Here is the honest situation. The Cyber Resilience Act makes cybersecurity a condition of placing any product with digital elements on the EU market. It requires products to be secure by design and by default with no known exploitable vulnerabilities at release, a full vulnerability handling process including a software bill of materials, security updates across a support period of at least five years, conformity assessment and CE marking, and reporting of actively exploited vulnerabilities and severe incidents to ENISA within 24 hours. Building that into your product lifecycle and evidencing it is a major program, and a product shipped with known vulnerabilities or no update mechanism is exactly where manufacturers fall short.
This Kit removes that build. It is every CRA obligation written as an adopt-ready control you personalize in a weekend, with the evidence a market surveillance authority examines.
What you get, the moment you buy
Grounded in the Cyber Resilience Act (Regulation (EU) 2024/2847), with the product scope, the Annex I essential cybersecurity requirements and vulnerability handling, the support period, conformity assessment and CE marking, and the 24-hour and 72-hour reporting duties called out. Editable Word and Excel files.
What one control looks like
This is determining scope and which products with digital elements are in scope, where CRA compliance begins. All 36 are built to this depth.
Why this is not another template pack
- The evidence is the point. A requirement you cannot evidence fails market surveillance. This tells you what an authority examines and where manufacturers fall short, for every obligation.
- Vulnerability handling and reporting built in. The essential requirements, the SBOM and secure updates, and the 24-hour and 72-hour reporting duties are written into the controls, the substance the CRA requires.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The CRA aligns with IEC 62443, ETSI EN 303 645 and secure development standards, so this work feeds your wider product security program.
Who buys this
Manufacturers, importers and distributors of hardware and software products with digital elements on the EU market, and the product security, engineering and compliance leads who own it. Whether it is a first assessment or a product launch, you save weeks and walk in with the requirements, vulnerability handling and evidence structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this legal advice? No. It is an implementation toolkit grounded in the Regulation. For a specific matter consult counsel; this gets your controls and evidence in order fast.
Does it cover the reporting duties? Yes. The 24-hour early warning and 72-hour notification of actively exploited vulnerabilities and severe incidents to ENISA and the CSIRT are built as controls.
Does it cover the support period? Yes. Security updates across a support period of at least five years, or the expected product lifetime, is its own control.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com