Skip to main content
Image coming soon

EU Cyber Resilience Act (CRA) Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
EU CRA · Cyber Resilience Act 2024/2847 · Evidence & Implementation Kit
Meet the EU Cyber Resilience Act, without turning the essential requirements into controls yourself.
Every CRA obligation handed to you as an adopt-ready control, from the product scope and essential cybersecurity requirements through vulnerability handling and updates to conformity, CE marking and the 24-hour reporting duties, with the evidence a market surveillance authority examines.
CRA-ready in a weekend, not a quarter.

Here is the honest situation. The Cyber Resilience Act makes cybersecurity a condition of placing any product with digital elements on the EU market. It requires products to be secure by design and by default with no known exploitable vulnerabilities at release, a full vulnerability handling process including a software bill of materials, security updates across a support period of at least five years, conformity assessment and CE marking, and reporting of actively exploited vulnerabilities and severe incidents to ENISA within 24 hours. Building that into your product lifecycle and evidencing it is a major program, and a product shipped with known vulnerabilities or no update mechanism is exactly where manufacturers fall short.

This Kit removes that build. It is every CRA obligation written as an adopt-ready control you personalize in a weekend, with the evidence a market surveillance authority examines.

What you get, the moment you buy

36
Obligations as adopt-ready controls. Every CRA obligation, from the product scope and essential cybersecurity requirements through vulnerability handling, updates, conformity, CE marking and the reporting duties, written so you personalize and apply it.
36
Evidence-they-examine checklists. For each control, exactly what a market surveillance authority examines, plus where manufacturers fall short, so you close the gap first.
1
Product Cybersecurity Control Matrix, pre-built. Every obligation in a working spreadsheet, ready to record status, owner and evidence location across your products.
1
Gap & Readiness Assessment. Score each obligation and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the Cyber Resilience Act (Regulation (EU) 2024/2847), with the product scope, the Annex I essential cybersecurity requirements and vulnerability handling, the support period, conformity assessment and CE marking, and the 24-hour and 72-hour reporting duties called out. Editable Word and Excel files.

No known exploitable vulnerabilities, and a way to fix the rest
The CRA requires products to ship with no known exploitable vulnerabilities and to carry a vulnerability handling process, an SBOM and a secure update mechanism across the support period. A product with no way to patch fails the essential requirements. This Kit builds the secure-by-design and vulnerability handling controls with the evidence, so the core of the CRA is covered.

What one control looks like

This is determining scope and which products with digital elements are in scope, where CRA compliance begins. All 36 are built to this depth.

CRA-1 Determine products with digital elements in scope DIGITAL PRODUCTS
Put this control in place

Maintain a documented inventory that classifies every hardware and software offering as a product with digital elements when its intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, recording for [your product portfolio owner] the rationale, connection type, and inclusion or exclusion decision for each item.

Regulatory note.

The Regulation applies to products with digital elements whose use includes a direct or indirect data connection.

Evidence a market surveillance authority examines
  • Product inventory listing all hardware and software offerings
  • Scope determination records with connection analysis per product
  • Reasonably foreseeable use assessments
  • Exclusion justifications for out of scope items
Common finding they raise: Firms often exclude accessory software or embedded firmware that independently meets the connected product definition.

Why this is not another template pack

  • The evidence is the point. A requirement you cannot evidence fails market surveillance. This tells you what an authority examines and where manufacturers fall short, for every obligation.
  • Vulnerability handling and reporting built in. The essential requirements, the SBOM and secure updates, and the 24-hour and 72-hour reporting duties are written into the controls, the substance the CRA requires.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The CRA aligns with IEC 62443, ETSI EN 303 645 and secure development standards, so this work feeds your wider product security program.

Who buys this

Manufacturers, importers and distributors of hardware and software products with digital elements on the EU market, and the product security, engineering and compliance leads who own it. Whether it is a first assessment or a product launch, you save weeks and walk in with the requirements, vulnerability handling and evidence structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 36 obligations
✓  A completed product cybersecurity control matrix
✓  The evidence a market surveillance authority examines
✓  Your secure-by-design and vulnerability handling in place
✓  A readiness percentage and a fix list
✓  The common essential-requirement failures designed out

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this legal advice? No. It is an implementation toolkit grounded in the Regulation. For a specific matter consult counsel; this gets your controls and evidence in order fast.

Does it cover the reporting duties? Yes. The 24-hour early warning and 72-hour notification of actively exploited vulnerabilities and severe incidents to ENISA and the CSIRT are built as controls.

Does it cover the support period? Yes. Security updates across a support period of at least five years, or the expected product lifetime, is its own control.

What if it is not for me? A 30-day money-back guarantee.

Do not ship a product with known vulnerabilities or no update path.
Every CRA obligation is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be CRA-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com