{"title":"EU Compliance \u0026 Product Regulations – Templates","description":"\u003ch2\u003eEU Compliance \u0026amp; Product Regulations – templates for companies 2026\/2027\u003c\/h2\u003e\n\u003cp\u003eConsolidated category for practical document templates and compliance packages linked to new EU regulations for digital products, product safety, data, platforms, and supply chains. This includes, among other things, templates for the Cyber Resilience Act (CRA), GPSR, EUDR, Digital Services Act, Data Act, and accessibility requirements.\u003c\/p\u003e\n\u003cp\u003eThe purpose is to provide companies with a clear work structure for risk assessment, documentation, reporting, traceability, incident management, and other regulatory compliance. The templates are designed for Swedish operations affected by EU law and are continuously reviewed against the current legal situation.\u003c\/p\u003e","products":[{"product_id":"data-act-mallpaket-2026","title":"Data Act Template Package 2026 – Agreements \u0026 Compliance Word\/PDF\/Excel","description":"\n\u003ch2\u003eData Act Template Package 2026 – agreements, data sharing and cloud switching\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete compliance package for companies affected by the EU Data Act (Regulation (EU) 2023\/2854)\u003c\/strong\u003e. The package is designed for Swedish companies working with connected products, related digital services, data sharing, third-party access, or data processing services such as cloud, SaaS, PaaS, and IaaS.\u003c\/p\u003e\n\n\u003cp\u003eThe Data Act began to apply on \u003cstrong\u003eSeptember 12, 2025\u003c\/strong\u003e. As of \u003cstrong\u003eSeptember 12, 2026\u003c\/strong\u003e, Article 3(1)’s specific design requirements also apply to connected products and related services placed on the market after this date. The package is updated and legally reviewed as of \u003cstrong\u003eOctober 2, 2026\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Holder – User\u003c\/strong\u003e, agreement template in Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eData Holder – User, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Holder – Data Recipient\u003c\/strong\u003e, agreement template in Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eData Holder – Data Recipient, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCloud Switching \u0026amp; Exit Addendum\u003c\/strong\u003e, Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eCloud Switching \u0026amp; Exit Addendum, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Act Compliance Guide \u0026amp; Checklist 2026\u003c\/strong\u003e, Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eData Act Compliance Guide \u0026amp; Checklist 2026, PDF\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Act Compliance 2026 – Excel tool\u003c\/strong\u003e with registers, monitoring, and control\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e1. Agreement between Data Holder and User\u003c\/h3\u003e\n\u003cp\u003eThe first agreement template is intended for the relationship between the entity holding readily available data from a connected product or related service and the user who has rights under the Data Act. The template regulates, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eproduct data and related service data\u003c\/li\u003e\n\n\u003cli\u003edata catalogs, metadata, and technical formats\u003c\/li\u003e\n\n\u003cli\u003edirect and indirect access\u003c\/li\u003e\n\n\u003cli\u003eAPIs, export functions, and other interfaces\u003c\/li\u003e\n\n\u003cli\u003efree access for the user where required by the Data Act\u003c\/li\u003e\n\n\u003cli\u003ethe data holder’s use of non-personal data\u003c\/li\u003e\n\n\u003cli\u003ethe user’s right to request sharing with third parties\u003c\/li\u003e\n\n\u003cli\u003epersonal data and the relationship to the GDPR\u003c\/li\u003e\n\n\u003cli\u003etrade secrets and protective measures\u003c\/li\u003e\n\n\u003cli\u003esecurity limitations\u003c\/li\u003e\n\n\u003cli\u003eprohibited competitive use of data\u003c\/li\u003e\n\n\u003cli\u003eincidents, amendments, and termination\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e2. Agreement between Data Holder and Data Recipient\u003c\/h3\u003e\n\u003cp\u003eThe second agreement template is used when a user requests that a data holder makes data available to an external third party. It is particularly relevant for companies building services on top of IoT, automotive, machine, energy, industrial, or other product data.\u003c\/p\u003e\n\n\u003cp\u003eThe template includes provisions regarding the user’s instruction, data quality, technical delivery, permitted use, further sharing, compensation, trade secrets, personal data, security, and non-discriminatory terms.\u003c\/p\u003e\n\n\u003ch3\u003eReasonable compensation and the SME rule\u003c\/h3\u003e\n\u003cp\u003eWhen Article 9 of the Data Act is applicable, compensation for making data available between businesses must be \u003cstrong\u003enon-discriminatory and reasonable\u003c\/strong\u003e. The package contains a specific compensation annex where costs for, among other things, formats, electronic transfer, and storage can be documented.\u003c\/p\u003e\n\n\u003cp\u003eIf the data recipient is an SME or a qualified non-profit research organization, the compensation may be specifically limited under Article 9(4). The template therefore contains specific fields for SME status and cost documentation.