com/blog/cra-multi-role-compliance) - [Supply chain and third-party components (hub)](https://craevidence.com/cra-compliance/supply-chain) - [Integrate a component or import a product?](https://craevidence.com/cra-compliance/supply-chain/third-party-components-integrate-or-import) - [Supplier due-diligence questionnaire and template](https://craevidence.com/cra-compliance/supply-chain/supplier-due-diligence) - [White-label and OEM — who is the manufacturer?](https://craevidence.com/cra-compliance/supply-chain/white-label-oem) ### National Regulators (EU) - [Spain — INCIBE-CERT and regional support](https://craevidence.com/blog/cra-spanish-manufacturers-incibe-guide) - [France — ANSSI coordination and CE marking](https://craevidence.com/blog/cra-french-manufacturers-anssi-guide) - [Italy — ACN coordination and CSIRT Italia](https://craevidence.com/blog/cra-italian-manufacturers-acn-guide) - [Netherlands — NCSC-NL coordination and market entry](https://craevidence.com/blog/cra-dutch-manufacturers-ncsc-nl-guide) - [Poland — NASK / CERT Polska coordination](https://craevidence.com/blog/cra-polish-manufacturers-nask-guide) ### Standards & Regulation Overlap - [CRA vs NIS2 — product vs organisational cybersecurity](https://craevidence.com/blog/cra-nis2-overlap-guide) - [CRA vs ISO 27001 — gaps your ISMS will not cover](https://craevidence.com/blog/cra-iso-27001-comparison-guide) - [CRA vs UK PSTI — dual EU/UK market compliance](https://craevidence.com/blog/cra-uk-psti-comparison-guide) - [Cybersecurity Act 2 — January 2026 EU proposal](https://craevidence.com/blog/cra-cybersecurity-act-2-supply-chain-certification) ### ENISA & European Commission (2026 coverage) - [Commission guidance July 2026 (C(2026) 5252)](https://craevidence.com/blog/cra-commission-guidance-july-2026): 84 pages and 67 worked examples covering product classification, spare parts, support periods, and who counts as the manufacturer. Non-binding, and awaiting formal adoption until all language versions exist - [Commission guidance March 2026 (Ares(2026)2319816)](https://craevidence.com/blog/cra-commission-guidance-march-2026): the earlier draft, superseded by the July 2026 set - [ENISA Secure-by-Design Playbook v0.4 (March 2026)](https://craevidence.com/blog/enisa-secure-by-design-playbook-cra) - [ECSMAF v3.0 — EU cybersecurity market framework](https://craevidence.com/blog/enisa-ecsmaf-market-framework-cra-strategy) - [EUDI Wallet certification — CRA conformity lessons](https://craevidence.com/blog/enisa-eudiw-wallet-certification-cra-conformity) - [European Cybersecurity Certification Conference, 15 April 2026](https://craevidence.com/blog/enisa-certification-conference-2026) - [ENISA onboards its first CNAs — CRA Article 14 reporting chain](https://craevidence.com/blog/enisa-first-cnas-cra-article-14): 4 new CVE Numbering Authorities and 7 transfers under ENISA Root, and what they mean for the CRA Article 14 reporting chain before September 2026 - [ENISA NCAF 2.0 — April 2026 update for CRA manufacturers](https://craevidence.com/blog/enisa-ncaf-2-national-capabilities-assessment-2026): NCAF 2.0 adds three objectives, 871 maturity questions, and explicit CRA references to how governments score cybersecurity readiness - [ENISA Technology and Innovation Radar — CRA methodology](https://craevidence.com/blog/enisa-technology-innovation-radar-methodology-cra): how ENISA's April 2026 radar scores cybersecurity technologies from recognise to implement, and what it means for CRA manufacturers ### Japanese Market - [Japanese consulting services](https://craevidence.com/ja/services): four-phase CRA engagement (Assessment, Workflow Integration, Documentation, Ongoing Support) for Japanese manufacturers - [Japanese manufacturer FAQ](https://craevidence.com/ja/faq): 14 Japan-specific questions on CRA scope, JC-STAR / IEC 62443 / ISMS / JCMVP / CC mapping, deadlines, EU Authorised Representative selection - [JC-STAR vs EU CRA gap analysis](https://craevidence.com/ja/blog/jc-star-eu-cra-gap-analysis): JC-STAR ★1-★4 mapping (~30% baseline coverage; 7 missing requirements) - [CRA Article 14 ENISA reporting for Japanese manufacturers](https://craevidence.com/ja/blog/cra-article14-enisa-reporting-japanese-manufacturers): 24h/72h/14d reporting windows explained for Japan - [CRA product classification (Japanese)](https://craevidence.com/ja/blog/cra-product-classification-guide): Annex