Shadow AI has nowhere to hide. AI Nerve Center is GA. Run your first scan! Read more
Buy Uno via Microsoft using your Azure Consumption Credits Learn how
Compliance Launchpad: audit-ready in 20 weeks, unlimited frameworks, one fixed price Get your quote
Assessment Agents: comprehensive, state-of-the-art, on demand, pay per use Explore assessments
Home
About
The Uno Story Team Advisors News & Press
Platform
Platform Overview AI Agents FSD Assessments Modular Customizable Integrations
Solutions
Enterprise Risk Management ERM Framework Risk Quantification Cyber Risk Management Compliance & Attestations SOX Compliance Continuous Monitoring Regulatory Change Management Internal Audit Risk Assessment Controls Monitoring Third-Party Risk Vendor Risk Assessment AI Governance Business Resilience BCP & Disaster Recovery Operational Resilience Incident Management Policy Management Regulatory Reporting EU Cyber Resilience Act Business Continuity Customer Assurance Contractual Obligations
Industries
Banking & Fintech Healthcare & Life Sciences Higher Education Technology Energy Federal & SLED Fortune 2000
Migrations & Integrations
Agentic Capabilities for Archer IRM Connect with ServiceNow Migrate from OneTrust Migrate from Optro (AuditBoard)
Resources
Blog Webinars GRC Glossary The Integrated Approach Microsoft Partnership
More
Partners Contact Us
EU Cyber Resilience Act

are you a
manufacturer
under the CRA?

Article 14 reporting obligations apply from 11 September 2026, to products already on the EU market. Most institutions have never checked whether any of theirs are in scope.

11 Sep 2026 Article 14 reporting
Vulnerability and incident notification to CSIRT and ENISA
11 Jun 2027 Conformity assessment bodies
Notification of conformity assessment bodies by Member States
11 Sep 2027 Market surveillance
Market surveillance and reporting obligations for authorities
11 Dec 2027 Full application
All CRA obligations apply, including essential requirements and CE marking
The Distinction That Does the Work

the CRA regulates
products. not entities.

Regulation (EU) 2024/2847 is a horizontal product regulation. It uses the same machinery the EU applies to any other product on its market: essential requirements, conformity assessment, technical documentation, declaration of conformity, CE mark. Where DORA regulates the financial entity, the CRA regulates the product with digital elements that the entity places on the market.

Manufacturer

Develops or manufactures a product, or has one designed, developed or manufactured, and markets it under its own name or trademark.

Read the middle clause twice. Commissioning a product and putting your brand on it makes you the manufacturer.

Importer

Established in the EU and places a product from a non-EU manufacturer on the Union market.

Distributor

Makes a product available on the EU market without affecting its properties. Not the manufacturer or importer.

Authorised Representative

Established in the EU and mandated by a non-EU manufacturer to act on their behalf for specified tasks.

Where an institution becomes a manufacturer

Supply free of charge still counts as making available on the market (Article 3).

Annex IV — Critical Products

Payment cards and terminals sit in the CRA's most demanding tier

Self-assessment is not available for critical products. They require a European cybersecurity certificate under a scheme adopted pursuant to Regulation (EU) 2019/881, or mandatory third-party conformity assessment where no such scheme is in force.

Hardware Security Modules Secure Payment Terminals Payment Cards Secure Elements

Implementing Regulation (EU) 2025/2392 — technical descriptions of Annex III and Annex IV categories.

Classification turns on the core functionality of the product, not on whether a product happens to contain a matching component. A banking application that uses a secure element is not itself a secure element for the purposes of Annex IV.

CRA Article 14 Economic Operator Classification Annex III & IV Conformity Assessment CE Marking Technical Documentation Vulnerability Handling SBOM CRA Article 14 Economic Operator Classification Annex III & IV Conformity Assessment CE Marking Technical Documentation Vulnerability Handling SBOM
One Event, Two Filings

two clocks that
do not converge.

A single vulnerability or incident in a product with digital elements can trigger reporting under both the CRA and DORA. Different trigger, different classification test, different recipient, different template. One filing does not satisfy the other.

CRA Article 14 — Product Reporting

Early warning24 hours
Full notification72 hours
Final report14 days
Recipient: CSIRT and ENISA via the Single Reporting Platform

DORA Article 19 — Entity Reporting

Initial notification4 hours
Intermediate report72 hours
Final report1 month
Recipient: Competent financial authority
The Gap

what your DORA program
does not give you.

DORA compliance does not satisfy CRA obligations. The two regulations address different subjects, through different mechanisms, with different evidence requirements. Three gaps matter most.

