Readiness report · Harborlight Sentinel — fictional product 1.2.0
In scope — important product, class I
Annex III, Class I, point 17
- Assessment date
- 16 September 2026
- Ruleset
- CRA-2024/2847 + Commission guidance 2026-03 — ruleset 0.2, Annex III/IV verified
- Legal source
- Regulation (EU) 2024/2847
- Obligations
- 8 identified
- Prepared for
- Harborlight Devices — fictional company
- Generated
- 17 September 2026
- Legal review
- Ruleset CRA-2024/2847 + Commission guidance 2026-03 — ruleset 0.2, Annex III/IV verified — annex text verified against the Official Journal.
What this document is
Scopeward provides indicative CRA scoping information, not legal advice. Using it does not create a lawyer-client relationship. You remain responsible for your own conformity assessment, documents and deadlines.
Ruleset CRA-2024/2847 + Commission guidance 2026-03 — ruleset 0.2, Annex III/IV verified — annex text verified against the Official Journal.
Contents
- 01Classification and basis
- 02Dates and route
- 03Your CRA roadmap
- 04Obligations and source text
- 05Your recorded implementation plan
- 06Evidence inventory
- 07Included working materials
- 08Derivation from your answers
01Classification and basis
Assessment overview
In scope — important product, class I
Your answers match an important-product category in class I. Self-assessment alone is not available unless harmonised standards fully cover the product.
8 obligations identified by this assessment
02Dates and route
- Reporting duty start
- 11 September 2026Article 71(2) · See source 16
- Full compliance
- 11 December 2027Article 71(2) · See source 17
- Conformity route
- Third-party assessment, or full harmonised-standard coverageAnnex III, Class I, point 17
03Your CRA roadmap
This roadmap lists the obligations identified by this assessment with their stored dates and legal bases. It does not depend on workspace setup.
| Obligation | Applicable date | Legal basis | Workspace starting point |
|---|---|---|---|
| Report actively exploited vulnerabilities & severe incidents (24h early warning / 72h notification / 14d-1mo final) via ENISA SRP | 11 September 2026 | Art 14 | Obligation record in your workspace |
| Register on ENISA Single Reporting Platform; map main-establishment CSIRT | 11 September 2026 | Art 14/16 | Obligation record in your workspace |
| Conformity assessment, EU Declaration of Conformity, CE marking | 11 December 2027 | Art 28-30 | Obligation record in your workspace |
| Essential cybersecurity requirements (secure-by-default, no known exploitable vulns at release…) | 11 December 2027 | Annex I Part I | Obligation record in your workspace |
| Security-update support period >= 5 years | 11 December 2027 | Art 13(8) | Obligation record in your workspace |
| Technical documentation incl. risk assessment | 11 December 2027 | Art 31 / Annex VII | Obligation record in your workspace |
| User information & instructions (Annex II), incl. support end-date | 11 December 2027 | Annex II | Obligation record in your workspace |
| Vulnerability handling: SBOM, coordinated disclosure policy, security updates | 11 December 2027 | Annex I Part II | Obligation record in your workspace |
04Obligations and source text
Open a source passage for each obligation. The document view prints all passages in full.
Report actively exploited vulnerabilities & severe incidents (24h early warning / 72h notification / 14d-1mo final) via ENISA SRP
What this asks of you: Notify the designated CSIRT and ENISA within 24 hours of becoming aware of an actively exploited vulnerability in your product, then follow with a full notification within 72 hours.
Register on ENISA Single Reporting Platform; map main-establishment CSIRT
What this asks of you: Notifications are submitted through the single reporting platform, using the electronic notification end-point of the CSIRT designated as coordinator in the Member State of your main establishment in the Union, and are simultaneously accessible to ENISA. Your main establishment is where decisions about your products' cybersecurity are predominantly taken. Identify that coordinator and confirm your access to the platform before you need to report, rather than while reporting. This item is about being able to report; the deadlines themselves belong to the reporting duty.
Vulnerability handling: SBOM, coordinated disclosure policy, security updates
What this asks of you: Identify and document vulnerabilities in the product, including its components, and keep the handling process current for the whole support period.
Essential cybersecurity requirements (secure-by-default, no known exploitable vulns at release…)
What this asks of you: Assess the cybersecurity risks of the product and document how the essential requirements in Annex I are met. The assessment must be part of the technical documentation and updated when the product changes materially.
Technical documentation incl. risk assessment
What this asks of you: Compile a technical file describing the product, its design, development and vulnerability handling processes, and the assessment of applicable essential requirements. Keep it for ten years after placing on the market.
Conformity assessment, EU Declaration of Conformity, CE marking
What this asks of you: Affix the CE marking visibly, legibly and indelibly to the product or its packaging, followed by the notified body's identification number where applicable.