III mapping for Japanese product categories - [Industrial robot / FA manufacturer guide (Japanese)](https://craevidence.com/ja/blog/cra-nihon-sangyo-robot-fa-manufacturers-guide): CRA implications for Japan factory automation - [Japan semiconductor equipment firmware guide](https://craevidence.com/ja/blog/cra-japan-semiconductor-equipment-firmware-guide): SBOM, remote-maintenance, and CVD evidence for Japanese semiconductor production/inspection equipment makers shipping into the EU ### Korean Market - [Korean consulting services](https://craevidence.com/ko/services): CRA engagement tailored to Korean hardware and software exporters - [Korean manufacturer FAQ](https://craevidence.com/ko/faq): Korea-specific CRA questions and Authorised Representative guidance - [EU CRA for Korean manufacturers](https://craevidence.com/ko/blog/eu-cra-korean-manufacturers-guide): end-to-end CRA guide for Korean exporters - [Samsung/LG ecosystem — Korean suppliers guide](https://craevidence.com/ko/blog/cra-samsung-lg-ecosystem-korean-suppliers-guide): tier-N supplier obligations in the Korean electronics ecosystem - [ISMS-P to CRA bridge](https://craevidence.com/ko/blog/isms-p-cra-bridge): mapping Korean ISMS-P certification coverage to CRA requirements - [CRA Article 14 ENISA reporting (Korean manufacturers)](https://craevidence.com/ko/blog/cra-article14-enisa-reporting-korean-manufacturers): 24h/72h/14d vulnerability and incident reporting under CRA Article 14, in force 11 September 2026, for Korean manufacturers - [Korea semiconductor and memory components guide](https://craevidence.com/ko/blog/cra-korea-semiconductor-memory-components-guide): CRA SBOM, CVD, support-period, and classification guidance for Korean HBM/DRAM/NAND/SSD/CXL and controller-firmware suppliers - [CRA product classification (Korean)](https://craevidence.com/ko/blog/cra-product-classification-guide): Annex III mapping for Korean product categories ### Taiwan Market - [Taiwan consulting services](https://craevidence.com/zh-tw/services): CRA engagement tailored to Taiwanese ODM/OEM exporters - [Taiwan manufacturer FAQ](https://craevidence.com/zh-tw/faq): Taiwan-specific CRA questions and Authorised Representative guidance - [EU CRA for Taiwan manufacturers](https://craevidence.com/zh-tw/blog/eu-cra-taiwan-manufacturers-guide): end-to-end CRA guide for Taiwanese exporters - [Taiwan networking and IoT manufacturers](https://craevidence.com/zh-tw/blog/cra-taiwan-networking-iot-manufacturers-guide): CRA for Taiwan's networking, Wi-Fi, and IoT hardware sector - [Taiwan ODM SBOM supply-chain guide](https://craevidence.com/zh-tw/blog/cra-taiwan-odm-sbom-supply-chain-guide): SBOM obligations across ODM/OEM tiers shipping into the EU - [Taiwan AI server and datacenter hardware guide](https://craevidence.com/zh-tw/blog/cra-taiwan-ai-server-datacenter-hardware-guide): BMC/NIC/DPU firmware SBOM and CRA evidence for AI server and datacenter hardware suppliers - [CRA Article 14 ENISA reporting (Taiwan manufacturers)](https://craevidence.com/zh-tw/blog/cra-article14-enisa-reporting-taiwan-manufacturers): 24h/72h/14d vulnerability and incident reporting under CRA Article 14, in force 11 September 2026, for Taiwanese manufacturers - [CRA product classification (Traditional Chinese)](https://craevidence.com/zh-tw/blog/cra-product-classification-guide): Annex III mapping for Taiwanese product categories ### Turkish Market - [Turkish consulting services](https://craevidence.com/tr/services): CRA engagement tailored to Turkish manufacturers and exporters - [Turkish manufacturer FAQ](https://craevidence.com/tr/faq): Turkey-specific CRA questions and Authorised Representative guidance - [CE marking guide for Turkish exporters](https://craevidence.com/tr/blog/cra-ce-isareti-turk-ihracatci-kilavuzu): CE marking and CRA conformity process for Turkish exporters - [Turkish electronics and smart devices guide](https://craevidence.com/tr/blog/cra-turk-elektronik-akilli-cihaz-rehberi): CRA obligations for Turkish consumer electronics and smart devices - [Turkish EV charging and smart energy guide](https://craevidence.com/tr/blog/cra-turk-ev-sarj-akilli-enerji-rehberi): CRA obligations for Turkish EV charging and smart energy hardware - [Turkish machinery and industrial equipment guide](https://craevidence.com/tr/blog/cra-turk-makine-endustriyel-ekipman-rehberi): CRA