\u003c\/p\u003e\n\n\u003ch3\u003e3. Cloud Switching \u0026amp; Exit Addendum\u003c\/h3\u003e\n\u003cp\u003eThe cloud section is designed for data processing service agreements where the Data Act's rules on provider switching are applicable. It can be used as an addendum to, for example, SaaS, PaaS, or IaaS agreements and regulates, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eswitching to another provider\u003c\/li\u003e\n\n\u003cli\u003eporting to local ICT infrastructure\u003c\/li\u003e\n\n\u003cli\u003eexportable data and digital assets\u003c\/li\u003e\n\n\u003cli\u003enotice period for initiating a switch\u003c\/li\u003e\n\n\u003cli\u003etransition period\u003c\/li\u003e\n\n\u003cli\u003ereasonable technical assistance\u003c\/li\u003e\n\n\u003cli\u003eoperational continuity\u003c\/li\u003e\n\n\u003cli\u003esecurity during transfer\u003c\/li\u003e\n\n\u003cli\u003eAPIs and export formats\u003c\/li\u003e\n\n\u003cli\u003edata retrieval period\u003c\/li\u003e\n\n\u003cli\u003efinal deletion\u003c\/li\u003e\n\n\u003cli\u003eswitching fees and the transition to 2027\u003c\/li\u003e\n\n\u003cli\u003einformation on international governmental access to non-personal data\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant cloud dates\u003c\/h3\u003e\n\u003cp\u003eThe Data Act requires, among other things, that relevant cloud agreements clearly describe the switching process. The maximum notice period to initiate the switching process may generally not exceed \u003cstrong\u003etwo months\u003c\/strong\u003e, and the mandatory maximum transition period is generally \u003cstrong\u003e30 calendar days\u003c\/strong\u003e. Furthermore, the customer must have at least a \u003cstrong\u003e30-calendar-day data retrieval period\u003c\/strong\u003e after the transition period where the rules are applicable.\u003c\/p\u003e\n\n\u003cp\u003eFrom \u003cstrong\u003eJanuary 12, 2027\u003c\/strong\u003e, switching charges under Article 29 must be fully abolished. Until then, only reduced switching charges may be levied within the limits specified by the Data Act.\u003c\/p\u003e\n\n\u003ch3\u003e4. Compliance Guide 2026\u003c\/h3\u003e\n\u003cp\u003eThe guide helps the business determine where the Data Act affects the organization and how implementation can be structured. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003escope test for roles and operations\u003c\/li\u003e\n\n\u003cli\u003eimportant dates\u003c\/li\u003e\n\n\u003cli\u003eproduct and service mapping\u003c\/li\u003e\n\n\u003cli\u003edata mapping\u003c\/li\u003e\n\n\u003cli\u003eArticle 3 design requirements\u003c\/li\u003e\n\n\u003cli\u003euser access and third-party sharing\u003c\/li\u003e\n\n\u003cli\u003etrade secrets\u003c\/li\u003e\n\n\u003cli\u003eB2B compensation\u003c\/li\u003e\n\n\u003cli\u003eunfair unilaterally imposed data terms\u003c\/li\u003e\n\n\u003cli\u003ecloud switching\u003c\/li\u003e\n\n\u003cli\u003eSwedish supplementary legislation and current status\u003c\/li\u003e\n\n\u003cli\u003eimplementation checklist\u003c\/li\u003e\n\n\u003cli\u003elegal sources and EU Commission guidance\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e5. Excel tool for practical implementation\u003c\/h3\u003e\n\u003cp\u003eThe Excel file is built as a working tool, not just an empty table. It contains separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eScope\u003c\/strong\u003e – role assessment and applicability\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eProducts\u003c\/strong\u003e – connected products and related services\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eData Catalog\u003c\/strong\u003e – product data, service data, formats, metadata, and access\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRequests\u003c\/strong\u003e – register of user and third-party requests\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRecipients\u003c\/strong\u003e – data recipients, compensation, and protective measures\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCloud Switching\u003c\/strong\u003e – control of notice period, transition, export, and deletion\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eAgreement Review\u003c\/strong\u003e – risk control for unfair terms under Article 13\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eActions\u003c\/strong\u003e – compliance plan with person responsible, priority, and deadline\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSources\u003c\/strong\u003e – primary EU sources and Swedish legislative status\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe dashboard automatically calculates, among other things, the number of mapped products, open access requests, active data recipients, cloud services needing action, and open compliance actions.\u003c\/p\u003e\n\n\u003ch3\u003eFor connected products after September 12, 2026\u003c\/h3\u003e\n\u003cp\u003eArticle 3(1) implies that relevant connected products and related services placed on the market after September 12, 2026, must be designed so that product data and related service data, including relevant metadata, are by default easily and securely accessible, free of charge, comprehensive, structured, commonly used, and machine-readable, and – where relevant and technically feasible – directly accessible to the user.\u003c\/p\u003e\n\n\u003cp\u003eThis means that the Data Act is not just a legal contractual matter. For many businesses, it is also a matter of product architecture, API design, metadata, user portals, and internal data flows.\u003c\/p\u003e\n\n\u003ch3\u003eTrade secrets\u003c\/h3\u003e\n\u003cp\u003eThe Data Act does not mean that trade secrets must automatically be disclosed without protection, but trade secrets are not a general exception to data access either. The package therefore contains clauses for proportionate technical and organizational protective measures, documentation, and specific handling of situations where the data holder needs to withhold, suspend, or, in exceptional cases, refuse access according to the Data Act’s conditions.