Security-update support period >= 5 years
What this asks of you: Determine and publish the support period, which shall reflect the expected product lifetime and be at least five years unless the lifetime is shorter.
User information & instructions (Annex II), incl. support end-date
What this asks of you: Supply instructions to the user covering intended use, security properties, the support period, and where to report vulnerabilities — in plain language, with each release.
05Your recorded implementation plan
This section shows every obligation alongside the state, owner, planning target and evidence recorded in your workspace at capture time.
Captured 17 September 2026 at 12:00 UTC · plan revision 1
2 process states recorded · 1 owner recorded · 1 evidence record
6 of 8 obligations have no recorded state, owner or target date. The snapshot reflects workspace records at the capture time. Recorded status and evidence do not independently verify compliance.
| Obligation | State | Owner | Your target | Evidence |
|---|---|---|---|---|
| Conformity assessment, EU Declaration of Conformity, CE marking | Not recorded | — | — | None |
| Essential cybersecurity requirements (secure-by-default, no known exploitable vulns at release…) | Not recorded | — | — | None |
| Security-update support period >= 5 years | Not recorded | — | — | None |
| Technical documentation incl. risk assessment | Not recorded | — | — | None |
| User information & instructions (Annex II), incl. support end-date | Not recorded | — | — | None |
| Vulnerability handling: SBOM, coordinated disclosure policy, security updates | Not recorded | — | — | None |
| Report actively exploited vulnerabilities & severe incidents (24h early warning / 72h notification / 14d-1mo final) via ENISA SRPReview the recorded evidence and workspace statusOpen the obligation record, read the saved evidence references and update your own status if needed.Notes: Discuss the existing workflow at the next team planning meeting. | In progressYour entries before purchase: Not startedSaved with checkout: 16 September 2026 at 12:00 UTCRecord source: Updated after purchaseRecord timestamp (UTC): 17 September 2026 at 12:00 UTC | Alex — product team | 1 October 2026 | 1 reference |
| Register on ENISA Single Reporting Platform; map main-establishment CSIRTAssign an owner and target planning dateName the person responsible for the work and choose your own planning target date.Notes: Discuss the existing workflow at the next team planning meeting. | In progressRecord source: Updated after purchaseRecord timestamp (UTC): 17 September 2026 at 12:00 UTC | — | — | None |
06Evidence inventory
- Example internal workflow reference — no file attached — metadata-only reference — 17 September 2026 · obligation record
07Included working materials
Your workspace includes these working materials for this assessment. Document templates remain drafts until you complete and review them.
- Working plan
- Annex VII technical-documentation draft
- EU Declaration of Conformity draft
- Coordinated vulnerability disclosure policy draft
- Download audit export
Documentation checklist
The items below are taken from the technical-documentation source text stored with this assessment.
ANNEX VII CONTENT OF THE TECHNICAL DOCUMENTATION The technical documentation referred to in Article 31 shall contain at least the following information, as applicable to the relevant product with digital elements:
- 1. a general description of the product with digital elements, including: (a) its intended purpose; (b) versions of software affecting compliance with essential cybersecurity requirements; (c) where the product with digital elements is a hardware product, photographs or illustrations showing external features, marking and internal layout; (d) user information and instructions as set out in Annex II;
- 2. a description of the design, development and production of the product with digital elements and vulnerability handling processes, including: (a) necessary information on the design and development of the product with digital elements, including, where applicable, drawings and schemes and a description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing; (b) necessary information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities and a description of the technical solutions chosen for the secure distribution of updates; (c) necessary information and specifications of the production and monitoring processes of the product with digital elements and the validation of those processes;
- 3. an assessment of the cybersecurity risks against which the product with digital elements is designed, developed, produced, delivered and maintained pursuant to Article 13, including how the essential cybersecurity requirements set out in Part I of Annex I are applicable;
- 4. relevant information that was taken into account to determine the support period pursuant to Article 13(8) of the product with digital elements;
- 5. a list of the harmonised standards applied in full or in part the references of which have been published in the Official Journal of the European Union , common specifications as set out in Article 27 of this Regulation or European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 pursuant to Article 27(8) of this Regulation, and, where those harmonised standards, common specifications or European cybersecurity certification schemes have not been applied, descriptions of the solutions adopted to meet the essential cybersecurity requirements set out in Parts I and II of Annex I, including a list of other relevant technical specifications applied. In the event of partly applied harmonised standards, common specifications or European cybersecurity certification schemes, the technical documentation shall specify the parts which have been applied;
- 6. reports of the tests carried out to verify the conformity of the product with digital elements and of the vulnerability handling processes with the applicable essential cybersecurity requirements as set out in Parts I and II of Annex I;
- 7. a copy of the EU declaration of conformity;
- 8. where applicable, the software bill of materials, further to a reasoned request from a market surveillance authority provided that it is necessary in order for that authority to be able to check compliance with the essential cybersecurity requirements set out in Annex I.
