PartsProof

EU Cyber Resilience Act — reporting obligations start September 11, 2026

Who can prepare your EU CRA documentation and SBOM: every option compared (2026)

The question behind every CRA vendor search is really two questions — who is allowed to write this, and who ends up carrying it if it is wrong. The Regulation answers both, and the answers do not line up the way the market implies.

Who must draw up the fileThe manufacturer. Art. 13(12): before placing the product on the market, manufacturers shall draw up the technical documentation referred to in Art. 31Regulation (EU) 2024/2847
Qualification required to write itNone. The Regulation sets no qualification, accreditation or registration for whoever drafts the documentation or generates the SBOMRegulation (EU) 2024/2847
Can an authorised representative take the dutyNo. Art. 18(2) excludes Art. 13(1) to (11), Art. 13(12) first subparagraph and Art. 13(14) from the mandateRegulation (EU) 2024/2847
Can a notified body advise youNot on products it assesses. Art. 39(4) bars conformity assessment bodies from any activity conflicting with independence — “this shall in particular apply to consultancy services”Regulation (EU) 2024/2847
Who signs it off by defaultYou do. Under internal control (module A) the manufacturer ensures and declares on its sole responsibility that the product meets Annex IRegulation (EU) 2024/2847
A CRA consultant registerDoes not exist. The Commission's implementation timeline lists notifying authorities and conformity assessment bodies only — no consultant accreditation scheme is plannedEuropean Commission — CRA implementation

If you make hardware or software sold in the EU and you have started looking for someone to prepare your Cyber Resilience Act documentation, the search results will suggest a professional class exists for this — certified assessors, accredited consultants, approved CRA partners. Regulation (EU) 2024/2847 creates no such class. It is worth knowing that before you compare quotes, because it changes what you are actually buying.

Who can legally prepare EU CRA documentation and an SBOM?

Anyone. There is no licence to write a technical file. Article 13(12) of the Cyber Resilience Act says that “before placing a product with digital elements on the market, manufacturers shall draw up the technical documentation referred to in Article 31”, and Article 31 says that documentation “shall contain all relevant data or details of the means used by the manufacturer” and “shall at least contain the elements set out in Annex VII”. Neither article, and nothing in Annex VII, says who must hold the pen. The same is true of the software bill of materials: Annex I, Part II(1) requires you to draw one up in a commonly used machine-readable format, and is silent on who generates it.

The duty is placed on the manufacturer. The drafting is not reserved to anyone. Those are two different statements, and most of the confusion in this market lives in the gap between them.

Is there an accredited Cyber Resilience Act consultant?

No. The only body the Regulation accredits is the notified body — a conformity assessment body designated by a Member State under Chapter V — and its job is to assess, not to prepare. Article 39(3) requires a conformity assessment body to be “a third-party body independent of the organisation or the product with digital elements it assesses”. Article 39(4) goes further: a conformity assessment body and its personnel “shall not engage in any activity that may conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall in particular apply to consultancy services.”

Read that alongside the market and the shape of the problem becomes clear. The one actor the CRA accredits is the one actor forbidden to write your documentation for the products it assesses. Everyone else who can write it is unaccredited by design — not because they slipped through a gap, but because the Regulation never created an accreditation for the drafting side at all. The Commission’s own implementation timeline bears this out: its milestones cover notifying authorities, conformity assessment bodies, implementing acts and standardisation deliverables. There is no consultant register on it, and none planned.

So “are they accredited?” is not a question that separates good CRA help from bad. It cannot be, because there is nothing to be accredited for. The questions that do separate them are further down this page.

Can an authorised representative do it for you?

Not the part you most want moved. Article 18(1) lets a manufacturer “by a written mandate, appoint an authorised representative”, which is the standard instrument a non-EU maker uses to have a presence inside the Union. But Article 18(2) carves the core out of it in one sentence: the obligations in Article 13(1) to (11), Article 13(12) first subparagraph, and Article 13(14) “shall not form part of the authorised representative’s mandate”.

Translated, the excluded set is:

  • Article 13(1) to (3) — designing and producing the product in line with the Annex I essential requirements, and the documented cybersecurity risk assessment behind it.
  • Article 13(12) first subparagraph — drawing up the technical documentation itself.
  • Article 13(14) — the vulnerability reporting duty that starts on 11 September 2026.

