- CRA Compliance Software
EU Cyber Resilience Act: Compliance That Holds Up Under Audit
The CRA requires manufacturers to trace every cybersecurity requirement to a risk, a design decision, and a verification test and keep that evidence intact for 10 years. That is, at its core, a requirements management problem. Visure solves it.
CRA Enforcement Timeline
-
Chapter IV active. Notified body and authority obligations apply. Internal tooling and processes must be in place.
-
Article 14 reporting. Actively exploited vulnerabilities must be reported within 24 hours. Final report within 14 days.
-
Full application. All PDEs need CE marking, Annex I compliance evidence, and complete Annex VII documentation.
-
Ongoing
10-year retention. All technical documentation, risk assessments, and baselines must be reproducible on demand.
CRA Requirements Overview
What is the EU Cyber Resilience Act?
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the first horizontal EU law mandating cybersecurity requirements for any Product with Digital Elements (PDE) sold on the European market. Entered into force on 10 December 2024 and applying fully from 11 December 2027, it covers hardware and software with network connections, ranging from industrial controllers and smart home devices to enterprise software, IoT sensors, and connected vehicle components.
The CRA requires manufacturers to enhance cybersecurity throughout the product lifecycle and provide transparent security information to users prior to purchase. Once in scope, manufacturers must satisfy Annex I essential requirements, document risk assessments, systematically manage vulnerabilities, and maintain evidence for 10 years. Excluded sectors include medical devices, motor vehicles, civil aviation, national defense, and non-commercial open-source software.
Product Risk Tiers Articles 7, 8 & 32
- Default
Self-assessment permitted
- Important Class I
Full standards or EU-type examination
- Important Class II
Third-party assessment required
- Critical Annex IV
Certification scheme mandatory
Article 64 Enforcement
The Cost of Non-compliance Is Not Just A Fine
or up to
2.5% worldwide turnover
Non-compliance with Annex I essential requirements or Articles 13 and 14 manufacturer obligations
or up to
2% worldwide turnover
Breaches of importer, distributor, CE marking, conformity assessment, or declaration obligations
or up to
1% worldwide turnover
Incorrect, incomplete or misleading information supplied to notified bodies or market surveillance authorities
Market surveillance authorities can order mandatory product withdrawal from the EU market
Mandatory product recall powers for non-conforming products already on the market
Increased manufacturer liability for damages under EU product liability rules
The Core Challenge
Why CRA Is a Requirements Management Problem
Every Article 13 obligation requires engineering teams to own security requirements, trace them to verification evidence, and maintain that audit chain throughout years of product support. Satisfying these regulatory mandates is ultimately a systems engineering problem rather than a legal task.

Traceability Mandates Demand Systems Integration
Annex VII mandates proving how each Annex I cybersecurity clause is verified. Static spreadsheets cannot generate live links on demand or demonstrate continuous compliance.

10-Year Retention Requires Architecture
Article 13(13) sets a 10-year evidence retention window. Surviving audits requires reproducible, frozen baselines rather than disconnected files or email trails.

Vulnerabilities Reopen Evidence Chains
Article 14’s 24-hour reporting window requires immediate identification of all affected versions, requirements, and test suites, demanding real-time, dynamic lifecycle traceability.
The CRA Evidence Chain

CRA Annex I Clause
Applicable essential requirement identified and scoped to your product
- Standard Reference

Cybersecurity Risk Assessment
Threat modelled, CVSS score assigned, linked to Annex I clause
- Risk Item

Security Requirement
Authored, linked to risk, approved by Product Security Officer
- Approved

Design and SBOM
Implementation traced to components, architecture, and software dependencies
- Linked