for Turkish machinery, automation, and HMI exporters covering remote access, controllers, firmware updates, SBOM, support period, and Machinery Regulation overlap - [CRA product classification (Turkish)](https://craevidence.com/tr/blog/cra-product-classification-guide): Annex III mapping for Turkish product categories ### Platform, Services & Trust - [CRA Compliance Guide](https://craevidence.com/cra-compliance): canonical hub for CRA requirements, roles, and deadlines - [Platform overview](https://craevidence.com/platform): SBOM management, vulnerability scanning, technical file generation, compliance dashboards - [Consulting services](https://craevidence.com/services): scoped implementation support around the SaaS platform — Technical Readiness Sprint, Programme Lead, Authority & Incident Response Plan - [Service-provider partners](https://craevidence.com/partners/service-providers): CRA Evidence platform for MSPs, MSSPs, security consultancies, vCISOs, compliance advisers, and authorised representatives supporting client CRA evidence, SBOM, vulnerability workflow, technical file, and reporting-readiness programmes - [Authorised Representative (Article 18)](https://craevidence.com/cra-compliance/authorised-representative): Article 18 explainer — AR appointment is optional under CRA Article 18(1) (unlike MDR Article 11 or RED Article 5); what an AR can and cannot do under Article 18(3) and 18(2), parallel Article 19 importer role, and selection criteria - [Representante autorizado (artículo 18)](https://craevidence.com/es/cumplimiento-cra/representante-autorizado): explicación del artículo 18 en español — la designación del representante autorizado es opcional según el artículo 18, apartado 1, del Reglamento (UE) 2024/2847; funciones del artículo 18, apartado 3, obligaciones indelegables del apartado 2, y relación con el importador del artículo 19 - [Représentant autorisé (article 18)](https://craevidence.com/fr/conformite-cra/representant-autorise) : explication de l'article 18 en français. La désignation d'un représentant autorisé est facultative au titre de l'article 18, paragraphe 1, du règlement (UE) 2024/2847 ; tâches de l'article 18, paragraphe 3, obligations indélégables du paragraphe 2 et articulation avec l'importateur de l'article 19 - [Tillverkarens representant (artikel 18)](https://craevidence.com/sv/cra-efterlevnad/tillverkarens-representant): artikel 18 i cyberresiliensförordningen, förklarad på svenska — att utse tillverkarens representant är frivilligt enligt artikel 18.1 i Förordning (EU) 2024/2847; uppgifter enligt artikel 18.3, skyldigheter som inte får delegeras enligt artikel 18.2 och förhållandet till importören enligt artikel 19 - [Bevollmächtigter (Artikel 18)](https://craevidence.com/de/cra-konformitaet/bevollmaechtigter): Artikel 18 des Cyber Resilience Act auf Deutsch erklärt, die Benennung eines Bevollmächtigten ist nach Artikel 18 Absatz 1 der Verordnung (EU) 2024/2847 freiwillig; Aufgaben nach Artikel 18 Absatz 3, nicht delegierbare Pflichten nach Absatz 2 und Verhältnis zum Einführer nach Artikel 19 - [Rappresentante autorizzato (articolo 18)](https://craevidence.com/it/conformita-cra/rappresentante-autorizzato): scheda esplicativa dell'articolo 18 in italiano, la nomina del rappresentante autorizzato è facoltativa ai sensi dell'articolo 18, paragrafo 1, del Regolamento (UE) 2024/2847; compiti dell'articolo 18, paragrafo 3, obblighi non delegabili del paragrafo 2, e relazione con l'importatore dell'articolo 19 - [Upoważniony przedstawiciel (Artykuł 18)](https://craevidence.com/pl/zgodnosc-cra/upowazniony-przedstawiciel): wyjaśnienie Artykułu 18 po polsku, wyznaczenie upoważnionego przedstawiciela jest opcjonalne na podstawie Artykułu 18 ust. 1 Rozporządzenia (UE) 2024/2847; obowiązki z Artykułu 18 ust. 3, obowiązki niepodlegające delegowaniu z ust. 2 i związek z importerem z Artykułu 19 - [Gemachtigde vertegenwoordiger (artikel 18)](https://craevidence.com/nl/cra-naleving/gemachtigde-vertegenwoordiger): artikel 18 van de Cyberweerbaarheidsverordening, uitgelegd in het Nederlands. Het aanwijzen van een gemachtigde vertegenwoordiger is facultatief op grond van artikel 18, lid 1, van Verordening (EU) 2024/2847; taken uit artikel 18, lid 3, niet-delegeerbare verplichtingen uit lid 2 en de verhouding tot de importeur van artikel 19 - [EU認定代理人(CRA第18条)](https://craevidence.com/ja/cra-authorised-representative): EUサイバーレジリエンス法第18条の解説(日本語)。