\u003c\/p\u003e\n\n\u003ch3\u003eUnfair data terms between businesses\u003c\/h3\u003e\n\u003cp\u003eChapter IV contains specific rules on unilaterally imposed B2B terms regarding data access, data use, liability, and remedies. Certain terms may be directly unfair or presumed to be unfair. The compliance tool therefore contains a specific agreement review tab.\u003c\/p\u003e\n\n\u003ch3\u003eThe EU Commission’s model terms\u003c\/h3\u003e\n\u003cp\u003eThe EU Commission has published non-binding model terms for data access and data use as well as standard clauses for cloud computing contracts. The templates in this package are independently designed Swedish documents that build on the Data Act’s binding requirements and use the Commission’s guidance as support. They are not a verbatim copy of the Commission’s models.\u003c\/p\u003e\n\n\u003ch3\u003eSwedish status 2026\u003c\/h3\u003e\n\u003cp\u003eThe Data Act is an EU regulation and applies directly. Sweden is simultaneously working on supplementary rules regarding, among other things, the competent authority, sanctions, and dispute resolution. SOU 2025:118 has proposed supplementary Swedish legislation and designated the Swedish Post and Telecom Authority (PTS) as the competent authority. As of the product's review date, the Swedish legislative chain is still marked as ongoing, which is taken into account in the guide.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2023\/2854 of the European Parliament and of the Council (Data Act)\u003c\/li\u003e\n\n\u003cli\u003eGDPR – Regulation (EU) 2016\/679, where personal data is processed\u003c\/li\u003e\n\n\u003cli\u003eapplicable Swedish contract and trade secret law\u003c\/li\u003e\n\n\u003cli\u003eEU Commission Data Act FAQ and implementation material\u003c\/li\u003e\n\n\u003cli\u003eEU Commission non-binding MCT\/SCC material\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eSuitable for, among others\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eIoT and hardware companies\u003c\/li\u003e\n\n\u003cli\u003emachine and industrial companies\u003c\/li\u003e\n\n\u003cli\u003eautomotive and mobility services\u003c\/li\u003e\n\n\u003cli\u003eenergy and smart-grid solutions\u003c\/li\u003e\n\n\u003cli\u003eSaaS, PaaS, and IaaS providers\u003c\/li\u003e\n\n\u003cli\u003esystem integrators\u003c\/li\u003e\n\n\u003cli\u003edata and analysis services\u003c\/li\u003e\n\n\u003cli\u003ecompanies receiving product data at the customer’s request\u003c\/li\u003e\n\n\u003cli\u003elegal, compliance, and IT functions\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant to know\u003c\/h3\u003e\n\u003cp\u003eThe Data Act is technically and contractually dependent on the business’s actual products, data flows, roles, and system architecture. The templates must therefore always be adapted. The package does not replace individual legal advice in complex, cross-border, or litigious situations.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-02\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55579233321302,"sku":"DATA-ACT-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/data-act-mallpaket-2026.png?v=1790956180"},{"product_id":"tillganglighetslagen-ehandel-mallpaket-2026","title":"Accessibility Act E-commerce Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003eAccessibility Act for E-commerce 2026 – complete compliance package\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eProfessional template package for Swedish e-commerce companies that need to work in a structured manner with the Act (2023:254) on the Accessibility of Certain Products and Services (LPTT) and the European Accessibility Act (EAA).\u003c\/strong\u003e The package contains ready-to-use Word and PDF templates as well as a comprehensive Excel tool for scope assessment, auditing, defect management, suppliers, feedback, exemptions, and ongoing follow-up.\u003c\/p\u003e\n\n\u003cp\u003eThe Accessibility Act entered into force on \u003cstrong\u003eJune 28, 2025\u003c\/strong\u003e. E-commerce services covered by the act must, among other things, be accessible to persons with disabilities, provide information on the service's accessibility, and ensure that key functions such as identification, electronic signing, security, and payment can be used in an accessible manner.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eInformation on e-commerce service accessibility 2026 – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eInformation on e-commerce service accessibility 2026 – PDF\u003c\/li\u003e\n\n\u003cli\u003eAccessibility routine and compliance policy for e-commerce – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eAccessibility routine and compliance policy for e-commerce – PDF\u003c\/li\u003e\n\n\u003cli\u003eAssessment of exemptions from accessibility requirements – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eAssessment of exemptions from accessibility requirements – PDF\u003c\/li\u003e\n\n\u003cli\u003eAudit log for accessible e-commerce – Word (DOCX)\u003c\/li\u003e\n\n\u003cli\u003eAudit log for accessible e-commerce – PDF\u003c\/li\u003e\n\n\u003cli\u003eAccessibility Act E-commerce 2026 – Excel compliance tool (XLSX)\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e1. Information on the service's accessibility\u003c\/h3\u003e\n\u003cp\u003eA service provider covered by the act must produce information on how the service meets accessibility requirements. The information must, among other things, describe the applicable requirements and, where necessary for the assessment, the design and function of the service.