EU Cyber Resilience Act · Regulation (EU) 2024/2847

Build the technical file and Declaration the CRA actually asks for — in hours, not weeks.

Vandorisk guides you through the Cyber Resilience Act in plain language, for hardware, embedded firmware and pure software alike: classification and conformity route, the mandatory risk assessment, every applicable requirement, and the generated technical file, EU Declaration of Conformity and user information. Its edge is that it tells the truth about gaps. A missing element prints as NOT SUPPLIED, no Declaration exports while a requirement is unmet, and the rules it applies are published for anyone to check.

Built by an EU cybersecurity assessor·Deterministic checks, not AI guesses·You stay in control

11 Sept 2026vulnerability & incident reporting duties begin
11 Dec 2027full CRA application, mandatory to sell in the EU
90%+of products fall in the Default category, where self-assessment is the conformity route
€15M / 2.5%maximum fine, of worldwide turnover, whichever is higher

01 · Applicability

Does the CRA apply to your product?

Three quick questions, 60 seconds. No signup.

1. Does your product include software or digital elements (firmware, an app, cloud connection)?

2. Is it made available on the EU market (sold, distributed, or imported into the EU)?

3. Is it a medical device, motor vehicle, or aviation product (covered by their own rules)?

02 · The first deadline

The first deadline isn’t 2027. It’s 11 September 2026.

From 11 September 2026, every manufacturer with a product with digital elements on the EU market must report actively exploited vulnerabilities and severe incidents: a 24-hour early warning, a 72-hour notification, and a final report within 14 days (one month for incidents), filed to your CSIRT and ENISA. Failing the reporting obligations sits in the CRA’s highest penalty tier: fines up to €15 million or 2.5% of worldwide turnover, whichever is higher. You can’t file a 24-hour report with a process you don’t have. We help you build it before the clock starts.

On 27 July 2026 the Commission published its practical guidance on applying the CRA (C(2026) 5252 and its annex). The guidance is non-binding and it moves neither deadline, so the dates on this page stand. What it adds is answers to the questions manufacturers ask most: how far scope reaches into remote data processing solutions and free and open source software, what counts as a substantial modification, how to set a support period, and what the reporting and risk assessment duties look like in practice. It runs to 67 worked examples and was written with microenterprises and SMEs in mind. Read it on the Commission’s site.

VDP guidance

We help you stand up a vulnerability disclosure program that satisfies the CRA: a coordinated-disclosure policy, a single point of contact for vulnerability reports (Art. 13(17)), security.txt, and the internal routing that makes a researcher’s report actually reach someone who can act.

Review of your existing VDP

Already have a disclosure program? We review it clause-by-clause against the CRA’s vulnerability-handling requirements (Annex I Part II) and the Article 14 duties, and hand you a prioritized gap list: what holds up, what doesn’t, and what to fix first.

Reporting-obligation playbooks

Step-by-step playbooks for the 24h / 72h / 14-day vulnerability timeline and its incident equivalent: who does what, in which hour, with which template, so when a report is due, September 2026 is a drill your team has already run.

Ready before the deadline beats scrambling after it. Start your self-assessment → or get CRA updates by email.

Not sure you could even file on the day? Take the 24-hour test: twelve questions, no signup, nothing stored, and it tells you which gap would hurt first. Not sure which class you are? Check against the 26 named Annex III and IV categories →

03 · The method

How Vandorisk works

A guided self-assessment that mirrors how an assessor actually reviews a product, from “does this even apply to me?” to documents you can stand behind.

Step i.

Classify with confidence

A guided Annex III/IV decision tree (the real 26 product categories in plain language) tells you whether you’re Default, Important or Critical, and exactly which conformity route that means. Where a notified body is genuinely required, it says so.

Step ii.

Risk assessment, guided

The mandatory Article 13 risk assessment as a structured, six-field flow: intended purpose, foreseeable misuse, operational environment, assets, lifetime, threats. It drives which requirements apply, with a documented justification for anything that doesn’t.