Sources
Source 1
1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
Regulation (EU) 2024/2847 — Article 14(1)Source 2
2. For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit: (a) an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available; (b) unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be; (c) unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following: (i) a description of the vulnerability, including its severity and impact; (ii) where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; (iii) details about the security update or other corrective measures that have been made available to remedy the vulnerability.
Regulation (EU) 2024/2847 — Article 14(2)Source 3
3. A manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that incident via the single reporting platform established pursuant to Article 16.
Regulation (EU) 2024/2847 — Article 14(3)Source 4
4. For the purposes of the notification referred to in paragraph 3, the manufacturer shall submit: (a) an early warning notification of a severe incident having an impact on the security of the product with digital elements, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, including at least whether the incident is suspected of being caused by unlawful or malicious acts, which shall also indicate, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available; (b) unless the relevant information has already been provided, an incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the incident, which shall provide general information, where available, about the nature of the incident, an initial assessment of the incident, as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be; (c) unless the relevant information has already been provided, a final report, within one month after the submission of the incident notification under point (b), including at least the following: (i) a detailed description of the incident, including its severity and impact; (ii) the type of threat or root cause that is likely to have triggered the incident; (iii) applied and ongoing mitigation measures.
Regulation (EU) 2024/2847 — Article 14(4)Source 5
7. The notifications referred to in paragraphs 1 and 3 of this Article shall be submitted via the single reporting platform referred to in Article 16 using one of the electronic notification end-points referred to in Article 16(1). The notification shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be simultaneously accessible to ENISA. For the purposes of this Regulation, a manufacturer shall be considered to have its main establishment in the Union in the Member State where the decisions related to the cybersecurity of its products with digital elements are predominantly taken. If such a Member State cannot be determined, the main establishment shall be considered to be in the Member State where the manufacturer concerned has the establishment with the highest number of employees in the Union. Where a manufacturer has no main establishment in the Union, it shall submit the notifications referred to in paragraphs 1 and 3 using the electronic notification end-point of the CSIRT designated as coordinator in the Member State determined pursuant to the following order and based on the information available to the manufacturer: (a) the Member State in which the authorised representative acting on behalf of the manufacturer for the highest number of products with digital elements of that manufacturer is established; (b) the Member State in which the importer placing on the market the highest number of products with digital elements of that manufacturer is established; (c) the Member State in which the distributor making available on the market the highest number of products with digital elements of that manufacturer is established; (d) the Member State in which the highest number of users of products with digital elements of that manufacturer are located. In relation to the third subparagraph, point (d), a manufacturer may submit notifications related to any subsequent actively exploited vulnerability or severe incident having an impact on the security of the product with digital elements to the same CSIRT designated as coordinator to which it first reported.
Regulation (EU) 2024/2847 — Article 14(7)Source 6
1. For the purposes of the notifications referred to in Article 14(1) and (3) and Article 15(1) and (2) and in order to simplify the reporting obligations of manufacturers, a single reporting platform shall be established by ENISA. The day-to-day operations of that single reporting platform shall be managed and maintained by ENISA. The architecture of the single reporting platform shall allow Member States and ENISA to put in place their own electronic notification end-points.
Regulation (EU) 2024/2847 — Article 16(1)Source 7
Part II Vulnerability handling requirements Manufacturers of products with digital elements shall: (1) identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products; (2) in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates; (3) apply effective and regular tests and reviews of the security of the product with digital elements; (4) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch; (5) put in place and enforce a policy on coordinated vulnerability disclosure; (6) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements; (7) provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner; (8) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.
Regulation (EU) 2024/2847 — Annex I, Part IISource 8
Part I Cybersecurity requirements relating to the properties of products with digital elements (1) Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks. (2) On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall: (a) be made available on the market without known exploitable vulnerabilities; (b) be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state; (c) ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them; (d) ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access; (e) protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means; (f) protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions; (g) process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation); (h) protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks; (i) minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks; (j) be designed, developed and produced to limit attack surfaces, including external interfaces; (k) be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques; (l) provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user; (m) provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner.
Regulation (EU) 2024/2847 — Annex I, Part ISource 9
1. The technical documentation shall contain all relevant data or details of the means used by the manufacturer to ensure that the product with digital elements and the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Annex I. It shall at least contain the elements set out in Annex VII.
Regulation (EU) 2024/2847 — Article 31(1)Source 11
1. The EU declaration of conformity shall be drawn up by manufacturers in accordance with Article 13(12) and state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated.