\u003c\/p\u003e\n\n\u003cp\u003eThe template contains ready-made sections for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eservice provider and service\u003c\/li\u003e\n\n\u003cli\u003egeneral description of the e-commerce service\u003c\/li\u003e\n\n\u003cli\u003eapplicable accessibility requirements\u003c\/li\u003e\n\n\u003cli\u003enavigation and keyboard\u003c\/li\u003e\n\n\u003cli\u003etext, contrast, and magnification\u003c\/li\u003e\n\n\u003cli\u003eimages and media\u003c\/li\u003e\n\n\u003cli\u003eforms and error messages\u003c\/li\u003e\n\n\u003cli\u003eshopping cart and checkout\u003c\/li\u003e\n\n\u003cli\u003eidentification, security, and payment\u003c\/li\u003e\n\n\u003cli\u003eaccessibility information for products sold\u003c\/li\u003e\n\n\u003cli\u003ecustomer support\u003c\/li\u003e\n\n\u003cli\u003etesting and quality assurance methods\u003c\/li\u003e\n\n\u003cli\u003eknown defects and action plan\u003c\/li\u003e\n\n\u003cli\u003eany exemptions\u003c\/li\u003e\n\n\u003cli\u003econtact path for accessibility feedback\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe Swedish Post and Telecom Authority (PTS) states that this information serves a similar function to an accessibility statement under the DOS Act, even though the term \u003cem\u003eaccessibility statement\u003c\/em\u003e is not used in the LPTT. The information must be easily accessible along with the service, available to persons with disabilities, and capable of being provided in written and oral form.\u003c\/p\u003e\n\n\u003ch3\u003e2. Internal accessibility routine and compliance policy\u003c\/h3\u003e\n\u003cp\u003eThe internal policy creates an ongoing workflow for compliance. It includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003escope and micro-enterprise assessment\u003c\/li\u003e\n\n\u003cli\u003eresponsibility matrix for management, e-commerce, IT, content, customer service, and legal\u003c\/li\u003e\n\n\u003cli\u003eminimum checks before release\u003c\/li\u003e\n\n\u003cli\u003etest strategy\u003c\/li\u003e\n\n\u003cli\u003eprocess for public accessibility information\u003c\/li\u003e\n\n\u003cli\u003edefect and incident management\u003c\/li\u003e\n\n\u003cli\u003ereporting to authorities\u003c\/li\u003e\n\n\u003cli\u003efeedback and complaint procedure\u003c\/li\u003e\n\n\u003cli\u003erequirements for third-party components and suppliers\u003c\/li\u003e\n\n\u003cli\u003eannual and event-driven review\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e3. Audit log for web shop and app\u003c\/h3\u003e\n\u003cp\u003eThe audit log is a practical working document for testing the parts of the website or app that belong to the e-commerce service. It is structured according to the four fundamental principles:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\u003cstrong\u003ePerceivable\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eOperable\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eUnderstandable\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eRobust\u003c\/strong\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe log also contains specific checks for e-commerce, including accessibility product information, identification, electronic signing, CAPTCHA\/2FA, security functions, payment, order confirmation, and support.\u003c\/p\u003e\n\n\u003cp\u003eEN 301 549 and WCAG are used in the package as practical technical support where relevant. They do not replace the actual legal requirements in the LPTT, the regulation, and the PTS regulations.\u003c\/p\u003e\n\n\u003ch3\u003e4. Exemption assessment – disproportionate burden\u003c\/h3\u003e\n\u003cp\u003eThe LPTT contains the possibility, in certain situations, to make exemptions from a specific accessibility requirement if the application would result in a significant change to the fundamental nature of the service or a disproportionate burden.\u003c\/p\u003e\n\n\u003cp\u003eThe separate assessment template contains:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eidentification of the exact accessibility requirement\u003c\/li\u003e\n\n\u003cli\u003eassessment of alternative solutions\u003c\/li\u003e\n\n\u003cli\u003enet-based cost analysis\u003c\/li\u003e\n\n\u003cli\u003ecost in relation to total costs\u003c\/li\u003e\n\n\u003cli\u003ecost in relation to net turnover\u003c\/li\u003e\n\n\u003cli\u003eassessment of user benefit\u003c\/li\u003e\n\n\u003cli\u003enumber and frequency of use for affected users\u003c\/li\u003e\n\n\u003cli\u003eassessment of external accessibility resources\u003c\/li\u003e\n\n\u003cli\u003edecision, justification, and next reassessment\u003c\/li\u003e\n\n\u003cli\u003efields for reporting to the supervisory authority\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e5. Excel tool for practical implementation\u003c\/h3\u003e\n\u003cp\u003eThe Excel file is a complete working tool and contains separate sheets for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eStart\u003c\/strong\u003e – dashboard with KPIs and legal reference points\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eScope\u003c\/strong\u003e – check of e-commerce service, consumer focus, and micro-enterprise exemption\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eAudit Web\/App\u003c\/strong\u003e – ongoing test register\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCritical Functions\u003c\/strong\u003e – identification, e-signing, security, payment, and order confirmation\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eAccessibility Info\u003c\/strong\u003e – check of public information on service accessibility\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDefects \u0026amp; Actions\u003c\/strong\u003e – prioritization, responsible party, deadline, and re-test\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSupport \u0026amp; Feedback\u003c\/strong\u003e – user complaints and accessibility issues\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eExemptions\u003c\/strong\u003e – documentation of exemption assessments\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSuppliers\u003c\/strong\u003e – third-party components and accessibility documentation\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eTests\u003c\/strong\u003e – test and revision log\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSources\u003c\/strong\u003e – key legal sources and PTS guidance\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe start page automatically calculates, among other things, the number of defects, critical functional defects, open actions, feedback issues, suppliers needing action, exemptions, and overdue reviews.