Digital work tools for businessesTemplates · Practice Kits for businesses
Cyber Resilience Act · Practical work tools for manufacturers

Implementing the Cyber Resilience Act (CRA) - Practice Kit

Work through the CRA in a structured way with the Practice Handbook, Master Checklist, 44 work tools, Cockpit and editable target documents for technical documentation, information and instructions to the user, and conformity preparation.

  • The central CRA Master Checklist in the Cockpit links main review points, completion criteria, work tools and evidence status
  • 44 editable work tools plus Practice Handbook, Navigator, Practical Task Guide, Customer Situation Response Guide, Cockpit, Quality Checks and a coherent worked example
  • Use editable target documents for the technical dossier, information and instructions to the user, and conformity preparation
44 Work tools1 CRA Cockpit3 Target documents4 AI assistants
Product at a glance

Implementing the Cyber Resilience Act (CRA) in practice: Master Checklist, risks, SBOM, evidence and technical documentation

Work through the Cyber Resilience Act for products with digital elements in a practical way: clarify scope and roles, maintain the central Master Checklist, document cybersecurity risks and SBOM/VEX, manage vulnerabilities and incidents, and consolidate results in a technical CRA/Product Cybersecurity Dossier.

Legal basis: Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act), OJ L, 2024/2847, 20 November 2024.

Product typeDigital B2B Practice Kit
Target usersManufacturers and responsible teams for products with digital elements
File formatsPDF · DOCX · XLSX · HTML · MD · JSON · ZIP
DeliveryDigital delivery through CopeCart after successful purchase
ProviderSP Services GmbH
Price€399.00 incl. VAT

What is the CRA Practice Kit?

A structured work system consisting of the Practice Handbook, Navigator, Practical Task Guide, Master Checklist, 44 work tools, Cockpit, Quality Checks, worked example and editable target documents.

What task does it support?

Work through CRA tasks from scope and roles through requirements, risks, components, SBOM/VEX and incidents to technical documentation and conformity preparation.

What is not included?

No legal advice, certification, technical assessment, production SBOM or automatic confirmation of conformity.

For manufacturers of products with digital elements

What this product helps you achieve

Bring CRA work into a controlled work status using the Master Checklist, work tools, Cockpit, Quality Checks and editable target documents.

Typical starting point

CRA information, evidence and approval status are spread across the organisation

CRA-relevant product information, roles, requirements, risks, components, vulnerabilities, incidents and evidence are often distributed across different teams and files. Without a central review logic, open items, evidence and approval status are difficult to trace.

Outcome after working through the kit

Controlled CRA work status with Master Checklist and target documents

The Master Checklist, TASK_INDEX, 44 work tools, Cockpit status, the WT-07 baseline with 80 prefilled CRA review requirements and editable target documents bring tasks, requirements, evidence and approval together.

Clarify scope, product boundary, economic-operator role and supply path

Document the product boundary, digital elements, economic-operator role and supply path in a traceable way.

Control the Master Checklist, requirements, gaps and verification

Maintain a case-specific review overview with completion criteria, evidence status and linked work tools.

Connect risks, components, SBOM and VEX

Connect product-security tasks, cybersecurity risks, supplier, component, SBOM and VEX information in a structured way.

Control vulnerabilities, incidents and technical documentation

Bring vulnerability management, updates, incidents, reporting, evidence and technical documentation together through conformity preparation.

REQUIREMENTS & TASKS

Which tasks you can work through with this Practice Kit

From the relevant timing and scope/role questions through risks, components, SBOM/VEX, vulnerabilities and incidents to technical documentation and authority requests: the work tools bring the concrete CRA tasks together in a structured way.

When does the CRA need to be considered?

Art. 71

Clarify which CRA milestones are relevant to your product case and which preparatory work is required now.

Use: Master Checklist, WT-05 and WT-07; WT-01 to WT-04 as needed for the product/case baseline.

Outcome: A dated, traceable starting point with visible open questions, responsibilities and freshness checks.

Does the product fall within the CRA and what is your role?

Scope & roles

Document the product boundary, digital elements, scope/applicability, economic-operator role and supply path in a traceable way.

Use: WT-01, WT-05 and WT-06; WT-02 to WT-04 as needed for variants, responsibilities and stakeholders/suppliers.

Outcome: Documented scope and role/supply-path status with visible open specialist questions.

Which product and cybersecurity requirements apply?

Requirements

Review the prefilled CRA requirements for the concrete case and connect requirement applicability, product-security requirements, verification/evidence, gaps and actions.

Use: WT-07 to WT-11; WT-07 contains 80 prefilled CRA review requirements.

Outcome: Requirements/applicability status with verification planning, transparent gaps, actions, owners and dates.

How are cybersecurity risks addressed?

Risk

Work through assets, threat and misuse scenarios, risks, treatments and residual risks for the product case in a structured way.