Step iii.

Every requirement in plain language

All Annex I product-security and vulnerability-handling requirements, each with what it means, how to satisfy it, and the exact legal reference. Upload your SBOM and Vandorisk screens it against known vulnerabilities, and the results attach to your evidence automatically.

Step iv.

Documents, not homework

A live readiness score with a prioritized gap list and hard compliance blockers, then one-click Word exports of your Annex VII technical file, EU Declaration of Conformity and Annex II user information. Autosaved, versioned against the requirement pack, audit-trailed.

03 · What it looks like

The actual screens, not a rendering

A smart thermostat part-way through its assessment. Nothing here is mocked up: this is what the product shows, with the numbers it computed.

The readiness step: 78 per cent ready with 78 per cent evidenced, 19 requirements met, 4 partial, 2 not met, and a gap list ordered worst-first with the Article 14 reporting deadline counting down.
Readiness. The second figure only counts answers with evidence behind them, the gaps are ordered by what is worst rather than by list position, and the Article 14 line carries the days left until 11 September 2026.
The products dashboard, showing a product with its readiness percentage, how many requirements are assessed, its conformity category, and controls to continue, start a new version, or delete it.
Every product with its readiness, its blockers and its conformity category. New version copies a finished assessment forward rather than making you retype it.

See a finished technical file →— the whole Annex VII document, no account needed.

04 · The economics

The maths your CFO will ask for

Your Annex III/IV classification decides the route, and the route decides the cost. Most products fall in the Default category, where self-assessment was always the legal route (Art. 32(1), Module A) and no lab fee was ever due: the real spend there is consultant fees and your own team’s weeks. Class II and Critical products always involve a notified body, and in practice Class I does too until harmonised standards are cited. Whichever column is yours, the work Vandorisk replaces is the same:

Scroll to compare →
Test lab / notified bodyCompliance consultantVandorisk
Typical cost€25,000+ per producttens of thousandsa fraction of that, per year
Typical timeweeks to monthsweekshours
Your team’s timehours of prep and chasinghours of interviews and reviewsanswering guided questions
Who does the workthe lab (you wait)the consultant (you brief)you, guided step by step
What you learnlittlesomehow your own product complies
When rules changepay againpay againyour assessment updates with the pack

Required to use a notified body (Class II and Critical always, Class I in practice for now)? Vandorisk doesn’t pretend otherwise: the classification step says so, and it prepares the evidence pack that makes that assessment faster.

05 · The reuse

Write the evidence once. Four regimes want most of the same file.

A machine with a radio module, sold into the EU and the US, can face four separate cybersecurity regimes. The legal framing differs completely. The engineering facts underneath barely change.

RED

Radio equipment, already in force

The cybersecurity requirements activated by Delegated Regulation (EU) 2022/30, with the EN 18031 series as the harmonised standards: network protection, personal data and privacy, and protection from fraud. Product properties, assessed on the device.

CRA

Regulation (EU) 2024/2847

Annex I Part I product properties, Annex I Part II vulnerability handling, and the Annex VII technical file. The widest of the four, and the only one that puts you on a 24-hour reporting clock from 11 September 2026.

Machinery

Regulation (EU) 2023/1230, from January 2027

Cybersecurity treated as a safety requirement: protection against corruption (Annex III 1.1.9) and the safety and reliability of control systems (Annex III 1.2.1). The Commission’s CRA guidance says CRA compliance “could facilitate” this, demonstrated through your risk assessment.

US

Cyber Trust Mark, the FCC’s voluntary label

Consumer IoT criteria built on the NIST IR 8425 baseline. Different jurisdiction, same questions about default credentials, update mechanisms and data protection. The programme is still being stood up, and the criteria have been stable throughout.

Eight things get asked for by every one of them: an SBOM, a risk assessment, authentication and access control, the update mechanism, cryptography, logging, the vulnerability-handling process, and the support period. Answer those once, properly, in a form that can be cited, and you have done most of the substantive work four times over.