\u003c\/p\u003e\n\n\u003ch3\u003eWhich e-retailers are covered?\u003c\/h3\u003e\n\u003cp\u003eThe Act covers e-commerce services provided at a distance via websites or services for mobile devices, electronically and at the individual request of a consumer for the purpose of concluding a consumer contract.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eMicro-enterprises are exempt from the accessibility requirements for services.\u003c\/strong\u003e According to the act, a micro-enterprise is a company with fewer than ten employees and an annual turnover or annual balance sheet total not exceeding 2 million euros. The package therefore contains a specific scope and micro-enterprise assessment.\u003c\/p\u003e\n\n\u003ch3\u003eWhat is required of the website and app?\u003c\/h3\u003e\n\u003cp\u003eWebsites, web applications, and mobile apps that are part of the service in question must be made accessible in a uniform and functional way by being perceivable, operable, understandable, and robust. In practice, this includes, for example, keyboard usage, focus, alternative texts, contrast, forms, error messages, semantics, support for assistive technologies, and functional user journeys.\u003c\/p\u003e\n\n\u003ch3\u003eSpecific requirements for e-commerce\u003c\/h3\u003e\n\u003cp\u003eIn addition to the general requirements, there are e-commerce-specific requirements. An e-retailer must, among other things, provide accessibility information about the products and services sold when such information is provided by the responsible economic operator.\u003c\/p\u003e\n\n\u003ch3\u003eCustomer support and assistive technologies\u003c\/h3\u003e\n\u003cp\u003eIf the company offers support services, such as a helpdesk or technical support, the support service must be able to provide information about the accessibility of the service and how the service works with assistive technologies. The information must be provided via accessible means of communication.\u003c\/p\u003e\n\n\u003ch3\u003eOngoing responsibility and PTS supervision\u003c\/h3\u003e\n\u003cp\u003eThe service provider must continuously ensure that the service meets accessibility requirements. If a service does not conform to the requirements, the provider must take the necessary measures and immediately inform the supervisory authorities in the Member States where the service is provided about the defect and the measures taken.\u003c\/p\u003e\n\n\u003cp\u003eThe Swedish Post and Telecom Authority (PTS) supervises e-commerce services. During 2025 and 2026, PTS will conduct active supervision of the accessibility of Swedish e-commerce services.\u003c\/p\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eAct (2023:254) on the Accessibility of Certain Products and Services\u003c\/li\u003e\n\n\u003cli\u003eRegulation (2023:676) on the Accessibility of Certain Products and Services\u003c\/li\u003e\n\n\u003cli\u003ePTSFS 2024:6 on the accessibility of certain services\u003c\/li\u003e\n\n\u003cli\u003ePTSFS 2024:7 on criteria for disproportionate burden\u003c\/li\u003e\n\n\u003cli\u003eDirective (EU) 2019\/882 of the European Parliament and of the Council – European Accessibility Act\u003c\/li\u003e\n\n\u003cli\u003eEN 301 549 and WCAG as technical support where relevant\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eSuitable for, among others\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003eweb shops selling to consumers\u003c\/li\u003e\n\n\u003cli\u003ecompanies with Shopify, WooCommerce, or another e-commerce platform\u003c\/li\u003e\n\n\u003cli\u003ecompanies with a mobile app for purchases\u003c\/li\u003e\n\n\u003cli\u003ee-commerce, IT, compliance, and legal departments\u003c\/li\u003e\n\n\u003cli\u003eagencies and consultants assisting e-retailers with accessibility work\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant to know\u003c\/h3\u003e\n\u003cp\u003eWhich parts of a website are covered by the LPTT and what technical measures are required must be assessed based on the actual service. PTS assesses that it is the parts of the website belonging to the e-commerce service that are covered by the requirements for e-commerce. The package is a professional working document and does not replace individual legal or technical advice in complicated cases.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-02\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55580087189846,"sku":"TILLG-EHANDEL-2026","price":149.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/tillganglighetslagen-ehandel-2026.png?v=1790963710"},{"product_id":"leverantorsavtal-supplier-agreement-2026-2027-word-pdf-english-svensk-ratt","title":"Supplier Agreement 2026\/2027 – Word\/PDF + English | Swedish Law","description":"\n\u003ch2\u003eSupplier Agreement Template Package 2026\/2027 – Word\/PDF + English | Swedish Law\u003c\/h2\u003e\n\u003cp\u003eThis is a complete and professional \u003cstrong\u003eSupplier Agreement for ongoing B2B deliveries of goods and\/or services\u003c\/strong\u003e. The package is designed for companies that want to manage their supplier relationship clearly from a purchasing and supply-chain perspective – with concrete rules regarding orders, forecasts, capacity, delivery precision, quality, warranty, product compliance, subcontractors, audits, continuity, GDPR, liability, and termination.