Findings register
Visible gaps with evidence references, severity and a closure route.
For manufacturers of digital products: we clarify scope, review existing evidence and structure the next steps.
You get a findings register, a prioritised action plan and structured technical evidence you can review with your team.
Our engagements turn open compliance questions into concrete working documents. Scope and deliverables are agreed before work begins.
Visible gaps with evidence references, severity and a closure route.
Sequenced actions, owners and review points for the work ahead.
A clear file structure for the documents your product actually needs.
Answer them and the page tells you where you probably stand: out of scope, in scope as a distributor, or in scope as a manufacturer — and how heavy the work is likely to be.
Software, network interfaces and components obtained from other manufacturers are what turn a physical product into a product with digital elements — the subject of the questions below.
Question 1 of 3
This is an orientation, not a classification decision. Category assignment under Annex III depends on the product's intended purpose and is documented in the technical file; we confirm it in writing before any other work starts.
Start with the question that matters most. Each service names the problem, the deliverable and the next decision.
Not a slide deck. A register in which every requirement has a state, an owner and a piece of evidence — or an explicit note that the evidence does not exist yet.
Architecture, release process, existing security documentation, SBOM if it exists, vulnerability handling, support commitments.
Annex I Part I against the product, Part II against the process. Each line gets one of four states: met, partially met, missing, not applicable.
Every gap written so that an engineer can act on it and an auditor can verify it. Severity, evidence, closure route, effort.
Sequenced by what blocks CE marking first, not by what is easiest. With named owners and review dates.
| ID | Requirement | State | Severity |
|---|---|---|---|
| I-04 | Secure default configuration, ability to reset to a secure state | Partly met | High |
| I-07 | Security updates available for the support period | Met | — |
| I-09 | Limitation of attack surface, including external interfaces | Missing | High |
| II-02 | Vulnerability handling process with coordinated disclosure | Missing | Critical |
| II-05 | Software bill of materials, maintained per release | Partly met | Medium |
Findings are written against the regulation's own wording. Where a requirement does not apply to your product, that is recorded too — a documented non-applicability is worth as much as a fix.
This is a gap analysis while it runs: every requirement is assessed, the findings are marked, then they are closed. The 28 checks illustrate a sample register, not the number of legal requirements or a real product.
Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents. The clock starts when you become aware — not when the fix ships.
Timings per Article 14 of Regulation (EU) 2024/2847. Administrative fines for missing the 24-hour deadline do not apply to micro and small enterprises — the reporting duty itself still does.
Plus two long-running obligations: a support period of at least five years unless the product's lifetime is shorter, and a software bill of materials that is maintained — not generated once for an audit.
The same requirement set applies to everyone in scope. What changes with the category is how you have to prove conformity — and who has to look at it.
| Category | Where it is defined | Typical assessment route |
|---|---|---|
| Default products | All products with digital elements not listed in Annex III or IV | Internal control — self-assessment against Annex I, documentation, CE marking |
| Important · Class I | Annex III | Self-assessment against harmonised standards, or third-party assessment where those standards are not applied |
| Important · Class II | Annex III | Third-party conformity assessment |
| Critical | Annex IV | European cybersecurity certification or a full third-party assessment |
Category is assigned on the basis of the product's intended purpose, and can change if the intended purpose changes. It is one of the first things we put in writing, because it drives the timeline, the cost and who signs off.
Depending on the agreed scope, we prepare the documents below for your team to use and maintain. We agree which are included before work starts.
We believe effective compliance starts with understanding the engineering itself.
Engineering experience gives us the context. Risk-based thinking gives us the method. Compliance and cybersecurity give us the focus.
Article 14 reporting also covers in-scope products placed on the market before 11 December 2027. Other CRA requirements apply to those products if they undergo a substantial modification from that date (Article 69(2)–(3)).
A single-customer contract does not in itself exclude software from the CRA. We check market supply, connectivity and the specific exclusions in Article 2; remote data processing can also be part of a product.
With the intended purpose and the interfaces. Which digital elements are part of the product you place on the market, and which are components obtained from others? That split decides your obligations and your evidence.
It creates a presumption of conformity for the requirements it covers. Without applicable harmonised standards, the route may change, particularly for Class I products — which is why category and standards availability are checked before documentation starts.
We write the file, but not the facts. Documentation without real evidence fails the first serious audit — worse than having none. So we make the gap visible, sequence the closures, and build the file to hold up.
Timing depends on the product scope, available evidence and access to your team. We agree milestones and deliverables before the engagement starts.
In an initial conversation, we review your product, its intended use and your current questions. Together we define what needs closer assessment and agree the scope of the next step.
The company is being established. The contact address is not yet available. You can prepare and copy an enquiry here; nothing is sent.
The recipient address is still being confirmed. You can copy your details and use your usual contact route.