Signed Baseline
Test passed, evidence frozen with electronic signature, retained 10 years
- Verified and Signed
Visure in Action
How Visure Satisfies Each CRA Obligation
Annex I, Part I + Article 13(2)-(4) · Requirements and Risk Traceability
From Annex I Requirements to Test Evidence. Fully Linked, Fully Auditable
The CRA requires manufacturers to map every Annex I cybersecurity clause directly to a documented risk, design decision, and passing test. Visure delivers end-to-end, live traceability by structuring these elements as linked engineering items rather than static documentation.
- Import Annex I as Requirements: Automatically import Annex I clauses as structured requirements to build your compliance baseline from day one.
- Live Risk Register Integration: Link threats directly to mitigation requirements, enabling real-time risk coverage analysis.
- Live Traceability Matrix. End-to-end coverage from Annex I clause to design to test result. Always current. Gaps flagged with compensating measures.
- Automated Suspect Linking: Instantly flag downstream dependencies when upstream requirements or risks change to maintain continuous audit readiness.
Annex I, Part II + Article 14 · SBOM Traceability and Vulnerability Response
Instant Product Impact Analysis Before the 24-Hour Window Expires
Article 14 requires reporting actively exploited vulnerabilities within 24 hours. Visure pairs Software Bill of Materials (SBOM) data with your live requirement structure to evaluate real-time impact before deadlines expire.
- SBOM-to-Requirement Mapping: Ingest SBOMs to link third-party components directly to your functional security requirements and design models.
- Instant Blast-radius Analysis: Run automated queries when a new CVE is published to pinpoint every affected product variant, version, and component.
- Fast-Track Reporting: Generate complete impact reports, linked test suites, and mitigation plans within minutes to fulfill reporting obligations without operational panic.
Annex VII · Technical Documentation Package
Generate Complete, Audit-Ready Technical Packs on Demand
Article 13(13) mandates keeping complete Annex VII technical documentation available for market surveillance authorities for 10 years. Visure replaces manual document assembly with real-time, audit-ready exports.
- Automated Annex VII Packages: Export fully formatted technical documentation aligned directly with Annex VII structure in a single click.
- 10-Year Reproducible Baselines: Freeze versioned baselines to prove exact compliance states for any shipped release throughout its support window.
- ReqIF and Word export. Generate the full documentation pack from a signed baseline in minutes not the days it takes to manually assemble from scattered documents.
- Complete Audit Trails: Automatically capture electronic signatures, change logs, and review histories to demonstrate uncompromised evidence integrity.
Article 13(13) + Article 32 · Baselines, Signatures and Conformity Assessment
Lock, Sign, and Secure Baseline Compliance for 10 Years
Article 13(13) requires keeping technical documentation reproducible for 10 years after a product hits the market. Visure ensures historical evidence remains unalterable, fully audit-proof, and accessible across long support lifecycles.
- Immutable Version Freezing: Lock exact compliance states, including requirements, test runs, and SBOMs, at the precise moment of release.
- Cryptographic Signatures: Apply eIDAS-compliant electronic signatures to baselines to guarantee tamper-proof evidence integrity during audits.
- Instant Historic Rollbacks: Retrieve and inspect historical baseline configurations instantly without manual re-creation or data loss.
Vivia AI · Governed Security Requirements Generation
Accelerate Annex I Security Requirement Definition with AI
Vivia, Visure’s governed AI engine, generates CRA-aligned security requirement drafts from your product description and Annex I clauses. It cuts drafting time from weeks to hours while enforcing human sign-offs and an immutable audit trail.
- Prompt-to-Structured Requirements: Input your product type, CRA tier, and Annex I clauses to generate candidate requirement sets with pre-filled verification methods.
- Human-in-the-Loop Sign-off: Ensure no AI output enters a baseline without explicit approval. Every generation event is logged and permanently timestamped.
- On-Premise Security: Run Vivia entirely on your infrastructure, ensuring zero product data or risk information leaves your environment.
- Beyond Risk Templates: Automatically generate complete requirement text, attributes, and Annex I links ready for immediate review, approval, and baselining.
Explore More
CRA Resources from Visure