\u003c\/p\u003e\n\u003cp\u003eThe template package is \u003cstrong\u003elegally reviewed against applicable Swedish law and current EU regulation as of October 4, 2026\u003c\/strong\u003e and developed for use during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e. It contains a Swedish Supplier Agreement, a complete English-language \u003cstrong\u003eSupplier Agreement\u003c\/strong\u003e based on Swedish law, and a separate detailed user guide.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eDelivery:\u003c\/strong\u003e 3 documents in both Word (DOCX) and PDF – a total of \u003cstrong\u003e6 files, 37 A4 pages, and 12 appendices\/schedules\u003c\/strong\u003e. The product is delivered digitally. No physical goods are shipped.\u003c\/p\u003e\n\n\u003ch3\u003eWhat is included\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eSupplier Agreement 2026\/2027 – Swedish version\u003c\/strong\u003e, 17 pages with 26 contract sections and 12 appendices.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eSupplier Agreement 2026\/2027 – English \/ Swedish law\u003c\/strong\u003e, 17 pages with a corresponding structure and 12 schedules.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eDetailed user guide\u003c\/strong\u003e, 3 pages with legal checklists, a walkthrough of all appendices, and a final checklist.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen is a Supplier Agreement appropriate?\u003c\/h3\u003e\n\u003cp\u003eThe template is intended for an identified supplier relationship between companies, for example when a company continuously buys products, components, spare parts, consumables, manufacturing, support, service, or other services from a supplier.\u003c\/p\u003e\n\u003cp\u003eIt is particularly suitable when the customer wants more control over the supplier's performance than what is typically covered by a simple purchase or standard purchase order.\u003c\/p\u003e\n\n\u003ch3\u003eDifference from Framework Agreements and Customer Agreements\u003c\/h3\u003e\n\u003cp\u003eA \u003cstrong\u003eFramework Agreement\u003c\/strong\u003e is often more neutral and general between parties. A \u003cstrong\u003eCustomer Agreement\u003c\/strong\u003e typically focuses on a supplier's relationship with its customer. This Supplier Agreement, on the other hand, is structured from the \u003cstrong\u003ebuyer's purchasing and supply chain perspective\u003c\/strong\u003e.\u003c\/p\u003e\n\u003cp\u003eThis implies more and clearer clauses regarding, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edelivery precision and lead time,\u003c\/li\u003e\n\n\u003cli\u003eforecasts and reserved capacity,\u003c\/li\u003e\n\n\u003cli\u003echange control for factory, material, process, and subcontractor,\u003c\/li\u003e\n\n\u003cli\u003eroot cause and recurring quality defects,\u003c\/li\u003e\n\n\u003cli\u003eproduct compliance and recalls,\u003c\/li\u003e\n\n\u003cli\u003ecritical subcontractors,\u003c\/li\u003e\n\n\u003cli\u003eaudit\/inspection,\u003c\/li\u003e\n\n\u003cli\u003ebusiness continuity and alternative sources of supply.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e26 contract sections\u003c\/h3\u003e\n\u003cp\u003eThe main agreement includes, among other things:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ebackground and purpose,\u003c\/li\u003e\n\n\u003cli\u003econtract documents and order of priority,\u003c\/li\u003e\n\n\u003cli\u003escope and Orders,\u003c\/li\u003e\n\n\u003cli\u003eforecasts, capacity, and minimum commitments,\u003c\/li\u003e\n\n\u003cli\u003eprices, costs, and price changes,\u003c\/li\u003e\n\n\u003cli\u003einvoicing and payment,\u003c\/li\u003e\n\n\u003cli\u003edelivery of goods,\u003c\/li\u003e\n\n\u003cli\u003eservices and deliverables,\u003c\/li\u003e\n\n\u003cli\u003equality, specification, and change control,\u003c\/li\u003e\n\n\u003cli\u003einspection, acceptance, and claims,\u003c\/li\u003e\n\n\u003cli\u003edefects, warranty, and remedy,\u003c\/li\u003e\n\n\u003cli\u003eproduct compliance, traceability, and recalls,\u003c\/li\u003e\n\n\u003cli\u003esubcontractors and supply chain,\u003c\/li\u003e\n\n\u003cli\u003ebusiness continuity and delivery readiness,\u003c\/li\u003e\n\n\u003cli\u003eaudit and follow-up,\u003c\/li\u003e\n\n\u003cli\u003eintellectual property rights and documentation,\u003c\/li\u003e\n\n\u003cli\u003epersonal data and information security,\u003c\/li\u003e\n\n\u003cli\u003econfidentiality and trade secrets,\u003c\/li\u003e\n\n\u003cli\u003ecompliance, sanctions, and anti-corruption,\u003c\/li\u003e\n\n\u003cli\u003eliability and limitation of liability,\u003c\/li\u003e\n\n\u003cli\u003einsurance,\u003c\/li\u003e\n\n\u003cli\u003eforce majeure,\u003c\/li\u003e\n\n\u003cli\u003eterm, termination, and exit,\u003c\/li\u003e\n\n\u003cli\u003einternational purchases and CISG,\u003c\/li\u003e\n\n\u003cli\u003enotices, assignment, and amendments,\u003c\/li\u003e\n\n\u003cli\u003egoverning law and dispute resolution.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003e12 practical appendices \/ schedules\u003c\/h3\u003e\n\u003col\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eProducts, services, and specifications\u003c\/strong\u003e – product\/SKU, version, criticality, and documentation.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eOrder process, authority, and contacts\u003c\/strong\u003e – order channel, authorized purchasers, and order confirmation.