- CRA Compliance Software
EU Cyber Resilience Act: Compliance That Holds Up Under Audit
The CRA requires manufacturers to trace every cybersecurity requirement to a risk, a design decision, and a verification test and keep that evidence intact for 10 years. That is, at its core, a requirements management problem. Visure solves it.
CRA Enforcement Timeline
-
Chapter IV active. Notified body and authority obligations apply. Internal tooling and processes must be in place.
-
Article 14 reporting. Actively exploited vulnerabilities must be reported within 24 hours. Final report within 14 days.
-
Full application. All PDEs need CE marking, Annex I compliance evidence, and complete Annex VII documentation.
-
Ongoing
10-year retention. All technical documentation, risk assessments, and baselines must be reproducible on demand.
CRA Requirements Overview
What is the EU Cyber Resilience Act?
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the first horizontal EU law mandating cybersecurity requirements for any product with digital elements (PDE) sold on the European market. It entered into force 10 December 2024 and applies fully from 11 December 2027.
A PDE is any hardware or software product whose intended or foreseeable use includes a direct or indirect logical or physical connection to a device or network from industrial controllers and smart home devices to enterprise software, IoT sensors, and connected vehicle components.
The CRA’s two objectives: ensure manufacturers improve cybersecurity throughout the entire product lifecycle, and give users reliable security information before purchase. Once in scope, a manufacturer must design against defined essential cybersecurity requirements (Annex I), document a risk assessment, manage vulnerabilities systematically, and maintain evidence for at least 10 years.
Excluded from CRA scope: medical devices (EU MDR), motor vehicles (UNECE WP.29 Reg. 2019/2144), civil aviation products, marine equipment, and national security/defence items. Open-source software outside commercial activity is also excluded.
Product Risk Tiers Articles 7, 8 & 32
- Default
Self-assessment permitted
- Important Class I
Full standards or EU-type examination
- Important Class II
Third-party assessment required
- Critical Annex IV
Certification scheme mandatory
Article 64 Enforcement
The cost of non-compliance is not just a fine
or up to
2.5% worldwide turnover
Non-compliance with Annex I essential requirements or Articles 13 and 14 manufacturer obligations
or up to
2% worldwide turnover
Breaches of importer, distributor, CE marking, conformity assessment, or declaration obligations
or up to
1% worldwide turnover
Incorrect, incomplete or misleading information supplied to notified bodies or market surveillance authorities
Market surveillance authorities can order mandatory product withdrawal from the EU market
Mandatory product recall powers for non-conforming products already on the market
Increased manufacturer liability for damages under EU product liability rules
The Core Challenge
Why CRA Is a Requirements Management Problem
Every Article 13 obligation demands that someone in your engineering org owns a requirement, traces it to evidence, and can reproduce that chain years later. That is not a legal task. It is an engineering one.

Requirements without traceability are unacceptable
Annex VII requires you to show, per requirement, how each Annex I clause is implemented and verified. A Word doc or spreadsheet cannot produce this link on demand and cannot prove it was maintained across years of product support.

10-year evidence retention is a systems architecture question
Article 13(13) requires 10 years minimum. Any compliance program built on shared drives or email trails will not survive a market surveillance audit five years after launch. You need reproducible baseline restore, not file versions.

Every vulnerability reopens the evidence chain
Article 14's 24-hour reporting window means the moment a vulnerability is discovered, you need to instantly identify every affected product version, requirement, and test. That requires live traceability, not retrospective documentation.
The CRA Evidence Chain

CRA Annex I Clause
Applicable essential requirement identified and scoped to your product
- Standard Reference

Cybersecurity Risk Assessment
Threat modelled, CVSS score assigned, linked to Annex I clause
- Risk Item

Security Requirement
Authored, linked to risk, approved by Product Security Officer
- Approved

Design and SBOM
Implementation traced to components, architecture, and software dependencies
- Linked