Use: WT-12 to WT-17 and the coherent worked example.

Outcome: Documented risk treatment with traceable residual-risk and approval logic.

How are components, SBOM and VEX managed?

Components

Manage components, supplier information, SBOM/validation status, VEX evidence, open-source and third-party components in a connected way.

Use: WT-18 to WT-22.

Outcome: Traceable component, supplier, SBOM and VEX work status.

How are vulnerabilities, updates, support and incidents controlled?

Vulnerabilities

Link vulnerability management, triage, CVD, security updates, support/end-of-support and incident/reporting work with responsibilities and evidence.

Use: WT-23 to WT-36.

Outcome: Controllable work status for vulnerabilities, updates, support, incidents and reporting.

How are technical documentation, evidence, release and reassessment brought together?

Dossier

Bring evidence/traceability, technical documentation, change/reassessment, internal release preparation and conformity preparation into controlled work states and editable target documents.

Use: WT-37 to WT-42 plus the three target documents; keep future-state optimisation options separate in WT-44 where needed.

Outcome: Reviewable documentation, release and reassessment status with visible open items and specialist reviews.

How are authority requests prepared?

Authorities

Record concrete authority/market-surveillance requests, assemble approved evidence and document the response, submission/receipt and follow-up.

Use: WT-43 together with WT-37 and WT-39; use WT-34 for communication events where useful.

Outcome: Versioned, traceable response and evidence status.

PACKAGE CONTENTS

What is included in the package

Work tools, guidance, worked examples, Quality Checks and AI assistants are connected through common references.

44 editable work tools

DOCX · XLSX

Editable specialist work tools for central CRA tasks; WT-07 contains a baseline with 80 prefilled CRA review requirements.

  • 16 Word work tools
  • 28 Excel work tools
  • shared IDs, status and evidence references

Practice Handbook, Navigator & practical guides

PDF · HTML

Methodical entry, case-specific navigation and practical execution along the eight-stage CRA Work Process.

  • CRA Navigator for the case-specific work path
  • Practical Task Guide with 18 concrete customer tasks
  • Customer Situation Response Guide for 7 typical situations

Coherent worked example

DOCX · XLSX · PDF · JSON

SecureEdge Gateway 200 as a fictional coherent worked example with 44 completed work tools, an SBOM example and a Guided Worked Example Walkthrough.

  • 44 completed worked-example work tools
  • 5 guided SecureEdge work chains
  • SBOM example as a machine-readable JSON file

CRA Cockpit & Master Checklist

XLSX

Maintain the case-specific work path, central Master Checklist, task navigation and consolidated work status.

  • PATH for activated work tools and work status
  • MASTER_CHECKLIST with example and evidence status
  • TASK_INDEX from 18 customer tasks to work tools, outcome, evidence and next step

7 Quality Checks

XLSX

Internal checks for completeness, plausibility, cross-references and open decisions.

  • one Quality Check for each Work Area A-G
  • make gaps visible
  • specialist and approval decisions remain with the user

4 AI assistants

MD

Navigation and Explanation, Working and Completion, Review/Consistency/Error Analysis, and Questions/Gaps/Clarification – each as a self-contained, system-neutral assistant file.

  • one assistant file per task type
  • use together with the concrete working file
  • system-neutral and locally storable
PRODUCT PREVIEW

Insights into the actual work tools

Start Here guide and a SecureEdge Gateway 200 worked example
Start Here guide and a SecureEdge Gateway 200 worked exampleStart the work path with the Practice Handbook, Navigator and a coherent worked example.
CRA Practice Kit overview and Master Checklist example
CRA Practice Kit overview and Master Checklist exampleReview central CRA points, work status and completion criteria in one connected overview.
CRA requirements, applicability and cybersecurity risk assessment
CRA requirements, applicability and cybersecurity risk assessmentConnect applicable requirements, product-security work and risk assessment for the concrete case.
Components, SBOM and VEX worked examples
Components, SBOM and VEX worked examplesConnect component and supplier information with SBOM and VEX work status.
EU Declaration of Conformity under Annex V
EU Declaration of Conformity under Annex VUse the controlled draft as part of documented conformity preparation.
Connected rather than isolated

Eight stages from the CRA case to a controlled work status

The Practice Handbook, Navigator, TASK_INDEX, work tools, evidence and target documents guide you through eight connected work stages. New findings may trigger targeted reassessment and the reopening of affected work states.

All results remain subject to specialist review and approval. The kit does not make a conformity or product decision.

Stages 1–2 · Start and scope the case

Start the CRA caseCreate the product/case baseline and open the work status.
Clarify scope, role and supply pathDetermine the case, product, product boundary, economic-operator role and supply path in a traceable way.
The product case and its scope/role framework are documented in a traceable way.