CRA Compliance Handbook

CRA Compliance Datasheet

Webinar: CRA in Practice
Get a Free CRA Readiness Assessment
CRA FAQ
Common Questions About CRA Compliance
The CRA aims to ensure that wired and wireless products connected to the internet or to a network are more secure; that manufacturers remain responsible for a product's cybersecurity throughout its lifecycle; and that consumers are properly informed about the cybersecurity of products they buy. It is the EU's response to an estimated annual cost of €5.5 trillion from cybercrime, much of it enabled by insecure connected products.
The CRA applies to products with digital elements (PDEs) commercially available in the EU, regardless of place of manufacture. PDEs include standalone software, hardware products with a direct or indirect connection to a network or device, and software or hardware components integrated into PDEs. It excludes websites and SaaS cloud applications that do not support remote processing for a PDE, open-source software outside commercial activity, and products covered by other EU sectoral regulation: medical devices under MDR, motor vehicles under UNECE WP.29, civil aviation products, and national security or defence items.
The CRA entered into force 10 December 2024. Two obligations apply before the full December 2027 deadline: manufacturers must implement Article 14 vulnerability and incident reporting by 11 September 2026 (21 months), and conformity assessment bodies must be established by 11 June 2026 (18 months, applicable to auditors only). Most requirements Annex I essential cybersecurity requirements, CE marking, and full Annex VII technical documentation apply from 11 December 2027.
From 11 September 2026, manufacturers must report to ENISA and the relevant national CSIRT: an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident; a full vulnerability notification within 72 hours with an initial assessment and any mitigation measures; and a final report within 14 days of a corrective measure becoming available, covering a severity and impact analysis, root cause (where known), and any information about malicious actors. A severe incident is defined as one where the product's ability to protect the availability, authenticity, integrity, or confidentiality of data is compromised, or where malicious code has been introduced and can be executed.
Annex VII requires: a general product description and intended purpose; a cybersecurity risk assessment; design and development documentation including system architecture; a list of harmonised standards applied with gap justifications where coverage is incomplete; security test reports; an EU Declaration of Conformity; a Software Bill of Materials (SBOM) in machine-readable format; details of the vulnerability handling process and CVD policy; and a lifecycle maintenance plan. This pack must be available to market surveillance authorities on reasoned request and retained for at least 10 years from the date of placing on the market.
Yes. Annex I, Part II requires manufacturers to identify and document software components in machine-readable format, covering at minimum top-level software dependencies. The SBOM must be maintained and kept current across the entire product support period, and must be included in the Annex VII technical documentation package. Visure models the SBOM as a set of linked items in the project data model, tracing each component to the security requirements and tests that cover it enabling live impact analysis when a component vulnerability is discovered.
No single standard covers all of Annex I confirmed by the JRC/ENISA Cyber Resilience Act Requirements Standards Mapping report (EUR 31892 EN). The most commonly required combination is: IEC 62443-4-1 for secure product development lifecycle; ETSI EN 303 645 for consumer IoT; ISO/IEC 29147 for vulnerability disclosure; ISO/IEC 30111 for vulnerability handling; ISO/IEC 27001/27002 for ISMS; and ISO/IEC 27005 for risk assessment. Your required combination depends on your product class. Manufacturers must demonstrate combined clause-by-clause Annex I coverage and document any gaps with compensating measures.
The CRA covers cybersecurity requirements for products with digital elements. NIS2 (Directive (EU) 2022/2555) requires organisations in specific industries energy, transport, health, digital infrastructure to secure their networks and information systems against cyberattacks. They are complementary: the CRA governs the product placed on the market, NIS2 governs the organisation operating critical infrastructure. A product manufacturer serving NIS2-regulated sectors may face obligations under both.
Visure provides the requirements authoring, end-to-end traceability, risk management, SBOM data modelling, baseline management with electronic signatures, and Annex VII export infrastructure that makes CRA compliance repeatable. Every Annex I requirement can be traced to a design element and verification test; risks are first-class items linked to mitigations; baselines are electronically signed and can be restored exactly at any future date; and the Annex VII evidence pack is generated from live project data on demand. Vivia AI can accelerate initial security requirements authoring against Annex I clauses, with human-in-the-loop approval before any AI output enters a baseline.
Get Started
Ensure CRA Compliance with Visure
Learn how Visure gives your engineering team the requirements management, traceability, and audit trail infrastructure that CRA compliance demands.
- Request a CRA Assesment Demo: Get a CRA project setup
- 14-day free trial full platform access, no credit card required
- Cloud or on-premise including on-premise Vivia AI with zero data egress
Talk to Our CRA Compliance Team
By submitting you agree to Visure’s Privacy Policy.
- 14-Day Trial
- Cancel Anytime
- All Features Included