Regulation (EU) 2024/2847 — Article 28(1)Source 12
1. The CE marking shall be affixed visibly, legibly and indelibly to the product with digital elements. Where that is not possible or not warranted on account of the nature of the product with digital elements, it shall be affixed to the packaging and to the EU declaration of conformity referred to in Article 28 accompanying the product with digital elements. For products with digital elements which are in the form of software, the CE marking shall be affixed either to the EU declaration of conformity referred to in Article 28 or on the website accompanying the software product. In the latter case, the relevant section of the website shall be easily and directly accessible to consumers.
Regulation (EU) 2024/2847 — Article 30(1)Source 13
4. The CE marking shall be followed by the identification number of the notified body, where that body is involved in the conformity assessment procedure based on full quality assurance (based on module H) referred to in Article 32. The identification number of the notified body shall be affixed by the body itself or, under its instructions, by the manufacturer or the manufacturer’s authorised representative.
Regulation (EU) 2024/2847 — Article 30(4)Source 14
8. Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I. Manufacturers shall determine the support period so that it reflects the length of time during which the product is expected to be in use, taking into account, in particular, reasonable user expectations, the nature of the product, including its intended purpose, as well as relevant Union law determining the lifetime of products with digital elements. When determining the support period, manufacturers may also take into account the support periods of products with digital elements offering a similar functionality placed on the market by other manufacturers, the availability of the operating environment, the support periods of integrated components that provide core functions and are sourced from third parties as well as relevant guidance provided by the dedicated administrative cooperation group (ADCO) established pursuant to Article 52(15) and the Commission. The matters to be taken into account in order to determine the support period shall be considered in a manner that ensures proportionality. Without prejudice to the second subparagraph, the support period shall be at least five years. Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time. Taking into account ADCO recommendations as referred to in Article 52(16), the Commission may adopt delegated acts in accordance with Article 61 to supplement this Regulation by specifying the minimum support period for specific product categories where the market surveillance data suggests inadequate support periods. Manufacturers shall include the information that was taken into account to determine the support period of a product with digital elements in the technical documentation as set out in Annex VII. Manufacturers shall have appropriate policies and procedures, including coordinated vulnerability disclosure policies, referred to in Part II, point (5), of Annex I to process and remediate potential vulnerabilities in the product with digital elements reported from internal or external sources.
Regulation (EU) 2024/2847 — Article 13(8)Source 15
ANNEX II INFORMATION AND INSTRUCTIONS TO THE USER At minimum, the product with digital elements shall be accompanied by: 1. the name, registered trade name or registered trademark of the manufacturer, and the postal address, the email address or other digital contact as well as, where available, the website at which the manufacturer can be contacted; 2. the single point of contact where information about vulnerabilities of the product with digital elements can be reported and received, and where the manufacturer’s policy on coordinated vulnerability disclosure can be found; 3. name and type and any additional information enabling the unique identification of the product with digital elements; 4. the intended purpose of the product with digital elements, including the security environment provided by the manufacturer, as well as the product’s essential functionalities and information about the security properties; 5. any known or foreseeable circumstance, related to the use of the product with digital elements in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to significant cybersecurity risks; 6. where applicable, the internet address at which the EU declaration of conformity can be accessed; 7. the type of technical security support offered by the manufacturer and the end-date of the support period during which users can expect vulnerabilities to be handled and to receive security updates; 8. detailed instructions or an internet address referring to such detailed instructions and information on: (a) the necessary measures during initial commissioning and throughout the lifetime of the product with digital elements to ensure its secure use; (b) how changes to the product with digital elements can affect the security of data; (c) how security-relevant updates can be installed; (d) the secure decommissioning of the product with digital elements, including information on how user data can be securely removed; (e) how the default setting enabling the automatic installation of security updates, as required by Part I, point (2)(c), of Annex I, can be turned off; (f) where the product with digital elements is intended for integration into other products with digital elements, the information necessary for the integrator to comply with the essential cybersecurity requirements set out in Annex I and the documentation requirements set out in Annex VII. 9. If the manufacturer decides to make available the software bill of materials to the user, information on where the software bill of materials can be accessed.
Regulation (EU) 2024/2847 — Annex IISource 16
However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.
Regulation (EU) 2024/2847 — Article 71(2)Source 17
2. This Regulation shall apply from 11 December 2027.
Regulation (EU) 2024/2847 — Article 71(2)
08Derivation from your answers
- Explanation 1: Q1 · What kind of product is this? — you answered: A device or hardware product
- Explanation 5: Q5 · Which listed category describes your product? — you answered: 17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
In scope — important product, class I
See explanation 1
See explanation 5
Reporting duty start: 11 September 2026
Full compliance: 11 December 2027
Conformity route
See explanation 1
See explanation 5
Ruleset CRA-2024/2847 + Commission guidance 2026-03 — ruleset 0.2, Annex III/IV verified — annex text verified against the Official Journal.