What an authorised representative does take on is listed in Article 18(3): keeping the EU declaration of conformity and the technical documentation at the disposal of market surveillance authorities for at least ten years or the support period, whichever is longer; answering reasoned requests from those authorities; and cooperating on action to eliminate risk. That is custody and correspondence. It is genuinely useful for a non-EU manufacturer, and it is not preparation.

The five options, compared

Every route to a CRA technical file and SBOM is one of these. The columns that matter are not price — they are what each option can produce, and what it can carry.

OptionCan draft the file and generate the SBOMCan hold the legal dutyAccredited under the CRAWhat it is actually for
Your own engineersYesYes — it is already yoursNo, and none requiredThe default. Free of fees, expensive in engineering weeks, and the only route where the product knowledge is already in the room.
A security or compliance consultancyYesNoNo, and none existsOpen-ended advisory, usually day-rated. Fits when the underlying engineering work is unknown and needs scoping before it can be priced.
A fixed-scope readiness service (this is us)The reporting-readiness set, yes. The full Annex VII technical file, noNoNo, and none existsA defined deliverable for a defined fee. Fits when you know which obligation you are answering and want the artefacts rather than the hours.
An authorised representative (Art. 18)No — expressly excluded by Art. 18(2)NoNoCustody of the declaration and technical file inside the EU, plus correspondence with market surveillance authorities. Required for many non-EU makers.
A notified body (Chapter V)No — barred by Art. 39(4) for products it assessesNoYes — the only accredited actorThird-party conformity assessment under modules B+C or H. Needed only for Annex III class II and Annex IV products, or class I without harmonised standards.

The column that stays empty is the one buyers most want filled. Nobody in this table can hold the duty except you. There is no arrangement under the CRA in which the responsibility for the technical documentation moves to a supplier — which is why the honest framing of every service on this list, ours included, is that it produces evidence you then own.

Do you need to hire anyone at all?

Often, no. Recital 89 and Article 32(1)(a) put the default route plainly: for products not listed as important or critical, conformity assessment “can be carried out by the manufacturer under its own responsibility following the internal control procedure based on module A”, and under that procedure “the manufacturer ensures and declares on its sole responsibility” that the product and its processes meet the essential requirements. No third party, no fee, no external sign-off.

That route closes for Annex III class II products — hypervisors, firewalls, tamper-resistant microprocessors and the rest of that list — and for the Annex IV critical categories, and it narrows for class I products where you have not applied harmonised standards. For everyone else, buying help is a decision about calendar time and confidence, not about legal necessity. We put the numbers behind that in what CRA compliance actually costs a small manufacturer.

What to check before you hire anyone

Since accreditation is not available as a filter, use the three the Regulation makes checkable.

  • Which obligation, and which date. The CRA has two live clocks — reporting under Article 14 from 11 September 2026, and everything in Annex I from 11 December 2027. A quote that does not say which one it covers is a quote you cannot compare against another. Ours covers the first and maps the second; we say so on the pricing section rather than in a footnote.
  • Does the SBOM regenerate. Annex I, Part II(1) wants a machine-readable record covering at least top-level dependencies. A hand-built document is stale on your next firmware release, and the format is still open pending an Article 13(24) implementing act, so the artefact needs to be re-emittable rather than filed once.
  • Ask what they will not do. A document pack does not make a product CE-compliant, and a supplier who does not volunteer that boundary is selling the gap between the two deadlines back to you. Nobody can sign the declaration of conformity but you.

What none of them can take off your hands

Three things stay with the manufacturer no matter who you engage, and it is worth naming them because they are the things that actually go wrong.

The declaration of conformity is yours: Article 13(12) has you draw it up and affix the CE marking once conformity is demonstrated. The 24-hour early warning is yours: Article 13(14) is on the Article 18(2) exclusion list, so no representative and no vendor becomes the party that owes the CSIRT a report — and if you are a microenterprise or small enterprise, the carve-out in Article 64(10)(a) removes the fine and not the duty. And the currency of the file is yours: Article 31(2) requires the technical documentation to be drawn up before placing on the market and “continuously updated, where appropriate, at least during the support period”. A document set that was accurate on delivery day and never touched again is a document set that stops satisfying Article 31 the first time the product changes.

Which is the real answer to who can prepare your CRA documentation. Anyone can write it. Only you can keep it true.