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eForecasts, volumes, and capacity\u003c\/strong\u003e – forecast horizon, binding portion, minimum purchases, reserved capacity, and safety stock.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003ePrice list, indexing, and payment\u003c\/strong\u003e – prices, fees, price change mechanisms, and payment terms.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eDelivery, logistics, and Incoterms\u003c\/strong\u003e – delivery location, Incoterms 2020, lead time, delivery precision, and transfer of risk.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eServices, milestones, and acceptance\u003c\/strong\u003e – deliverables, key personnel, and acceptance criteria.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eQuality, change control, and control plan\u003c\/strong\u003e – quality standard, critical characteristics, and prior approval of changes.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eWarranty, claims, and remedy\u003c\/strong\u003e – warranty period, RMA, response times, and root-cause process.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eProduct compliance, incidents, and recalls\u003c\/strong\u003e – product-specific rules, traceability, documentation, and recalls.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eSubcontractors, audit, and continuity\u003c\/strong\u003e – critical subcontractors, audit, BCP, and alternative supply.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eIP, data, and information security\u003c\/strong\u003e – intellectual property, GDPR, Data Processing Agreement (DPA), and incident reporting.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eCompliance, liability, term, CISG, and dispute\u003c\/strong\u003e – liability caps, insurance, termination, choice of law, and forum.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\n\n\u003ch3\u003eOrders and the supplier's standard terms\u003c\/h3\u003e\n\u003cp\u003eAppendix 2 is used to determine how an Order becomes binding and exactly who is authorized to place orders. The agreement also contains a clear order of priority between the main agreement, appendices, and Orders.\u003c\/p\u003e\n\u003cp\u003eThe supplier's own standard terms do not automatically apply just because they are printed on an order confirmation, invoice, or website. They must be explicitly accepted by the Buyer if they are to take precedence.\u003c\/p\u003e\n\n\u003ch3\u003eForecasts are not the same as a purchase guarantee\u003c\/h3\u003e\n\u003cp\u003eIn many supplier relationships, the customer sends rolling forecasts. A common dispute arises when the supplier perceives the forecast as binding while the customer views it as planning information.\u003c\/p\u003e\n\u003cp\u003eAppendix 3 therefore distinguishes between:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003enon-binding forecasts,\u003c\/li\u003e\n\n\u003cli\u003epotential binding forecast windows,\u003c\/li\u003e\n\n\u003cli\u003eminimum purchases,\u003c\/li\u003e\n\n\u003cli\u003ereserved capacity,\u003c\/li\u003e\n\n\u003cli\u003esafety stock.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eIf any of these are to be binding, it must be explicitly stated.\u003c\/p\u003e\n\n\u003ch3\u003ePrice changes and payment terms\u003c\/h3\u003e\n\u003cp\u003eAppendix 4 makes it possible to use fixed prices, indexing, or other clearly defined pricing formulas. The supplier may not automatically refer to a later price list if the agreement does not permit such a price change.\u003c\/p\u003e\n\u003cp\u003eFor B2B receivables regarding goods and services, the Swedish Interest Act (Räntelagen) stipulates that payment shall generally be made no later than 30 days after a demand for payment. Between businesses, longer payment terms may be used if the creditor has \u003cstrong\u003eexplicitly approved\u003c\/strong\u003e the longer period.\u003c\/p\u003e\n\u003cp\u003eTherefore, the template uses 30 days as the default and marks longer terms as an active contractual choice.\u003c\/p\u003e\n\n\u003ch3\u003eDelivery precision and Incoterms\u003c\/h3\u003e\n\u003cp\u003eFor physical goods, Appendix 5 contains fields for:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edelivery location,\u003c\/li\u003e\n\n\u003cli\u003eIncoterms 2020,\u003c\/li\u003e\n\n\u003cli\u003elead time,\u003c\/li\u003e\n\n\u003cli\u003edelivery precision\/KPI,\u003c\/li\u003e\n\n\u003cli\u003epackaging and labeling,\u003c\/li\u003e\n\n\u003cli\u003etransfer of risk.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eIt is important not only to write, for example, \"FCA\" or \"DAP\" but also to specify the named location to which the chosen Incoterm relates.\u003c\/p\u003e\n\n\u003ch3\u003eThe Swedish Sale of Goods Act – dispositive B2B regulation\u003c\/h3\u003e\n\u003cp\u003eThe Sale of Goods Act (1990:931) applies to the sale of personal property and is largely dispositive (supplementary). This means that the parties can agree on solutions other than the statutory standard rules.\u003c\/p\u003e\n\u003cp\u003eThe Supplier Agreement therefore explicitly regulates, among other things, delivery, inspection, defects, warranty, and liability. In mixed contracts where the service constitutes the predominant part of the supplier's commitment, the Sale of Goods Act generally does not apply to the entire performance.\u003c\/p\u003e\n\n\u003ch3\u003eQuality and change control\u003c\/h3\u003e\n\u003cp\u003eAppendix 7 is designed for supplier relationships where the Buyer needs control over changes that could affect the product or delivery.