What does not carry across: certificates, conformity assessments and declarations stay separate, and there is no automatic presumption of conformity between these regimes. Vandorisk builds the CRA technical file and EU Declaration of Conformity today; direct output for RED, Machinery and the Cyber Trust Mark is on the roadmap. What you get now is every one of those answers captured, dated and citable in one place, which is the input all four ask for. See the full mapping →

06 · The value

Why teams choose Vandorisk

Because the alternative isn’t really “do it yourself”: it’s buy the standards, decipher them, document everything by hand, and rebuild it every time the product changes. We removed each of those walls.

No standards shelf required

Understanding your obligations normally starts with buying standards at hundreds of euros apiece (thousands for a full set), written in regulatory language few product teams can parse. Vandorisk translates every applicable requirement into plain language, with how-to-satisfy guidance and the exact legal reference, so you don’t have to.

Assessor DNA

Vandorisk is built by an EU cybersecurity assessor who has evaluated real products against the standards behind this regulation: the same lens a lab would apply, encoded into software.

Deterministic, not generative

No black-box AI verdicts. Every check is a deterministic rule that traces to an article of Regulation (EU) 2024/2847: the same inputs always produce the same result, and you can show a market-surveillance authority why.

Experienced professionals on call

Stuck on a compliance question or a technical one? Professional help from experienced compliance practitioners is part of the offering: a person who has done real evaluations, not a chatbot.

06 · The guarantee

What we guarantee — and what we don’t

Vandorisk guarantees that every requirement maps to a correctly cited provision of Regulation (EU) 2024/2847, that the generated technical file contains every Annex VII element or an explicit NOT SUPPLIED marker, and that no signable document is exported while an applicable requirement is unmet. Each of those can be checked:

1

Read the citations

The requirement pack and its citation index are public: every requirement, next to the provision of the regulation it implements, before you create an account. Read the citation index →

2

See the markers

An Annex VII element you haven’t supplied is printed as NOT SUPPLIED in the document itself, where an assessor would look for it, rather than papered over. See a finished technical file →

3

Try to export too early

No link for this one, because there is nothing to read: while an applicable requirement is unmet, the Declaration export refuses. The readiness screen tells you what is blocking it and why.

It guarantees nothing about whether your answers are true.

You supply the facts about your product and sign the Declaration; Vandorisk makes sure the file built from those facts is complete, cited and consistent, and shows you plainly where it isn’t yet.

07 · Pricing

What an account actually gets you

The applicability check, the classifier and the guidance library above stay open to everyone without an account: an account is what turns those answers into an assessment and the documents that come out of it.

Straight about the state of it: nothing here is metered yet. During the pilot every account can use everything on this page, and the lists below say what each plan is expected to include once pricing starts. Anything not built yet is labelled.

Free

No cost

For taking one product all the way through.

  • One product, all seven steps: scope, Annex III/IV class, Art. 13 risk assessment, every requirement, readiness, documents
  • SBOM upload, screened against OSV, attached to your evidence
  • Readiness and evidence-weighted scores, a prioritized gap list, and the blockers that hold the Declaration back
  • Annex VII technical file, EU Declaration of Conformity and Annex II user information, as Word documents
  • The whole assessment as JSON, for your retention file
Create an account →

Email and a password. No card.

Recommended

Professional

Pricing on request

For a portfolio you have to keep current.

  • Everything in Free, for every product you place on the market
  • Versions that carry forward: clone last release’s assessment instead of starting again
  • Product families: one assessment across variants that do not differ in their cybersecurity properties
  • Teammates with owner, editor and viewer roles
  • Evidence register: name the test report behind an answer instead of describing it
  • API keys so CI can push an SBOM on every build
  • Product-specific test plan & results report (coming Q4 2026)
Ask us what it costs →

Four questions, on this page. A person replies with scope and a price. See exactly what you get →

Enterprise

Pricing on request

For portfolios and regulated environments.

