Reg (EU) 2024/2847Generate dossier — €149
LIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

Your POS terminal sits on the counter of a European restaurant. It connects to WiFi, processes card payments, runs Android and receives remote firmware updates. A cybersecurity breach in a POS terminal is not just a data leak — it is payment fraud at scale. Regulation (EU) 2024/2847 requires Annex VII technical documentation covering vulnerability handling, secure defaults and risk assessment. Your PCI-DSS certification covers payment security. The CRA covers product cybersecurity. CRACheck generates the CRA documentation.

European retail chains, hospitality groups and transport operators deploy thousands of POS terminals and self-service kiosks. Each device is a networked endpoint processing sensitive data. PCI-DSS certifies payment security. The CRA addresses the product's broader cybersecurity: firmware integrity, OTA update security, network exposure, authentication, vulnerability handling. POS terminals are not explicitly in Annex III — most are Default products under Module A. CRACheck generates 8 PDF documents per Annex VII. 15-25 minutes. €149 per terminal model. Browser-side.

Generate CRA dossier — €149Free: check your product classification

€149 one-time · 8-document ZIP · 15-25 minutes · Browser-side

Regulation (EU) 2024/2847 · Art. 31 + Annex VII · 8 documents · 100% browser-side

Key numbers

PCI + CRA
PCI-DSS covers payment security. CRA covers product cybersecurity. Both required. Different scopes.
Default
POS terminals without Annex III functionality are Default products. Module A self-assessment.
€149
Per terminal model. 8 documents. 15 minutes.

CRA documentation for POS terminals and kiosks from China

PCI-DSS is one layer. CRA is another. European retailers will require both.

1
Classify your terminal
POS terminals are not in Annex III. Default products. Module A self-assessment.
2
Map digital interfaces
WiFi/LTE/Ethernet, NFC/EMV payment, touchscreen, USB, printer, barcode scanner, camera (if present), cloud management platform, OTA updates.
3
Generate CRA dossier
Enter specifications into CRACheck. 15-25 minutes.
4
Differentiate from PCI-DSS
PCI covers cardholder data. CRA covers the product's cybersecurity. Document both in your compliance package.
5
Deliver to EU retail buyers
Include CRA documentation alongside PCI-DSS certificates in procurement responses.

PCI-DSS is one layer. CRA is another. European retailers will require both.

POS terminal CRA mistakes

SCOPE

PCI-DSS covers all cybersecurity requirements for payment terminals

PCI-DSS covers the security of cardholder data environments. Regulation (EU) 2024/2847 covers the cybersecurity of the product with digital elements — including firmware integrity, OTA update security, authentication, vulnerability handling and SBOM. A POS terminal can be PCI-compliant but CRA-non-compliant if it lacks Annex VII documentation.

ANNEX I, PART I, 1(d)

Our kiosk requires admin login — it is secure by default

Annex I Part I point 1(d) requires secure by default configuration. If your kiosk ships with a universal admin password (admin/1234), it is not secure by default regardless of the login requirement. Each unit must have unique default credentials or require credential setup before first use.

ART. 13.8

Our POS terminal has a 3-year warranty — support period covered

POS terminals are deployed for 5-10 years in retail environments. Art. 13.8 requires the support period to reflect expected use. A 3-year support period for a product with a 7-year deployment leaves 4 years without security updates. EU retail chains will not accept this.

What each CRACheck dossier contains: 8 documents

POS terminals and kiosks process payment and personal data. CRACheck generates 8 documents covering product cybersecurity — complementing your PCI-DSS certification.

1

Product Classifier

Determines product category per Annex III. Defines conformity assessment route under Art. 32.

2

Technical Documentation

Complete technical documentation structured per Art. 31 and Annex VII. All 8 mandatory sections.

3

Risk Assessment

Cybersecurity risk assessment per Art. 13.2 and Art. 13.3. Mapped against Annex I Part I requirements.

4

User Information

Information and instructions per Annex II. Security properties, support period, vulnerability reporting.

5

Declaration of Conformity

EU declaration of conformity per Art. 28 and Annex V.

6

CVD Policy

Coordinated Vulnerability Disclosure policy per Annex I Part II.

7

ENISA Notification Template

Pre-structured for 24h early warning, 72h notification, 14-day final report under Art. 14.

8

Obligations Calendar

Key dates: Art. 14 from 11 Sep 2026, full enforcement 11 Dec 2027, support period per Art. 13.8.

Mira antes de comprar — Descargar dossier de muestra (PDF, empresa ficticia) — Estructura real, artículos reales, formato real. Datos ficticios.

Generated in your browser. No product data is transmitted to any server.

What you pay for POS terminal CRA documentation

🧾 PAYMENT SECURITY CONSULTANCY (PCI + CRA)
€15,000–€30,000
Per terminal platform. 4-8 months.
✓ CRACHECK
€149
8 CRA documents. 15 min. PCI certification handled separately.

