Article 14 reporting obligations apply from 11 September 2026, to products already on the EU market. Most institutions have never checked whether any of theirs are in scope.
Regulation (EU) 2024/2847 is a horizontal product regulation. It uses the same machinery the EU applies to any other product on its market: essential requirements, conformity assessment, technical documentation, declaration of conformity, CE mark. Where DORA regulates the financial entity, the CRA regulates the product with digital elements that the entity places on the market.
Develops or manufactures a product, or has one designed, developed or manufactured, and markets it under its own name or trademark.
Read the middle clause twice. Commissioning a product and putting your brand on it makes you the manufacturer.
Established in the EU and places a product from a non-EU manufacturer on the Union market.
Makes a product available on the EU market without affecting its properties. Not the manufacturer or importer.
Established in the EU and mandated by a non-EU manufacturer to act on their behalf for specified tasks.
Supply free of charge still counts as making available on the market (Article 3).
Self-assessment is not available for critical products. They require a European cybersecurity certificate under a scheme adopted pursuant to Regulation (EU) 2019/881, or mandatory third-party conformity assessment where no such scheme is in force.
Implementing Regulation (EU) 2025/2392 — technical descriptions of Annex III and Annex IV categories.
Classification turns on the core functionality of the product, not on whether a product happens to contain a matching component. A banking application that uses a secure element is not itself a secure element for the purposes of Annex IV.
A single vulnerability or incident in a product with digital elements can trigger reporting under both the CRA and DORA. Different trigger, different classification test, different recipient, different template. One filing does not satisfy the other.
DORA compliance does not satisfy CRA obligations. The two regulations address different subjects, through different mechanisms, with different evidence requirements. Three gaps matter most.
Here is what your DORA program does not give you. Uno maps both onto a single control and incident architecture.
A product with digital elements that is also a high-risk AI system is deemed to comply with AI Act Article 15 cybersecurity where it meets CRA Annex I Parts I and II and the CRA declaration of conformity demonstrates it. Accuracy and robustness stay with the AI Act. Only cybersecurity travels.
Article 12(3) reverses the conformity assessment precedence for Annex III important products on certain routes and Annex IV critical products. The CRA procedures govern cybersecurity there, not the AI Act's own assessment.
Build the evidence once, or produce it twice in incompatible formats and get the benefit in neither. CRA conformity documentation that covers Annex I Parts I and II can satisfy the AI Act cybersecurity requirement directly.
Credit scoring run internally is an AI Act question only. Credit decisioning software licensed to a third party is both a CRA product and a high-risk AI system. The licensing model, not the algorithm, determines whether CRA obligations attach.
Uno's AI Governance module already holds AI system inventories, risk classifications and conformity records. Linking them to CRA product records means the cybersecurity evidence is produced once and reused across both regulatory tracks.
Products that are also high-risk AI systems need a single evidence set, not two. The AI Governance module connects them.
Concrete obligations mapped to concrete capabilities. No adjectives.
| CRA Obligation | Where It Lives in Uno |
|---|---|
| Economic operator classification across products | Entity and asset register, with role and Annex tier as first-class fields |
| Finding undeclared manufacturer status | Contract scanning across agreements for white-label, OEM and reseller terms |
| Annex I Parts I and II essential requirements | Control set crosswalked against your NIST, ISO 27001 and PCI library |
| Article 14 reporting on a 24-hour clock | Incident module, dual-track workflow with step SLAs and escalation |
| Technical documentation and declarations of conformity | Evidence objects with owners, expiry and support period tracking |
| Supplier CE marks, DoCs and support periods | TPRM, vendor trust centre integrations and document ingestion |
| Delegated and implementing acts as they move | Regulatory change management with automated impact analysis |
Regulation (EU) 2024/2847 entered into force on 10 December 2024. Article 14 reporting obligations apply from 11 September 2026. The remaining obligations, including essential requirements, conformity assessment and CE marking, apply from 11 December 2027.
If your institution develops a product with digital elements, or has one designed, developed or manufactured, and places it on the EU market under its own name or trademark, it is a manufacturer under Article 3. You do not have to build the product yourself. Commissioning it and branding it is enough. Common examples include own-brand payment terminals, merchant SDKs, licensed software and rebranded hardware.
No. DORA regulates the financial entity's ICT risk management. The CRA regulates the product placed on the market. They have different reporting channels, different evidence requirements (ICT risk framework versus product technical file and declaration of conformity), and typically different internal owners. One filing does not satisfy the other.
Secure payment terminals are listed in Annex IV as critical products. They require third-party conformity assessment or a European cybersecurity certificate. Self-assessment is not available. The technical descriptions are set out in Implementing Regulation (EU) 2025/2392.
Pure SaaS delivered entirely as a remote service is generally outside scope, because the CRA applies to products placed on the market, and a cloud service without a downloadable or installable component is not a product with digital elements. However, where SaaS includes a client-side component, SDK, agent or downloadable module, that component may itself be a product in scope.
ENISA is establishing a Single Reporting Platform for CRA Article 14 notifications. Manufacturers must submit early warnings (24 hours), full notifications (72 hours) and final reports (14 days) through this platform. It is separate from the reporting channels used for DORA, NIS2, GDPR and other regulations, including those being consolidated under the proposed Digital Omnibus.
Under CRA Article 12, a product with digital elements that is also a high-risk AI system is deemed to comply with the cybersecurity requirements of AI Act Article 15 where it meets CRA Annex I Parts I and II and the declaration of conformity demonstrates it. Accuracy and robustness remain with the AI Act. For Annex IV critical products and certain Annex III important products, the CRA conformity assessment procedures take precedence for cybersecurity.
General information, not legal advice. Verify against Regulation (EU) 2024/2847, its implementing and delegated acts, and take your own counsel.