  • Everything in Professional, across every product line you sell
  • Run it yourself: the same application as a container in your own network
  • Audit trail of who answered what and when, stamped with the pack version
  • Priority support and onboarding, with a named contact
  • New requirement packs as they ship (RED and the Machinery Regulation are next on the roadmap)
Talk to us about a rollout →

Same four questions, on this page. A person reads it, not an autoresponder.

Ask for a price

A price depends on how many products you have to keep current and how soon you need them defensible, so those are the questions. Tell us that much and a person comes back with the scope and the number. Prefer email? hello@vandorisk.com reaches the same person.

We use your email address and what you write here to answer this request and nothing else. It is not sold and not shared for advertising, and asking us to delete it at hello@vandorisk.com is enough.

A person reads it. No card, no call scheduled on you.

What we keep: what you type here, sent as one email to the founder and not stored in the product. We use it to answer you. We do not sell it and we do not share it for advertising. To have it deleted, email hello@vandorisk.com.

08 · Questions

Questions every team asks

Is this legal advice? Can I rely on it?

No. Vandorisk is guided self-assessment and documentation software, not legal advice, and the manufacturer remains responsible for the Declaration of Conformity. What it gives you is the same thing a good assessor would: the applicable requirements, in order, with evidence captured and documents generated, so the declaration you sign is defensible and traceable.

The Commission published new guidance in July 2026. Does it change what I have to do?

Not the dates. The guidance published on 27 July 2026 (C(2026) 5252 and its annex) is non-binding, so reporting duties still begin on 11 September 2026 and the main obligations still apply from 11 December 2027. What it changes is how much is left to interpretation. It works through the scope questions that come up most often, including when a remote data processing solution counts as part of your product and how free and open source software is treated, and it covers what counts as a substantial modification, how to set a support period, and what the reporting and risk assessment duties require. There are 67 worked examples, written with microenterprises and SMEs in mind.

My product might be Important Class I or II. Can I still self-assess?

Class I products may self-assess when harmonised standards are applied, but none have been cited in the Official Journal yet, which in practice pushes Class I toward a notified body for now. Class II and Critical products always involve a third party. Vandorisk tells you which class you’re in, is honest about the route, and prepares the evidence pack either way.

Does this apply to software products, or only physical devices?

Both. The CRA covers any “product with digital elements”, defined in the regulation as software orhardware, placed on the market as a product (Art. 3(1)). A standalone app, an operating system, a VPN client, a password manager, firmware: all are squarely in scope, under the same rules and routes, with no hardware required. The one real carve-out is pure cloud/SaaS offered purely as an online service with no downloadable or installable product: that’s generally outside the CRA’s scope, unless it’s the “remote data processing” backend a covered product depends on to work (then it’s in scope through that product). Vandorisk’s classifier and requirement pack already reflect this: several Annex III categories are pure software (operating systems, browsers, password managers, VPNs, anti-malware, SIEM, PKI software), not just connected devices.

Do I have to buy the standards to comply?

No, and this is where most of the months (and thousands of euros) usually go. The standards behind CE-marking cybersecurity cost hundreds of euros apiece and are written for assessors, not product teams. Vandorisk’s requirement packs, built by an experienced compliance evaluator, translate every applicable requirement into plain language with how-to-satisfy guidance and the exact legal reference. For the CRA specifically, no harmonised standards have been cited in the Official Journal yet, so assessment runs against Annex I directly, which is exactly what Vandorisk guides you through.

When do I actually need to act?

Vulnerability and incident reporting duties start in September 2026; the full regulation (technical file, Declaration of Conformity, CE marking) applies from 11 December 2027 to every product placed on the EU market. A first self-assessment typically surfaces gaps (a missing CVD policy, an undocumented support period) that take months to close. Teams that start in 2026 are the ones not paying rush rates in 2027.

09 · Stay informed

CRA updates, without the noise

Deadline changes, new Commission guidance, new product capabilities: one email when something matters. No spam.

What we keep: your email address, nothing else. We use it only for those updates. We do not sell it and we do not share it for advertising. To have it deleted, email hello@vandorisk.com.