Signed Baseline
Test passed, evidence frozen with electronic signature, retained 10 years
- Verified and Signed
Visure in Action
How Visure Satisfies Each CRA Obligation
Annex I, Part I + Article 13(2)-(4) · Requirements and Risk Traceability
Connect every Annex I clause to a risk, a requirement, and a passing test.
- Import Annex I as structured items. Each clause becomes a requirement in Visure. Your security requirements link to it via the "satisfies" link type not a spreadsheet column.
- Risk Register as first-class items. Threats modelled with CVSS score, severity, likelihood, and Annex I reference. Each risk links bidirectionally to the requirement that mitigates it.
- Live Traceability Matrix. End-to-end coverage from Annex I clause to design to test result. Always current. Gaps flagged with compensating measures.
- Suspect links. When any upstream clause, risk, or requirement changes, every downstream link is flagged for re-verification automatically across the full support period.
Annex I, Part II + Article 14 · SBOM Traceability and Vulnerability Response
Know which products are affected before the 24-hour clock runs out.
- SBOM as a linked data model. Software components modelled as traceable items in Visure each linked to the security requirements and tests that depend on them.
- Instant blast-radius analysis. Report a CVE against any component and the Traceability Diagram surfaces every affected requirement, baseline release, and product version in seconds.
- Article 14 SLA dashboard. 24h early warning, 72h notification, and 14-day final report deadlines tracked live visible to PSO and compliance lead throughout the incident.
- Governed patch workflow. Mitigation tracked from discovery through re-verification and a new signed baseline the full Article 14 audit trail in one place.
Annex VII · Technical Documentation Package
Stop rebuilding your evidence pack the week before an audit.
- Always assembled from live data. Requirements, risks, tests, standards mapping, and SBOM are linked and baselined as engineering work happens not assembled manually before an audit request.
- Standards coverage report. The Traceability Matrix produces a clause-by-clause Annex I coverage report the exact Annex VII §5 deliverable with gaps flagged and compensating measures documented.
- ReqIF and Word export. Generate the full documentation pack from a signed baseline in minutes not the days it takes to manually assemble from scattered documents.
- Always from a signed baseline. The Annex VII pack is generated from an immutable, electronically signed baseline state not the current working copy, which may be mid-flight.
Article 13(13) + Article 32 · Baselines, Signatures and Conformity Assessment
Every release locked, signed, and reproducible for 10 years.
- Review and approval gates. Every requirement, risk, and design document passes through a structured workflow Draft, Reviewed, Approved before it can enter a baseline. Notified bodies see a governed process, not a completed checklist.
- Electronic signatures. Designated users sign with a typed meaning (Approved, Reviewed, Declined), password, and timestamp. Immutable once applied. Full comments trail attributable to each reviewer.
- Baseline restore. Re-activate any historical baseline and inspect the project exactly as it was items, attributes, traceability, and risk state. Required for 10-year reproducibility on demand.
- Baseline comparison. Compare any two releases to surface added, deleted, modified, and moved items with clause-level highlights essential for demonstrating series conformity over time.
Vivia AI · Governed Security Requirements Generation
Define your Annex I requirements in hours, not weeks.
- Prompt to structured requirements. Describe your product type, CRA tier, and applicable Annex I clauses. Vivia generates a candidate requirement set with Annex I reference and verification method pre-filled.
- Human-in-the-loop approval. No AI output enters a baseline without a human sign-off. Every generation event is logged, timestamped, and attributable the AI audit trail is as permanent as the requirement itself.
- On-premise deployment. Vivia runs entirely on your own infrastructure. Zero product data, requirements, or risk information ever leaves your environment essential for classified programs and EU data sovereignty.
- Beyond CVSS templates. Unlike competing tools that only automate risk scoring, Vivia generates complete requirement text, attributes, and Annex I links ready to review, approve, and baseline immediately.
Explore More
CRA Resources from Visure

