A compromised smart lock opens a physical door. The cybersecurity requirements of Annex I intersect with physical security for this product category. Annex III point 17 classifies smart door locks as Important Class I. If harmonised standards are not fully applied, Article 32.2 requires conformity assessment by a notified body. CRACheck generates the technical documentation under Annex VII: 8 PDFs, 15-25 minutes, €149. Browser-side.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
You enter your product data. CRACheck structures the documentation per Article 31 + Annex VII.
Annex I Part I point 1(a) requires protection of confidentiality, integrity, availability and authenticity. Encryption of stored credentials is one element. The CRA also requires secure authentication, protection against unauthorized access, secure firmware updates and resistance to denial-of-service. AES-128 on stored PINs does not cover the full surface.
Annex I Part II requires ongoing vulnerability handling — not one-time patching. You must identify, document, address and remediate vulnerabilities without delay throughout the support period.
Annex I Part I point 1(d) requires secure by default configuration. A universal default PIN of 0000 is the exact pattern the CRA targets. Your lock must ship with unique default credentials or force credential setup before first use.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Class I confirmation per Annex III point 17.
Art. 31 + Annex VII. Covers authentication architecture, credential storage, encryption, BLE/WiFi security, firmware update mechanism.
Art. 13.2-13.3. Includes unauthorized physical entry, credential theft, replay attacks, brute force, jamming.
Annex II. Secure setup, master code management, battery replacement, vulnerability reporting, secure disposal (credential wipe).
Art. 28 + Annex V.
Critical for access control products. Clear reporting channel and response timeline.
Art. 14. A vulnerability in a smart lock is a high-severity incident. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.
CRA dates plus support period for the lock.
See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.
Generated from your data, in your browser. No data leaves your device.
Generates the Annex VII documentation for your smart lock. Covers authentication, encryption, credential management, vulnerability handling. Ready for notified body review.
CRACheck does not perform penetration testing, brute-force resistance testing or physical security assessment. A smart lock needs both documentation and security testing. CRACheck handles the documentation layer.
We document. You secure the lock.
Article 64 of Regulation (EU) 2024/2847.
Art. 64.2.
Art. 64.3.
Art. 64.4.
| Criterion | Security certification lab | Self-assess under Module A (incorrect for Class I) | Wait for EU buyer to enforce | CRACheck |
|---|---|---|---|---|
| Cost | €15,000–€30,000 | €0 | €0 | €149 |
| Result | Docs + pentest. 4-8 months. | Non-compliant. Notified body required without harmonised standards. | Lose the tender. Hotels will buy from compliant competitors. | 8 docs. 15 min. Documentation ready. Security testing separate. |
Each lock model with different firmware, authentication methods or connectivity needs its own Annex VII dossier. Volume pricing: €99/product (10-pack), €79/product (30-pack).
Request Volume PricingCRACheck generates a structured document according to Article 31 and Annex VII of Regulation (EU) 2024/2847 from the information you provide. The accuracy, completeness and truthfulness of that information is your responsibility as the manufacturer.
We guarantee that the document structure follows Article 31 and Annex VII of Regulation (EU) 2024/2847 and that the legal references cited are correct. We do not guarantee that a specific document will be accepted by a market surveillance authority in a specific case or by a commercial buyer in a procurement process.
CRACheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.
Eight documents. Article 31 + Annex VII fully structured. Regulation (EU) 2024/2847. Your data stays on your device. The ZIP you download is yours forever.