Product cybersecurity vs. payment security

● LAYER 1

What CRACheck does

Generates Annex VII documentation for your POS terminal or kiosk. Covers firmware, network security, OTA updates, USB management, vulnerability handling. The cybersecurity layer that PCI does not cover.

∅ LAYER 2

What CRACheck does NOT do

CRACheck does not perform PCI-DSS assessment, PA-DSS validation or payment transaction testing. PCI and CRA are complementary. CRACheck handles the CRA documentation.

We document product cybersecurity. Your PCI assessor handles payment security.

CRA penalty regime — Article 64 of Regulation (EU) 2024/2847

Article 64 establishes three tiers of administrative fines. Penalties are calculated per undertaking — but non-compliance on a single product can trigger inspection of your entire portfolio.

🇪🇺
Non-compliance with essential cybersecurity requirements (Annex I) and Art. 13/14 obligations
€15M / 2.5%

Art. 64.2. Up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher.

🇪🇺
Non-compliance with technical documentation (Art. 31), authorised representative (Art. 18), conformity assessment (Art. 32)
€10M / 2%

Art. 64.3. Up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Includes failure to produce Annex VII documentation.

🇪🇺
Supply of incorrect, incomplete or misleading information to authorities
€5M / 1%

Art. 64.4. Up to €5 million or 1% of total worldwide annual turnover, whichever is higher.

Art. 64.5 accounts for the nature, gravity and duration of the infringement, and gives consideration to microenterprises, small and medium-sized enterprises, including start-ups.

Alternatives

AlternativeCostWhat you get
PCI + CRA consultancy€15,000–€30,000Combined. 4-8 months.
Rely on PCI certification alone€0 additionalPCI covers payments. CRA covers the product. Separate.
Wait for retail buyer to enforce€0 nowLose EU procurement tenders.
CRACheck€1498 CRA docs. 15 min. Complement your PCI certification.

Your terminal portfolio spans POS, kiosk, vending and signage?

Each terminal model with different hardware/firmware needs its own CRA dossier. Volume pricing: €99/model (10-pack), €79/model (30-pack).

Request volume pricing
Response within one business day.

What CRACheck guarantees and what it does not

CRACheck generates a structured document according to Article 31 and Annex VII of Regulation (EU) 2024/2847 from the information you provide. The accuracy, completeness and truthfulness of that information is your responsibility as the manufacturer.

We guarantee that the document structure follows Article 31 and Annex VII of Regulation (EU) 2024/2847 and that the legal references cited are correct as of the last verification date. We do not guarantee that a specific document will be accepted by a market surveillance authority in a specific case or by a commercial buyer in a procurement process.

CRACheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.

Frequently asked questions

Does the CRA apply to a kiosk running Windows IoT?
Yes. A kiosk with Windows IoT, network connectivity and digital functionality is a product with digital elements under Art. 2.1. The OS vendor (Microsoft) provides the OS. You, as the manufacturer of the kiosk product, are responsible for the complete product's CRA documentation including the OS integration.
Our terminal processes payment card data — does CRA documentation expose security details?
The Annex VII documentation covers the product's cybersecurity architecture, not specific cardholder data flows. PCI-DSS restricts disclosure of cardholder data environment details. Your CRA documentation can describe the security measures without exposing PCI-sensitive implementation details.
Do digital signage screens without touch interaction need CRA documentation?
If the signage connects to a network (WiFi, Ethernet, LTE) for content updates and has digital firmware, it is a product with digital elements. A passive screen without network connectivity is not in scope.
What support period for a POS terminal?
POS terminals are deployed for 5-10 years. Art. 13.8 requires the support period to reflect expected use. For POS terminals, 7-10 years of security updates is consistent with retail deployment cycles.
Is this a subscription?
No. One-time payment. The licence includes 30 days of editing and 10 regenerations. The downloaded PDF is yours to keep.
Can I request a refund?
Pursuant to Art. 16(m) of Directive (EU) 2011/83 on consumer rights, by activating the licence you give express consent for the immediate generation of the digital content, waiving the 14-day withdrawal period. Refunds are accepted only for reproducible technical failures.
What if the regulation changes?
If the regulation changes during the validity of your licence, you can regenerate the document with the updated version of the generator at no additional cost.
⚠️ Important notice: CRACheck is a self-assessment documentation tool, not legal advice and not a third-party audit. The document under Article 31 and Annex VII of Regulation (EU) 2024/2847 is generated from your input data. You are responsible for the accuracy of the data you provide. CRACheck does not replace a qualified professional assessment.

Your POS terminal processes payments in European stores. CRA documentation is mandatory. Generate it — 15 minutes, €149.

€149 one-time payment
8 professional documents · 15-25 minutes · No subscription · 100% in your browser
Generate CRA dossier — €149
✓ Last regulatory check: 1 May 2026 · No substantive changes detected · View history