Stages 3–4 · Structure requirements and specialist work

Determine requirements and product securityStructure requirement applicability, security requirements, verification and evidence.
Address gaps, risks, components, suppliers, SBOM and VEXManage open items and risk, supply-chain and component work states in a connected way.
Requirements, treatments, responsibilities and open evidence are visible.

Stages 5–6 · Control vulnerabilities and incidents

Vulnerabilities, updates and supportWork through triage, CVD, security updates, support and end-of-support in a controlled way.
Incidents and reporting when triggeredTrace first signal, assessment, reporting decision, communication and closure.
Operational vulnerability, update, support and incident work states are documented in a controlled way.

Stages 7–8 · Evidence, release and reassessment

Documentation, evidence and conformity preparationConsolidate traceability, technical documentation and target documents.
Review management/release and activate reassessmentDocument release/hold/no-release rationale and keep reassessment triggers visible.
A controlled work, evidence and decision status with active reassessment is available.
Coherent structure A-G

Seven Work Areas for central CRA tasks

Each Work Area brings together the relevant work tools, Work Instructions, completed worked-example files and one Quality Check.

Work Area A – Product, Scope, Role & Supply Path

Work Area A

Product and Scope Record, variants/versions, internal roles, stakeholders/suppliers, scope/applicability and economic-operator/supply-path decisions.

  • Product and scope
  • Roles and supply path
  • Variants, stakeholders and suppliers

Work Area B – Requirements, Secure Development, Gaps & Actions

Work Area B

Requirements/Applicability Matrix, Product Security/Verification Plan, Gap Analysis, actions/priorities and responsibility/schedule control.

  • Requirements & applicability
  • Product security & verification
  • Gaps, actions, owners and dates

Work Area C – Cybersecurity Risks

Work Area C

Assets, protection needs, threat and misuse scenarios, risk assessment, treatment and residual-risk approval.

  • Assets and threats
  • Risk assessment and treatment
  • Residual risks and approval

Work Area D – Components, Suppliers, SBOM & VEX

Work Area D

Component Inventory, SBOM Preparation and Validation, VEX Status/Evidence, Supplier Security/Evidence and open-source/third-party components.

  • Components and SBOM
  • VEX and evidence
  • Suppliers, open source and third-party components

Work Area E – Vulnerabilities, Updates & Support

Work Area E

Vulnerability management, triage, CVD, security update/patch process, update release decision, support period, end-of-support and Security Advisory.

  • Vulnerabilities and triage
  • Security updates and CVD
  • Support and end-of-support

Work Area F – Incidents & Reporting

Work Area F

First signal/awareness, incident assessment, CRA reporting readiness, communication/receipt log, closure and lessons learned.

  • Incident assessment
  • Reporting and communication
  • Closure and process review

Work Area G – Technical Documentation, Evidence, Release & Reassessment

Work Area G

Evidence/Document Index, Requirement-Test-Evidence traceability, technical documentation, change/reassessment, internal product release decision, conformity preparation and authority response.

  • Evidence, tests and technical documentation
  • Release and conformity preparation
  • Change, reassessment and authority response
AI SUPPORT WITHOUT MULTI-FILE CHAOS

4 AI assistants

For one task, load exactly one assistant file together with the concrete working file into an internally approved AI system. The assistants support the work but do not make specialist or legal approval decisions.

Navigation and Explanation

Identify the appropriate entry point, relevant work stage, required work tools and next concrete steps in the Practice Kit and explain the relationships.

Working and Completion

Transfer supported information into the concrete working file in a structured way, keep assumptions and open items visible, and support completion.

Review, Consistency and Error Analysis

Review completeness, consistency, cross-references, evidence links and identifiable errors or open decisions.

Questions, Gaps and Clarification

Structure and prioritise missing information, evidence, specialist questions and clarification needs.

Recommended sequence

Get started in a few steps

Work with a copy, keep product states unambiguous and use the Navigator, Practical Task Guide, work tools, worked example and Quality Checks as one controlled work chain.

  • 1

    Read the CRA Practice Handbook and determine the current work stage.

  • 2

    Use the CRA Navigator and Cockpit/PATH to determine the case-specific work path and relevant work tools.

  • 3

    Open TASK_INDEX in the Cockpit and select the task matching the current work step.

  • 4

    Work through the task using the CRA Practical Task Guide and the relevant Work Instructions.

  • 5

    Use the activated work tools as the primary working and evidence records.

  • 6

    If the linkage or creation logic is unclear, use the Guided SecureEdge Worked Example Walkthrough – do not copy the example values.

  • 7

    Transfer approved results into evidence, traceability and the relevant target documents.

  • 8

    Complete the Quality Checks, release and reassessment; keep open specialist or freshness checks visible.

