PortaRegulus
HOME
07 // INTEL · ANALYSIS

The 48 documents a CRA audit asks for.

What each one is, who produces it, and what the work costs with and without the platform.

PortaRegulus Intel CRA · Technical Documentation 12 Jul 2026

The EU Cyber Resilience Act applies to nearly every product with digital elements sold in the EU. To keep your CE mark you must produce and maintain a technical documentation file, and from 11 September 2026 you must report actively exploited vulnerabilities and severe incidents to the authorities within 24 hours. Fines reach €15 million or 2.5 percent of global turnover.

We analyzed the full documentation sheet a consultancy could ask for. It contains 48 distinct items. Producing them by hand takes roughly 750 working hours for a single product. With our platform it takes about 230. This article walks through where those hours go, item group by item group, and what the difference is worth in euro at five regional labor rates, with the platform fee already included in every with-platform figure.

One platform, two halves

The platform merges two applications that share a single knowledge base and hand off to each other. The CRA Compliance Tool (cra.portaregulus.com) builds your technical file. It walks you through a structured risk assessment aligned with the prEN 40000 standards series, runs a STRIDE threat model against the Annex I essential requirements, and generates the documentation artifacts, including the EU Declaration of Conformity. Every generated document is stored as a versioned, unchangeable snapshot with a 10-year retention stamp, exactly as the regulation requires.

CVD Portal (cvdportal.com) runs your vulnerability handling. Your company gets its own public security page where researchers report flaws, your SBOM is checked daily against newly published vulnerabilities, and when something serious happens the portal computes your legal deadlines and assembles the report the authorities expect.

What the regulator will ask for, and who produces it

Of the 48 documentation items on the standard request sheet, the platform fully covers 37, partially covers 9, and 2 remain your responsibility entirely. More useful than the count is who does the work in each group.

The platform generates it, you review and approve

This is the largest group, around 30 items. It includes the product description, intended purpose, use scenarios, the complete risk assessment with acceptance criteria, assets and threats, the product security requirements, the EU Declaration of Conformity, the secure distribution and decommissioning plans, your internal vulnerability handling policy, and your public coordinated disclosure policy. You answer guided questions about your product, the platform drafts compliant documents, and you sign off. This is where the bulk of the 500-hour saving lives. The risk assessment alone drops from roughly 87 hours by hand to about 17 guided.

The platform is the evidence

Some requirements ask you to prove that infrastructure and processes exist. A secure channel for receiving vulnerability reports, a public advisory page with a subscription feed, daily CVE monitoring against your component list, a tamper-proof record of how you handled past reports, and 10-year retention of the file. You do not document these, because using the platform creates the evidence automatically. Without the platform each of these is roughly a 40-hour build-and-document project.

You provide it, the platform organizes it

Product photos, packaging and nameplate pictures, your version numbers, your user manuals, actual security test and review reports from your testers or labs, and the SBOM file your build tooling produces. The platform stores, indexes, and monitors these but cannot create them for you.

Two known gaps

The request sheet asks for evidence that your development environment and your production environment are themselves protected, typically an ISO 27001 certificate or a written description of your security practices. Neither application has a dedicated home for this today. If you hold a certificate, upload it to the artifact registry as a general document. A structured feature for this is on our roadmap.

What each tier is for

Free €0, forever

Complete vulnerability report intake. You get the public submission portal on your own subdomain, tracking IDs, the 48-hour acknowledgment clock, an auto-published CVD policy, PGP encrypted communication, and the append-only audit trail. If you only need researchers to be able to reach you and proof that you responded, Free does it, with one team seat. The typical fit is any manufacturer that needs a compliant public disclosure channel today.

Reporting €99 / month

The September 2026 tier. It covers Article 14 authority filing plus the full CRA vulnerability handling process of Annex I Part II. You get the 24-hour, 72-hour and 14-day notification workflow with a submission package ready for ENISA's Single Reporting Platform, deadline monitoring so nothing slips, SBOM and hardware registries, CVSS scoring, remediation tracking, CSAF 2.0 advisory export, threat intelligence feeds, security test and review scheduling, the 26-article obligation matrix, and 8 auto-drafted policy documents. Three team seats. The typical fit is an SME with products on the EU market that must file Article 14 notifications from September 2026.

Compliance €299 / month · up to 3 products

The December 2027 tier, and the one this article's 48-item analysis is about. Everything in Reporting, plus the full CRA self-assessment from risk assessment through to the EU Declaration of Conformity under Module A. That means the Annex I Part I cybersecurity risk assessment, STRIDE threat modelling with control mapping, product classification, conformity route selection, the 21-requirement self-assessment checklist, artifact drafting with gap analysis, the DoC draft, the Annex VII technical documentation index and export, CE marking guidance, the Annex II user-information sheet, monitoring triggers with immutable assessment snapshots, and the CRA exposure scanner. Up to 3 products and 5 team seats.