CRA Compliance Handbook

CRA Compliance Datasheet

Webinar: CRA in Practice
Get a Free CRA Readiness Assessment
CRA FAQ
Common Questions About CRA Compliance
The CRA aims to ensure that wired and wireless products connected to the internet or to a network are more secure; that manufacturers remain responsible for a product's cybersecurity throughout its lifecycle; and that consumers are properly informed about the cybersecurity of products they buy. It is the EU's response to an estimated annual cost of €5.5 trillion from cybercrime, much of it enabled by insecure connected products.
The CRA applies to products with digital elements (PDEs) commercially available in the EU, regardless of place of manufacture. PDEs include standalone software, hardware products with a direct or indirect connection to a network or device, and software or hardware components integrated into PDEs. It excludes websites and SaaS cloud applications that do not support remote processing for a PDE, open-source software outside commercial activity, and products covered by other EU sectoral regulation: medical devices under MDR, motor vehicles under UNECE WP.29, civil aviation products, and national security or defence items.
The CRA entered into force 10 December 2024. Two obligations apply before the full December 2027 deadline: manufacturers must implement Article 14 vulnerability and incident reporting by 11 September 2026 (21 months), and conformity assessment bodies must be established by 11 June 2026 (18 months, applicable to auditors only). Most requirements Annex I essential cybersecurity requirements, CE marking, and full Annex VII technical documentation apply from 11 December 2027.
From 11 September 2026, manufacturers must report to ENISA and the relevant national CSIRT: an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident; a full vulnerability notification within 72 hours with an initial assessment and any mitigation measures; and a final report within 14 days of a corrective measure becoming available, covering a severity and impact analysis, root cause (where known), and any information about malicious actors. A severe incident is defined as one where the product's ability to protect the availability, authenticity, integrity, or confidentiality of data is compromised, or where malicious code has been introduced and can be executed.
Annex VII requires: a general product description and intended purpose; a cybersecurity risk assessment; design and development documentation including system architecture; a list of harmonised standards applied with gap justifications where coverage is incomplete; security test reports; an EU Declaration of Conformity; a Software Bill of Materials (SBOM) in machine-readable format; details of the vulnerability handling process and CVD policy; and a lifecycle maintenance plan. This pack must be available to market surveillance authorities on reasoned request and retained for at least 10 years from the date of placing on the market.
Yes. Annex I, Part II requires manufacturers to identify and document software components in machine-readable format, covering at minimum top-level software dependencies. The SBOM must be maintained and kept current across the entire product support period, and must be included in the Annex VII technical documentation package. Visure models the SBOM as a set of linked items in the project data model, tracing each component to the security requirements and tests that cover it enabling live impact analysis when a component vulnerability is discovered.
No single standard covers all of Annex I confirmed by the JRC/ENISA Cyber Resilience Act Requirements Standards Mapping report (EUR 31892 EN). The most commonly required combination is: IEC 62443-4-1 for secure product development lifecycle; ETSI EN 303 645 for consumer IoT; ISO/IEC 29147 for vulnerability disclosure; ISO/IEC 30111 for vulnerability handling; ISO/IEC 27001/27002 for ISMS; and ISO/IEC 27005 for risk assessment. Your required combination depends on your product class. Manufacturers must demonstrate combined clause-by-clause Annex I coverage and document any gaps with compensating measures.
The CRA covers cybersecurity requirements for products with digital elements. NIS2 (Directive (EU) 2022/2555) requires organisations in specific industries energy, transport, health, digital infrastructure to secure their networks and information systems against cyberattacks. They are complementary: the CRA governs the product placed on the market, NIS2 governs the organisation operating critical infrastructure. A product manufacturer serving NIS2-regulated sectors may face obligations under both.
Visure provides the requirements authoring, end-to-end traceability, risk management, SBOM data modelling, baseline management with electronic signatures, and Annex VII export infrastructure that makes CRA compliance repeatable. Every Annex I requirement can be traced to a design element and verification test; risks are first-class items linked to mitigations; baselines are electronically signed and can be restored exactly at any future date; and the Annex VII evidence pack is generated from live project data on demand. Vivia AI can accelerate initial security requirements authoring against Annex I clauses, with human-in-the-loop approval before any AI output enters a baseline.
Get Started
Ensure CRA Compliance with Visure
Learn how Visure gives your engineering team the requirements management, traceability, and audit trail infrastructure that CRA compliance demands.
- Request a CRA Assesment Demo: Get a CRA project setup
- 14-day free trial full platform access, no credit card required
- Cloud or on-premise including on-premise Vivia AI with zero data egress
Talk to Our CRA Compliance Team
By submitting you agree to Visure’s Privacy Policy.
- 14-Day Trial
- Cancel Anytime
- All Features Included