Reg (EU) 2024/2847Generate dossier — €149
LIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

You develop software in the United States and sell licenses to European companies. Regulation (EU) 2024/2847 requires you to produce technical documentation under Article 31 and Annex VII before placing that product on the EU market. Your legal team does not need to read 81 pages — CRACheck structures the entire dossier from your product data.

The Cyber Resilience Act applies to all products with digital elements placed on the EU market, regardless of the manufacturer's country of establishment (Article 2(1)). If you develop downloadable software — a desktop application, a middleware component, a development tool, an on-premise enterprise solution — you are the manufacturer under Article 3(13). CRACheck generates the 8 documents required under Article 31 + Annex VII in 15-25 minutes for €149. All processing runs in your browser. Your source code and architecture data never leave your machine.

Generate CRA documentation — €149Free: check your product classification

€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side

Regulation (EU) 2024/2847 · Art. 31 + Annex VII · 8 documents · 100% browser-side — your data never leaves your device

Key numbers

8 documents
Complete technical dossier: classifier, documentation, risk assessment, user info, declaration, CVD, notification, calendar
2.5%
Maximum fine calculated on global annual turnover for non-compliance with Art. 13 obligations (Art. 64(2))
€149
One-time cost per product for the full Article 31 + Annex VII dossier

How CRACheck works

You enter your product data. CRACheck structures the documentation per Article 31 + Annex VII.

1
Enter product identity
Product name, version, manufacturer legal entity, contact details, EU authorized representative if applicable (Article 18).
2
Classify under Annex III
CRACheck walks you through the Annex III criteria to determine if your software is Default, Important Class I, Important Class II, or Critical. Desktop productivity software typically classifies as Default.
3
Describe architecture and components
Enter your tech stack, third-party libraries, open-source dependencies. CRACheck uses this to map your SBOM obligations and supply chain due diligence under Article 13(5).
4
Map against Annex I requirements
The tool checks your product against each essential cybersecurity requirement in Annex I, Part I (product security) and Part II (vulnerability handling processes).
5
Generate risk assessment
Structured cybersecurity risk analysis per Article 13(2)-(3), covering threats, attack vectors, and mitigations specific to your product type and deployment model.
6
Produce all 8 documents
Technical documentation (Art. 31 + Annex VII), declaration of conformity (Art. 28 + Annex V), user information (Annex II), CVD policy, ENISA notification template (Art. 14), and obligations calendar.
7
Download ZIP
8 PDFs ready for your compliance folder, your EU distributor, or your customer's procurement team.

Common mistakes

FRAMEWORK MISMATCH

"We already comply with US cybersecurity frameworks, so CRA should be covered"

NIST CSF, CMMC, and FedRAMP address organizational and service security. The Cyber Resilience Act requires product-specific technical documentation under Article 31 + Annex VII, a per-product cybersecurity risk assessment under Article 13(2)-(3), and a formal EU declaration of conformity under Article 28 + Annex V. These are distinct legal instruments with distinct content requirements. US frameworks do not produce CRA-compliant documents.

DELEGATION LIMIT

"We will appoint an EU authorized representative and let them handle documentation"

Article 18(2) explicitly states that the obligations under Article 13(1)-(11) — including technical documentation, risk assessment, and conformity procedures — "shall not form part of the authorised representative's mandate." The authorized representative holds documents and cooperates with authorities. The manufacturer produces the documents. You cannot delegate the documentation obligation.

SCOPE ERROR

"Our product is B2B-only, so consumer protection regulations do not apply"

The Cyber Resilience Act is not a consumer protection regulation. Article 2(1) covers all products with digital elements placed on the EU market with a direct or indirect data connection, regardless of whether the end user is a consumer or an enterprise. B2B software is fully within scope.

What the ZIP contains

8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.

1

Product Classifier

Determines your software's category under Annex III. Identifies whether you qualify for self-assessment (Module A) or require third-party evaluation (Module B+C or Module H).

2

Technical Documentation

Article 31 + Annex VII dossier structured for a US-developed software product: architecture description, design decisions, development processes, third-party component inventory, and conformity assessment path.

3

Risk Assessment

Per Article 13(2)-(3) and Annex I, Part I. Covers the specific threat landscape of your software product: data exfiltration, unauthorized access, supply chain compromise, update integrity, and residual risks.

4

User Information

Annex II document with manufacturer identity, security update policy, known residual risks, secure deployment instructions, and SBOM reference. Formatted for inclusion in your product documentation.

5

Declaration of Conformity

Article 28 + Annex V. The formal statement that your product meets CRA essential requirements. Pre-filled with your legal entity, product data, and applicable conformity modules.

6

CVD Policy

Coordinated vulnerability disclosure policy per Annex I, Part II. Defines intake channel, response timelines, and researcher communication protocol. Required for all manufacturers.

7

Notification Template

ENISA notification structure per Article 14: 24h early warning, 72h vulnerability notification, and 14-day final report. Adaptable to your incident response workflow.

8

Obligations Calendar

Key dates for your product: Art. 14 reporting active from September 2026, full CRA enforcement December 2027, support period calculation per Article 13(8).

Mira antes de comprar — Descargar dossier de muestra (PDF, empresa ficticia) — Estructura real, artículos reales, formato real. Datos ficticios.

Generated from your data, in your browser. No data leaves your device.

What you pay

🧾 IN-HOUSE LEGAL TEAM
$36,000–$100,000
120-200 attorney hours at $300-$500/h. 3-6 months. Output: untested internal documents that may not match the structure EU authorities expect.
✓ Last regulatory check: 1 May 2026 · No substantive changes detected · View history