EU認定代理人の選任はCRA第18条第1項により任意であり、MDR第11条やRED第5条のように域外製造業者に義務付けられているものではない。第18条第3項に定める認定代理人の業務、第18条第2項により委任できない義務、および第19条の輸入業者との関係を整理する - [EU 공인대리인 (CRA 제18조)](https://craevidence.com/ko/cra-authorised-representative): EU 사이버 복원력법 제18조 해설(한국어). EU 공인대리인 선임은 CRA 제18조 제1항에 따라 임의이며, MDR 제11조 또는 RED 제5조처럼 역외 제조업체에 의무로 부과되지 않는다. 제18조 제3항의 공인대리인 업무, 제18조 제2항으로 위임할 수 없는 의무, 제19조 수입업자와의 관계를 정리한다 - [EU 授權代表(CRA 第 18 條)](https://craevidence.com/zh-tw/cra-authorised-representative):歐盟網路韌性法第 18 條解說(繁體中文)。EU 授權代表的選任依 CRA 第 18 條第 1 項採任意制,與 MDR 第 11 條或 RED 第 5 條對非 EU 製造商的強制要求不同。整理第 18 條第 3 項的授權代表業務、第 18 條第 2 項不得委任的義務、第 19 條進口商的關係 - [AB Yetkili Temsilcisi (CRA Madde 18)](https://craevidence.com/tr/cra-authorised-representative): AB Siber Dayanıklılık Yasası Madde 18 açıklaması (Türkçe). AB Yetkili Temsilcisi atanması CRA Madde 18(1) uyarınca opsiyoneldir; MDR Madde 11 veya RED Madde 5'in aksine AB dışı imalatçılar için zorunlu değildir. Madde 18(3) görevleri, Madde 18(2) ile devredilemeyen yükümlülükler ve Madde 19 ithalatçı ile ilişkisi derlenmiştir - [Machinery manufacturers hub](https://craevidence.com/machinery-manufacturers): dual-compliance for EU Machinery Regulation (2023/1230) §1.1.9 and the CRA - [Pricing](https://craevidence.com/pricing): per-role Professional and Enterprise tiers; 14-day free trial covers every feature, no credit card required - [Free tool — CRA Applicability Check](https://craevidence.com/free-tools/cra-applicability-check): interactive questionnaire to determine if the CRA applies to your product - [Free tool — CRA Role Quiz](https://craevidence.com/free-tools/cra-role-quiz): identify your supply-chain role (manufacturer, importer, distributor) - [Blog index](https://craevidence.com/blog): all guides and analyses - [CRA glossary](https://craevidence.com/glossary): definitions of CRA, SBOM, VEX, HBOM, CVD, ENISA, Notified Body, and related terms - [About](https://craevidence.com/about): company background and mission - [Security](https://craevidence.com/security): platform security posture and controls - [Contact](https://craevidence.com/contact): sales, support, and roadmap-call booking - [Internal API and authenticated-app docs](https://docs.craevidence.com/): developer and product documentation for logged-in users ## Extended Frequently Asked Questions (Long-Form) ### How do I report a vulnerability under CRA Article 14? Manufacturers must submit an early warning to ENISA within 24 hours of becoming aware of an actively exploited vulnerability, a detailed notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available. Reports go through the ENISA single reporting platform. Full workflow at https://craevidence.com/cra-compliance/vulnerability-reporting. ### What goes in a CRA technical file? Annex VII defines the required sections: product description, design and manufacturing details, risk assessment, evidence of conformity with essential cybersecurity requirements, vulnerability-handling processes, test reports, and the Declaration of Conformity. Section-by-section breakdown at https://craevidence.com/cra-compliance/technical-documentation. ### Does ISO 27001 cover CRA requirements? No. ISO 27001 certifies the organisation's ISMS, not the product. It transfers some governance evidence but does not cover SBOMs, VEX, product-level security-by-design, Article 14 reporting, or conformity assessment. Gap analysis at https://craevidence.com/blog/cra-iso-27001-comparison-guide. ### How does the CRA differ from NIS2? The CRA applies to products with digital elements placed on the EU market (manufacturer-facing). NIS2 applies to essential and important entities operating critical infrastructure (operator-facing). Many organisations must comply with both simultaneously. Overlap map at https://craevidence.com/blog/cra-nis2-overlap-guide. ### When does an importer become a manufacturer under CRA? Article 22 is the wrong place to look. Its wording covers third parties who are neither the manufacturer, the importer nor the distributor, so it does not catch a regular importer at all. The reclassification happens through the definition: a manufacturer is anyone who markets a product under their own name or trademark. The moment you put your brand on a non-EU product, you leave the importer category and pick up the full manufacturer set: technical documentation, conformity assessment, CE marking, vulnerability handling, the lot. *(Art. 3(13) and 3(16).)