Retail technology manufacturers have operated under PCI-DSS for payment terminals and GDPR for customer data. The CRA adds a horizontal product cybersecurity layer. Art. 2(1) covers any product with a logical or physical data connection — POS terminals with Ethernet and Wi-Fi, self-checkout kiosks with network connectivity, RFID inventory scanners with cloud sync, electronic shelf labels with wireless gateways. Most retail hardware falls under Default classification. If your POS terminal includes identity management or access control functionality, Annex III Class I item 1 may apply. If it includes an embedded operating system, Annex III Class I item 11 applies. Art. 13 imposes manufacturer obligations regardless of PCI-DSS compliance status. CRACheck generates the 8-document technical file under Art. 31 and Annex VII. €149 per product. 15-25 minutes. Store network architecture stays in your browser.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
PCI-DSS is a payment card industry standard governing cardholder data environments. The CRA (Regulation (EU) 2024/2847) is an EU regulation governing product cybersecurity. PCI-DSS does not produce Art. 31 documentation, does not require ENISA reporting, does not mandate vulnerability handling processes per Annex I Part II, and does not cover non-payment retail hardware (inventory scanners, ESL systems, signage). The two frameworks are complementary, not substitutive.
Annex III Class I item 11 of Regulation (EU) 2024/2847 lists "operating systems." If your POS terminal runs a custom or embedded operating system (Android-based, Linux-based, proprietary RTOS), that OS component may trigger Important Class I classification. This affects the conformity assessment route under Art. 32(2).
Art. 13(2) of Regulation (EU) 2024/2847 requires the risk assessment to cover reasonably foreseeable use. A POS terminal is foreseeably deployed as one of dozens or hundreds across a retail chain. A vulnerability affecting the firmware of all terminals in a chain is a chain-wide risk — the risk assessment must account for aggregate deployment scale.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Identifies Default (standard scanners, ESL controllers) or Important Class I (POS with embedded OS per Annex III item 11, devices with identity management per item 1, network management per item 6).
Art. 31 and Annex VII documentation: device architecture, payment integration layer, wireless connectivity, cloud platform integration, firmware structure, SBOM.
Cybersecurity risk assessment covering retail vectors: POS firmware compromise, store network lateral movement, inventory data manipulation, customer data interception at kiosks, chain-scale firmware update attacks.
Annex II information for retail IT departments and franchisees: secure deployment, PCI environment integration, employee access provisioning, firmware update procedures, vulnerability reporting, support period.
EU Declaration per Art. 28 and Annex V.
Coordinated vulnerability disclosure policy for retail technology research community.
ENISA notification template per Art. 14 with retail chain-scale context.
Key dates with retail procurement cycles: Art. 14 from September 2026, full enforcement December 2027, retail store refresh windows.
See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.
Generated from your data, in your browser. No data leaves your device.
CRACheck generates Art. 31 and Annex VII technical documentation for each connected retail device. Coverage includes cybersecurity risk assessment for retail deployment, vulnerability handling procedures, SBOM, coordinated disclosure, ENISA template and support period definition. The documentation covers the CRA layer that PCI-DSS does not address — and positions your product for retail chain procurement.
CRACheck does not perform PCI-DSS compliance assessments. It does not conduct penetration testing on POS terminals. It does not audit payment data flows. It does not manage firmware update delivery infrastructure. It does not certify EMV compliance. For POS terminals, CRACheck covers the CRA product cybersecurity layer — PCI-DSS, EMV and payment scheme requirements are separate workstreams.
PCI covers the card data. The CRA covers the product. CRACheck documents the product layer for every connected device in the store.
A vulnerability in POS firmware deployed across a retail chain triggers 24h ENISA notification. Chain-scale deployment multiplies both urgency and impact.
Retail hardware placed on the EU market must carry CE marking and Art. 31 documentation. Retail chain procurement will require CRA evidence alongside PCI.
For retail hardware manufacturers non-compliant with Art. 13 or Annex I. Separate from any PCI-DSS consequences — a compromised POS chain may trigger both.
| Criterio | Retail IT security firm | Internal compliance | PCI-DSS only | CRACheck |
|---|---|---|---|---|
| Price | €10K-25K | Staff time | Does not cover CRA | €149 per device |
| CRA Art. 31 file | No — report | Variable | None | 8-document ZIP |
| Retail chain procurement evidence | Audit report | Internal docs | PCI report | Standardised Art. 31 file |
| POS architecture stays with you | Shared | Internal | Shared with QSA | 100% browser-side |
| CRACheck | €149 | 8-doc | Art. 31 | Browser-side |
Pack 10: €99 per product. Pack 30: €79 per product. For retail technology manufacturers with broad EU product portfolios, contact us for enterprise pricing.
Request volume pricingCRACheck generates a structured document set according to Art. 31 and Annex VII of Regulation (EU) 2024/2847 based on the information you provide about your retail device. The accuracy of device architecture, payment integration details and connectivity specifications is your responsibility as manufacturer.
We guarantee that the document structure follows Art. 31 and Annex VII and that the legal references cited are correct. We do not guarantee acceptance by a retail chain procurement process, PCI QSA or market surveillance authority.
CRACheck is not legal advice. For the CRA/PCI-DSS interaction and embedded OS classification under Annex III item 11, consult a qualified retail technology compliance specialist.
POS terminals, self-checkout kiosks, inventory scanners, ESL controllers. Every connected retail device needs Art. 31 documentation. Eight documents. €149 per device. Browser-side.