01 The reporting channel does not converge The proposed Digital Omnibus consolidates reporting for GDPR, NIS2, DORA, eIDAS and CER into a single entry point. CRA Article 14 product reporting stays outside it, on ENISA's own Single Reporting Platform. Every firm building one consolidated reporting capability is building something that structurally excludes the obligation that starts on 11 September. Reporting
02 The evidence is different in kind An ICT risk management framework, a Register of Information and resilience testing are not a product cybersecurity risk assessment, a declaration of conformity, an Annex VII technical file or a defined support period. The CRA requires product-level documentation that DORA does not produce. Evidence
03 The owner is different DORA sits with the operational resilience function. The CRA sits with whoever owns products placed on the market. In most banks, that is nobody. The CRA obligation has no natural internal home until someone creates one. Ownership
CRA Article 12

where the CRA meets
the EU AI Act.

A product with digital elements that is also a high-risk AI system is deemed to comply with AI Act Article 15 cybersecurity where it meets CRA Annex I Parts I and II and the CRA declaration of conformity demonstrates it. Accuracy and robustness stay with the AI Act. Only cybersecurity travels.

01

Conformity assessment precedence

Article 12(3) reverses the conformity assessment precedence for Annex III important products on certain routes and Annex IV critical products. The CRA procedures govern cybersecurity there, not the AI Act's own assessment.

02

Build the evidence once

Build the evidence once, or produce it twice in incompatible formats and get the benefit in neither. CRA conformity documentation that covers Annex I Parts I and II can satisfy the AI Act cybersecurity requirement directly.

03

The payments-specific twist

Credit scoring run internally is an AI Act question only. Credit decisioning software licensed to a third party is both a CRA product and a high-risk AI system. The licensing model, not the algorithm, determines whether CRA obligations attach.

04

From AI Nerve Center to CRA

Uno's AI Governance module already holds AI system inventories, risk classifications and conformity records. Linking them to CRA product records means the cybersecurity evidence is produced once and reused across both regulatory tracks.

Platform Capabilities

Uno maps the CRA
onto what you already run.

Concrete obligations mapped to concrete capabilities. No adjectives.

CRA Obligation Where It Lives in Uno
Economic operator classification across products Entity and asset register, with role and Annex tier as first-class fields
Finding undeclared manufacturer status Contract scanning across agreements for white-label, OEM and reseller terms
Annex I Parts I and II essential requirements Control set crosswalked against your NIST, ISO 27001 and PCI library
Article 14 reporting on a 24-hour clock Incident module, dual-track workflow with step SLAs and escalation
Technical documentation and declarations of conformity Evidence objects with owners, expiry and support period tracking
Supplier CE marks, DoCs and support periods TPRM, vendor trust centre integrations and document ingestion
Delegated and implementing acts as they move Regulatory change management with automated impact analysis
Frequently Asked Questions

CRA essentials

When does the CRA apply?

Regulation (EU) 2024/2847 entered into force on 10 December 2024. Article 14 reporting obligations apply from 11 September 2026. The remaining obligations, including essential requirements, conformity assessment and CE marking, apply from 11 December 2027.

Is my bank a manufacturer under the CRA?

If your institution develops a product with digital elements, or has one designed, developed or manufactured, and places it on the EU market under its own name or trademark, it is a manufacturer under Article 3. You do not have to build the product yourself. Commissioning it and branding it is enough. Common examples include own-brand payment terminals, merchant SDKs, licensed software and rebranded hardware.

Does DORA compliance cover the CRA?

No. DORA regulates the financial entity's ICT risk management. The CRA regulates the product placed on the market. They have different reporting channels, different evidence requirements (ICT risk framework versus product technical file and declaration of conformity), and typically different internal owners. One filing does not satisfy the other.

Are payment terminals in scope of the CRA?

Secure payment terminals are listed in Annex IV as critical products. They require third-party conformity assessment or a European cybersecurity certificate. Self-assessment is not available. The technical descriptions are set out in Implementing Regulation (EU) 2025/2392.

Is SaaS in scope of the CRA?

Pure SaaS delivered entirely as a remote service is generally outside scope, because the CRA applies to products placed on the market, and a cloud service without a downloadable or installable component is not a product with digital elements. However, where SaaS includes a client-side component, SDK, agent or downloadable module, that component may itself be a product in scope.

What is the CRA Single Reporting Platform?

ENISA is establishing a Single Reporting Platform for CRA Article 14 notifications. Manufacturers must submit early warnings (24 hours), full notifications (72 hours) and final reports (14 days) through this platform. It is separate from the reporting channels used for DORA, NIS2, GDPR and other regulations, including those being consolidated under the proposed Digital Omnibus.

How does the CRA interact with the EU AI Act?

Under CRA Article 12, a product with digital elements that is also a high-risk AI system is deemed to comply with the cybersecurity requirements of AI Act Article 15 where it meets CRA Annex I Parts I and II and the declaration of conformity demonstrates it. Accuracy and robustness remain with the AI Act. For Annex IV critical products and certain Annex III important products, the CRA conformity assessment procedures take precedence for cybersecurity.

The question worth asking

which products
are in scope?

SOC 2 Type II Attested ISO 27001 : 2022 In Progress Live in < 4 weeks No lock-in