Suitable for

  • Manufacturers of machinery, devices and components
  • Manufacturers whose products include firmware, apps, web interfaces, interfaces/APIs or remote maintenance
  • Software providers and companies using externally developed product software
  • Product management, engineering, CE/compliance, product security, procurement, service and project management

Prerequisites

  • Microsoft Word and Excel or compatible office software
  • PDF viewer
  • product-specific information, evidence and decisions
  • competent people for review and approval
  • optional: internally approved AI system with file upload

Not included

  • legal advice or binding CRA classification
  • certification or formal conformity assessment
  • technical architecture, source-code or security assessment
  • penetration testing, production SBOM or automated monitoring
  • review or approval of completed customer documents
  • automatically included future major versions
Related options

Further Practice Kits and individual support

Individual CRA analysis and support

Product scoping, readiness and gap analysis, and prioritised action planning are not included in the product price.

Request individual support →
Transparent before purchase

Availability, licence, support and updates

Company licence

Perpetual internal use and editing within the named legal entity. Your own substantially adapted work results may be shared for their intended purpose; blank original templates and AI assistant files may not be passed on.

Standard support

Support for download, file access, package structure and reproducible technical product errors. No individual legal, specialist or security advice.

Version and updates

You purchase the product version identified in the checkout. Later major versions, additional content and regulatory-status updates are included only where this is expressly stated.

Frequently asked questions

Questions answered before purchase

For further technical questions about the product, contact us at digitalprodukte@sp-services-gmbh.de

Is the CRA Practice Kit a certification?+

No. It is a digital work and documentation package. It does not confirm CRA conformity of a product or a professional qualification of the user.

Does completing all templates guarantee CRA conformity?+

No. The templates support structuring and documentation. Whether requirements are met depends on the concrete product, the measures and tests actually implemented, and the responsible decisions.

Is the kit only suitable for software manufacturers?+

No. It is also designed for manufacturers of machinery, devices, controllers, test equipment, industrial components and other technical products with digital functions.

Are the files editable?+

Yes. The working templates are provided in editable Word and Excel formats. A SecureEdge Gateway 200 SBOM example is provided as a machine-readable JSON file.

How do the AI assistants work?+

Select one of the four assistants, upload its Markdown file together with the concrete working file into your internally approved AI system, and give it a short task. Additional prompt or role files are not required for standard use.

Is an AI system included in the price?+

No. The product contains system-neutral assistant files. Selection, approval, cost and data protection for the AI system used remain the customer's responsibility.

Is an SBOM for our concrete product included?+

No. The kit contains work tools for component inventory, SBOM preparation and validation, plus a SecureEdge Gateway 200 SBOM example. A production SBOM is not generated automatically.

Does SP Services review completed documents?+

No. Individual review, approval or gap analysis is not included in the product price and can only be agreed as a separate service.

May several employees work with the kit?+

Yes. The company licence allows internal use by employees and commissioned persons of the named licensee.

Can the kit be used for several of our own products?+

Yes. The licensee may use the kit for several of its own products, product variants and internal projects.

May affiliated companies also use the kit?+

Not automatically. The licence applies to the named legal entity. Other legally independent entities generally require their own licence.

May completed documents be shared with customers or assessors?+

Yes, where they are your own substantially adapted work results and sharing is required for your own products or procedures. Blank original templates and AI assistant files may not be passed on.

Are later updates included?+

You purchase the product version identified in the checkout. Later major versions and regulatory-status updates are included only where this is expressly stated.

What support is included in standard support?+

Support for download, file access, package structure and reproducible technical product errors. Individual legal, specialist or security advice is not included.

Can I buy as a private individual?+

No. The product is intended exclusively for entrepreneurs and organisations in the B2B sector.

What technical documentation does the CRA Practice Kit support?+

The kit supports technical documentation with an Evidence/Document Index, Requirement-Test-Evidence Matrix, Completeness Record and an editable technical CRA/Product Cybersecurity Dossier aligned to Annex VII. Which content is required for the concrete product case and whether the evidence is technically sufficient must be reviewed and approved for the specific product.

How does the kit support CRA vulnerability management and reporting processes?+

The work tools connect the vulnerability register, triage, coordinated vulnerability disclosure, security updates, support/end-of-support decisions, incident escalation and CRA reporting assessment. Whether a concrete event is reportable remains a case-specific specialist and legal decision.

How does the kit prepare CRA conformity assessment?+

The kit brings together requirements, tests/evidence, technical documentation, product changes and internal release decisions, documents conformity preparation and includes a controlled draft EU Declaration of Conformity under Annex V. It does not itself perform a formal conformity assessment and does not establish CRA conformity.

English edition

Implementing the Cyber Resilience Act (CRA) - Practice Kit

Work through the CRA in English with the current digital Practice Kit. All binding purchase and delivery information is available in the CopeCart checkout.

Buy now
CRA Practice Kit€399.00 incl. VAT
Buy now