Threatstealth
EU CRA 2026-04-29 16 min read

EU CRA Policy & Procedure Register — 48 Documents Across 7 Domains

Master register of the 48 policies and procedures required by the EU Cyber Resilience Act, organised across 7 domains, with owner, priority, and the controlling CRA reference for each.

Threatstealth Compliance Research

Most CRA non-conformities discovered during pre-audit are not engineering failures — they are missing or stale documents. This register lists the 48 policies and procedures that a manufacturer of a product with digital elements is reasonably expected to maintain, organised across the seven domains that the CRA's essential requirements (Annex I), conformity-assessment procedures (Annex VIII), and reporting obligations (Article 14) collectively demand.

Use the priority column to sequence work: P1 documents must exist before placing the product on the market; P2 documents must exist within the support period; P3 documents are good service practice and reduce audit friction.

Domain A — Governance (P-01 → P-08)

IDDocumentOwnerPriorityCRA reference
P-01CRA Programme Charter & Scope StatementCISO / Head of Product SecurityP1Art. 13(1)–(2)
P-02Roles & Responsibilities (RACI) for CRA ComplianceCISOP1Art. 13 (general)
P-03Cybersecurity Risk Management PolicyHead of RiskP1Annex I §1(1)
P-04Acceptable Use & Code of ConductHR / CISOP2Annex I Part II §(3)
P-05CRA Training & Awareness ProcedureCISO / People OpsP2Annex I §1(1)
P-06Internal Audit & Management Review ProcedureInternal AuditP2Art. 13(11)
P-07Records Retention & Evidence Lifecycle PolicyDPO / CISOP1Art. 13(11)
P-08Document Control & Versioning ProcedureQuality ManagerP2Annex VII §(2)

Domain B — Secure Development (P-09 → P-15)

IDDocumentOwnerPriorityCRA reference
P-09Secure Development Lifecycle (SDLC) PolicyVP EngineeringP1Annex I §1(1)
P-10Threat Modelling ProcedureSecurity ArchitectP1Annex I §1(1)
P-11Secure Coding Standards (per language / runtime)Engineering LeadP1Annex I §1(2)(a–l)
P-12Code Review & Pull-Request Security GateEngineering LeadP1Annex I Part II §(3)
P-13Application Security Testing Procedure (SAST/DAST/IAST)AppSec LeadP1Annex I Part II §(3)
P-14Cryptography & Key Management StandardSecurity ArchitectP1Annex I §1(2)(e)(f)
P-15Secure-by-Default Configuration BaselineProduct ManagerP1Annex I §1(2)(b)

Domain C — Vulnerability Management (P-16 → P-22)

IDDocumentOwnerPriorityCRA reference
P-16Vulnerability Management PolicyCISOP1Annex I Part II §(2)
P-17Coordinated Vulnerability Disclosure (CVD) PolicyCISOP1Annex I Part II §(5)
P-18Security Advisory Publication ProcedurePSIRT LeadP1Annex I Part II §(8)
P-19Penetration Testing ProcedureAppSec LeadP2Annex I Part II §(3)
P-20Bug Bounty / Researcher Engagement ProcedurePSIRT LeadP3Annex I Part II §(5)
P-21SBOM Generation & Maintenance ProcedureEngineering LeadP1Annex I Part II §(1)
P-22Component & Library Vulnerability Monitoring ProcedureAppSec LeadP1Annex I Part II §(2)

Domain D — Incident Response & Reporting (P-23 → P-28)

IDDocumentOwnerPriorityCRA reference
P-23Incident Response Plan (IRP)CISO / PSIRT LeadP1Art. 14(3)
P-24ENISA / CSIRT Notification Procedure (24h / 72h / 14d)PSIRT LeadP1Art. 14(1)(3)
P-25User Notification Procedure (Severe Incidents)PSIRT Lead / CommsP1Art. 14(8)
P-26Incident Classification & Severity MatrixCISOP1Art. 14(3)
P-27Forensic Evidence Handling ProcedurePSIRT LeadP2Art. 14 (general)
P-28Post-Incident Review & Lessons Learned ProcedureCISOP2Art. 14 (general)

Domain E — Supply Chain Security (P-29 → P-34)

IDDocumentOwnerPriorityCRA reference
P-29Supplier & Third-Party Security PolicyProcurement / CISOP1Annex I §1(1), Recital 32
P-30Open-Source Software Use & Stewardship PolicyEngineering LeadP1Art. 24, Recital 18
P-31Build Pipeline Integrity & Artefact Signing ProcedureDevOps LeadP1Annex I §1(2)(f)
P-32Update Distribution & Authenticity Verification ProcedureDevOps / PSIRTP1Annex I Part II §(7)
P-33Provenance & SLSA Posture ProcedureDevOps LeadP3Annex I §1(1)
P-34Sub-Component Vulnerability Notification ProcedureProcurement / PSIRTP2Annex I Part II §(2)

Domain F — Documentation & User Information (P-35 → P-41)

IDDocumentOwnerPriorityCRA reference
P-35Technical Documentation Master (Annex VII Index)Quality ManagerP1Annex VII
P-36Cybersecurity Risk Assessment ReportSecurity ArchitectP1Annex VII §(3), Art. 13(2)
P-37Architecture & Data-Flow DiagramsSecurity ArchitectP1Annex VII §(2)
P-38User Information & Instructions (Annex II)Product Manager / Tech WriterP1Annex II
P-39Support Period & End-of-Support Notification ProcedureProduct ManagerP1Art. 13(8)
P-40Decommissioning & Data-Wipe User GuidanceProduct ManagerP2Annex I §1(2)(m)
P-41Logging & Monitoring User-Facing DocumentationProduct ManagerP2Annex I §1(2)(l)

Domain G — Conformity & Market-Surveillance (P-42 → P-48)

IDDocumentOwnerPriorityCRA reference
P-42Conformity Assessment Procedure & Module SelectionQuality ManagerP1Art. 32, Annex VIII
P-43EU Declaration of Conformity Template & RegisterQuality ManagerP1Art. 28, Annex V
P-44CE Marking ProcedureQuality ManagerP1Art. 30
P-45Substantial Modification & Re-Assessment ProcedureProduct Manager / QualityP1Art. 13(3)
P-46Notified Body Engagement & Liaison ProcedureQuality ManagerP1Art. 32(2)–(3)
P-47Non-Conformity Handling, Recall & Authority NotificationCISO / QualityP1Art. 13(5)(7)
P-48Importer & Distributor Verification ProcedureProcurement / QualityP2Art. 19, 20
Total: 48 documents across 7 domains. Use this register as the master index for the technical documentation pack required under Annex VII; every entry should resolve to a versioned artefact in the evidence repository.
← All articles