Enterprise €1,499 / month · 25 products included

Compliance at scale. Everything in Compliance for 25 products, then €99 per additional product each month. It adds the notified-body conformity evidence package, a trust portal on your own domain with a customer-facing view for approved viewers, automated SBOM-to-CVE supply chain alerts pushed from your CI pipeline, API access, SSO and SAML, Slack, Teams and Discord notifications, EUDI Wallet identity verification for reporters, CVE ID assistance, audit-ready compliance reports, ten team seats, a dedicated account manager and a 99.9 percent uptime SLA. The typical fit is a manufacturer with a large portfolio, integration needs, or notified-body evidence requirements.

Every new company starts with a 14-day Compliance trial, no credit card required.

What it is worth in hours and euro

We ran a PERT estimate (optimistic, most likely, pessimistic) over all 48 items, comparing manual production against platform-assisted work, priced at fully loaded internal engineering rates. For one product, manual production is about 746 expected hours. With the platform it is about 234, a 69 percent reduction in working time.

One productRateWithout platformWith platform, fee includedNet saving
Western Europe€90/h€67,140€24,621€42,519
Eastern Europe€45/h€33,570€14,105€19,465
Taiwan€42/h€31,332€13,403€17,929
China€35/h€26,110€11,768€14,342
India€22/h€16,412€8,729€7,683

The with-platform column already includes one year of the Compliance tier fee. Even at the lowest rates the net saving exceeds €7,600 per product.

A 20-product portfolio

The numbers compound in your favor, because the 16 company-level items (policies, reporting processes, monitoring infrastructure) are built once no matter how many products you sell, and those are exactly where the platform saves the most. Each additional product is cheaper than the last because product contexts are cloned and artifacts regenerate rather than being rewritten.

20 productsWithout platformWith platform, fee includedNet saving
Western Europe€514,134€145,502€368,632
Eastern Europe€257,067€81,745€175,322
Taiwan€239,929€77,494€162,435
China€199,941€67,577€132,364
India€125,677€49,158€76,519

The with-platform column already includes one year of the Enterprise tier fee, which covers all 25 products. In hours, documenting 20 products manually is roughly 5,700 hours, close to three person-years. With the platform it is about 1,400 hours.

Assumptions worth knowing. These are one-time documentation efforts for a mid-complexity product by someone who knows the product but is not a CRA specialist. The figures for test reports include the testing work itself, which no software can do for you. Recurring obligations, daily monitoring and future incident filings, are excluded from the totals, and they are precisely the work the platform automates from day one. This article updates our earlier SME cost analysis, which priced the five core CRA deliverables at 25 to 45 person-days for a first product, with an overall saving of 40 to 50 percent. The totals here are higher and the saving larger because the 48-item sheet also prices work the earlier piece deliberately left out, security test execution, review reports, photographs, user documentation and third-party due diligence, and because it uses a €90 per hour Western European rate rather than €400 to 600 per day. On the documentation spine the two analyses are consistent. Where figures differ, this article reflects the wider scope and supersedes the earlier numbers.

The two dates to plan around

11 September 2026. Article 14 reporting becomes mandatory for products already on the market. If a vulnerability in your product is being actively exploited, the 24-hour clock starts the moment you become aware. This is not a deadline you can meet by starting to prepare after it arrives. Free gets your intake channel live today, Reporting makes you filing-ready.

11 December 2027. The full CRA applies to every new product placed on the EU market. The complete technical file, the risk assessment, the SBOM, the support period commitment, all of it. The 48-item sheet in this article is what that means in practice, and the earlier you start, the more of the work happens on your schedule instead of an auditor's.

Frequently asked in evaluations

Do you file with the authorities for us?

ENISA provides no submission API yet. The platform produces a complete, field-mapped package for one-step manual submission and will automate filing when an API is published.

Who owns the data?

You do. Full export in CSV and JSON on every tier including Free. If you cancel, your portal becomes read-only and your history and exports remain available.

Does the platform replace a security consultant?

For document production, largely yes. For judgment calls, the platform drafts and your responsible person decides. Nothing ships without your review, and the regulation holds the manufacturer accountable, a responsibility no tool can take on.

We build firmware in Asia and sell in the EU. Does this apply to us?

Yes. The CRA binds whoever places the product on the EU market, wherever development happens. The platform's cost advantage is largest for Western European teams but the compliance obligation, and the coverage, is identical everywhere.

Figures are PERT expected values from a 48-item analysis of the standard CRA technical documentation request sheet, July 2026. Labor rates are estimated fully loaded internal averages per region, in euro. Your numbers will vary with product complexity and team experience. This article is informational and is not legal advice.

Want the numbers for your products?