Instant downloadAuditor-writtenSecure Stripe checkout
Cyber Resilience Act Documentation Pack – EU CRA Templates to Pinterest (opens in a new window)

Cyber Resilience Act Documentation Pack – EU CRA Templates

$99.00

74 editable templates for products with digital elements, written against a dated text – Regulation (EU) 2024/2847 as consolidated on 20 November 2024. Instant download, Microsoft Office format, one payment.

30-Day Money-Back Guarantee
Instant Download After Purchase
Secure Checkout via Stripe
Written by Certified Auditors

The Cyber Resilience Act is the first horizontal cybersecurity law for products. It does not care what sector you sell into: if your product has digital elements and connects to anything, it applies. Most Cyber Resilience Act documentation stops at the December 2027 date, and that is the wrong date to be planning against.

On this page:

Article 14 already applies, and it reaches products you sold years ago

Article 14 has applied since 11 September 2026. From that date a manufacturer that becomes aware of an actively exploited vulnerability in its product has 24 hours to file an early warning with the CSIRT coordinator and ENISA, 72 hours to file the notification, and 14 days after a fix is available to file the final report. A severe incident runs a parallel cascade with a different final-report deadline – one month from the notification, not 14 days from the fix.

Article 69(3) then applies that duty to products placed on the market before 11 December 2027. Article 69(2) says a legacy product only takes on the rest of the Regulation if it is substantially modified; Article 69(3) derogates, and the reporting obligations apply to all in-scope products already on the market, modified or not. That is the provision most manufacturers miss, because applies from 11 December 2027 reads as applies to what we ship next. A product you shipped in 2023 and no longer develop can generate a 24-hour reporting obligation.

The pack gives that its own document: a legacy product readiness assessment asking the only three questions that matter for reporting – can you detect it, can you report it, can you tell users – with worked examples including a discontinued product with no monitoring and no user channel, where the honest answer is a recorded acceptance of the exposure by top management.

What is inside the Cyber Resilience Act documentation pack

74 editable templates, each stating on its cover the consolidation date of the text it was written against.

  • Scope and classification – whether the Regulation applies, and whether the product is default, important class I or II, or critical.
  • Technical documentation – the Annex VII file, built as a structure rather than a checklist.
  • Essential requirements – Annex I Part I security properties and Part II vulnerability handling, as separate document sets.
  • Article 14 reporting – the 24-hour, 72-hour and final-report procedures, with the severe incident cascade kept separate from the vulnerability one.
  • Legacy products – the readiness assessment and the Article 69(3) position, with worked examples.
  • SBOM and vulnerability handling – the software bill of materials, the coordinated disclosure policy and the security update procedure.
  • Conformity assessment – the route decision under Article 32, including the notified body question.
  • Support period – the determination, its justification and the communication to users.
  • Economic operators – importer and distributor obligations, and the declaration of conformity.

Cyber Resilience Act documentation - editable Word and Excel templates from iso-toolkits.com

Every important product currently needs a notified body, and that is checkable

This is the finding that costs the most money and it is not visible from a plain reading of Annex III. Article 32(2) lets an important class I product self-assess only where harmonised standards, common specifications or a European cybersecurity certification scheme exist and are applied in full – or it pushes the product to a notified body where such instruments do not exist.

As at the date this pack was written, none existed. That was established on four checks: the EUR-Lex relationship queries on the Regulation record, the absence of the CRA from the Commission harmonised-standards index, a 404 at the expected per-instrument standards page, and a search for the CEN and CENELEC standardisation request. The middle two are the strongest, because the Commission opens a per-instrument standards page as soon as the first standard is cited.

Any Cyber Resilience Act documentation that assumes self-assessment for an important product is making a commercial assumption on your behalf. The pack states the position, dates it, and tells you how to re-check it yourself, because this is exactly the kind of fact that changes.

Who the Cyber Resilience Act documentation pack is written for

  • Manufacturers of any product with digital elements sold into the EU, in any sector.
  • Software vendors, including those whose product is delivered as a standalone application.
  • Importers and distributors with their own obligations under the Regulation.
  • Organisations with products already on the market that have not assessed their Article 69(3) exposure.

What the Cyber Resilience Act documentation pack does not do

It does not perform conformity assessment, and it cannot tell you whether a notified body will accept your file.

It is not an information security management system. This Cyber Resilience Act documentation sits alongside an ISMS rather than replacing it, and the overlap is marked so you do not write things twice.

It is not the medical device pack. Devices under MDR or IVDR have their own regime and their own article numbers.

Frequently asked questions

We only sell products we launched years ago. Does the CRA apply?

For the rest of the Regulation, generally only if substantially modified. For the Article 14 reporting obligations, yes – Article 69(3) applies them to in-scope products already on the market whether modified or not.

When do the main obligations apply?

11 December 2027. The reporting obligations in Article 14 have applied since 11 September 2026, which is the date most planning misses.

Do we need a notified body?

For default products, no. For important and critical products the Article 32 analysis decides it, and the availability of harmonised standards is the pivot. The pack sets out how to check the current position.

What formats are the files in?

Native Microsoft Word and Excel, fully editable, with placeholders marked throughout.

It sits alongside the ISO 27001 toolkit for the management system and the NIS2 toolkit where you are also an essential or important entity. Industrial products often need the IEC 62443 toolkit as well. The Commission publishes its CRA guidance at digital-strategy.ec.europa.eu.

Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.

Delivery, format and licence

The Cyber Resilience Act documentation pack downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is locked, nothing is a PDF you cannot edit, and no add-on or portal login is needed to open it. Every organisation-specific value is marked as a placeholder so you can see what still has to be decided.

One payment, no subscription and no annual renewal. The source files behind the Cyber Resilience Act documentation pack are yours to adapt for your own organisation for as long as you need them, including future revisions of your own documents.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Shopping Cart