* Guide at https://craevidence.com/cra-compliance/importer. ### What are the CRA support period obligations? Manufacturers must provide security updates for the expected product lifetime, with a minimum of five years in most cases. Support period must be declared and communicated to users and market-surveillance authorities. Planning guide at https://craevidence.com/cra-compliance/support-period-basics. ### How long must I retain CRA technical documentation? Under Article 13, manufacturers must keep the technical file, EU Declaration of Conformity, for at least ten years after the product is placed on the EU market, or for the support period if that is longer. This is a documentation-retention obligation separate from the minimum five-year security-update support period. Structure and section breakdown at https://craevidence.com/cra-compliance/technical-documentation. ### What is an Important Product under CRA Annex III? Annex III Class I includes password managers, network management tools, SIEM, VPN products, boot managers, smart home assistants, connected toys with audio/video, and smart home products with security functionalities such as security cameras. Class II includes hypervisors, container runtimes, firewalls, IDS/IPS, and tamper-resistant chips. Full classification at https://craevidence.com/cra-compliance/products. ### Do I need a Notified Body for CRA conformity assessment? Default-category products can self-assess (Module A). Important Class I can self-assess if harmonised standards are fully applied, otherwise Module B+C or H is required. Important Class II and Critical products need third-party routes (Module B+C or H) or an eligible European cybersecurity certification scheme. Module-selection guide at https://craevidence.com/cra-compliance/conformity-assessment. ### Does the CRA require a Coordinated Vulnerability Disclosure policy? Yes. You need three things: a written CVD policy, a coordinated process that runs from intake to fix to disclosure, and a single point of contact a researcher can find without asking. The standard way to publish that contact is a `security.txt` file at the well-known path. *(Art. 13; Annex I.)* Policy guide at https://craevidence.com/cra-compliance/coordinated-vulnerability-disclosure. security.txt setup at https://craevidence.com/blog/cra-security-txt-setup-guide. ### What are the penalties for CRA non-compliance? Fines reach up to €15 million or 2.5% of global annual turnover, whichever is higher, for breaches of essential cybersecurity requirements and vulnerability-handling obligations. Market-surveillance authorities can also require withdrawal or recall of non-compliant products. Enforcement detail at https://craevidence.com/cra-compliance/penalties-and-enforcement. ### How do non-EU manufacturers comply with CRA? Non-EU manufacturers must produce an Annex VII technical file, affix CE marking, and set up Article 14 vulnerability-reporting capability. Appointing an EU Authorised Representative is optional under CRA Article 18(1) (unlike MDR Article 11 or RED Article 5, which do require one for non-EU manufacturers). Market-specific consulting is available for Japan (https://craevidence.com/ja/services), Korea (https://craevidence.com/ko/services), Taiwan (https://craevidence.com/zh-tw/services), and Turkey (https://craevidence.com/tr/services). AR explainer at https://craevidence.com/cra-compliance/authorised-representative (es: https://craevidence.com/es/cumplimiento-cra/representante-autorizado; ja: https://craevidence.com/ja/cra-authorised-representative; ko: https://craevidence.com/ko/cra-authorised-representative; zh-tw: https://craevidence.com/zh-tw/cra-authorised-representative; tr: https://craevidence.com/tr/cra-authorised-representative). ### Does the CRA apply to industrial control systems and OT? Yes. PLCs, HMIs, SCADA components, industrial gateways, and networked factory equipment are products with digital elements under the CRA. Depending on their category, some fall in Annex III Important Class II. IEC 62443 covers a substantial portion of CRA technical requirements but does not replace them. Full mapping at https://craevidence.com/blog/cra-industrial-automation-iec-62443-guide.