\u003c\/p\u003e\n\u003cp\u003eThe parties can specify that the supplier must obtain written approval before, for example:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ematerials are replaced,\u003c\/li\u003e\n\n\u003cli\u003eproduction processes are changed,\u003c\/li\u003e\n\n\u003cli\u003emanufacturing sites are relocated,\u003c\/li\u003e\n\n\u003cli\u003edesigns are altered,\u003c\/li\u003e\n\n\u003cli\u003ecritical subcontractors are replaced.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eThis is particularly relevant in industry, component supply, technology, and regulated products.\u003c\/p\u003e\n\n\u003ch3\u003eWarranty, RMA, and root cause\u003c\/h3\u003e\n\u003cp\u003eAppendix 8 contains structured fields for the warranty period, response time for critical failures, RMA\/return process, cost liability, and recurring failures.\u003c\/p\u003e\n\u003cp\u003eIn this way, the agreement can link a quality problem to a concrete remedy process instead of a general formulation stating that the supplier is \"liable for defects.\"\u003c\/p\u003e\n\n\u003ch3\u003eGPSR and product compliance – correct demarcation\u003c\/h3\u003e\n\u003cp\u003eThe EU's \u003cstrong\u003eGeneral Product Safety Regulation (EU) 2023\/988\u003c\/strong\u003e imposes requirements on economic operators that manufacture or supply consumer products within the scope of the regulation. The rules cover, among other things, safety, traceability, technical documentation, and corrective measures.\u003c\/p\u003e\n\u003cp\u003eThe template does not claim that the GPSR automatically applies to all B2B goods. Appendix 9 is used instead to identify which product regulatory framework actually applies, for example:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eGPSR,\u003c\/li\u003e\n\n\u003cli\u003eCE-related harmonization legislation,\u003c\/li\u003e\n\n\u003cli\u003eproduct-specific EU regulations or directives,\u003c\/li\u003e\n\n\u003cli\u003eSwedish special legislation.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eRecall and incident management\u003c\/h3\u003e\n\u003cp\u003eAppendix 9 contains fields for traceability, batch\/serial numbers, technical documentation, incident contacts, and cost principles in the event of a recall.\u003c\/p\u003e\n\u003cp\u003eThis makes it possible to determine in advance how the parties will cooperate during a safety incident or product recall, including who bears which costs.\u003c\/p\u003e\n\n\u003ch3\u003eSubcontractors and supply chain\u003c\/h3\u003e\n\u003cp\u003eThe supplier is fully responsible for its subcontractors. Appendix 10 makes it possible to identify critical supply links and demand prior approval before certain subcontractors or production sites are changed.\u003c\/p\u003e\n\u003cp\u003eRelevant requirements regarding quality, safety, confidentiality, data protection, and compliance can also be passed on through the supply chain.\u003c\/p\u003e\n\n\u003ch3\u003eBusiness Continuity Plan – delivery readiness\u003c\/h3\u003e\n\u003cp\u003eFor critical deliveries, the parties can document:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003esafety stock,\u003c\/li\u003e\n\n\u003cli\u003ealternative production sites,\u003c\/li\u003e\n\n\u003cli\u003ealternative supply sources,\u003c\/li\u003e\n\n\u003cli\u003erecovery time targets,\u003c\/li\u003e\n\n\u003cli\u003eincident contacts,\u003c\/li\u003e\n\n\u003cli\u003ehow often the continuity plan should be tested.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\u003cp\u003eThis makes the agreement useful even for suppliers whose downtime would affect the Buyer's own production or customer deliveries.\u003c\/p\u003e\n\n\u003ch3\u003eAudit – proportional control\u003c\/h3\u003e\n\u003cp\u003eThe agreement includes provisions for supplier follow-up and, when the parties choose, audits. The audit right is intentionally limited to information necessary to verify, for example, quality, invoicing, or essential compliance.\u003c\/p\u003e\n\u003cp\u003eThis avoids a disproportionate audit clause that unnecessarily exposes the supplier's trade secrets.\u003c\/p\u003e\n\n\u003ch3\u003eGDPR and Data Processing Agreement (DPA)\u003c\/h3\u003e\n\u003cp\u003eIf the supplier processes personal data on the Buyer's behalf, the parties normally need a separate data processing agreement under Article 28 of the GDPR.\u003c\/p\u003e\n\u003cp\u003eAppendix 11 is used to document roles, systems, incident deadlines, storage, and deletion, but it does not replace a full DPA when a processor relationship exists.\u003c\/p\u003e\n\n\u003ch3\u003eLiability and insurance\u003c\/h3\u003e\n\u003cp\u003eAppendix 12 contains fill-in fields for liability caps, carve-outs, and insurance levels. The template leaves the amounts open because reasonable liability must be adapted to the contract value, criticality, insurance, and actual risk.\u003c\/p\u003e\n\n\u003ch3\u003eInternational sales of goods and CISG\u003c\/h3\u003e\n\u003cp\u003eFor international sales of goods, the \u003cstrong\u003eCISG\u003c\/strong\u003e and the Act (1987:822) on International Sales of Goods may become applicable. Appendix 12 therefore requires the parties to actively state whether the CISG is to apply or be excluded.\u003c\/p\u003e\n\u003cp\u003eFor purchases where both the seller and the buyer have their places of business in Denmark, Finland, Iceland, Norway, or Sweden, the special Nordic rule in Section 2 of the Act on International Sales of Goods applies.\u003c\/p\u003e\n\n\u003ch3\u003eEnglish Supplier Agreement according to Swedish law\u003c\/h3\u003e\n\u003cp\u003eThe English version contains the same structure and 12 schedules. It is intended for situations where the supplier, customer, group functions, or advisors work in English but \u003cstrong\u003eSwedish substantive law\u003c\/strong\u003e is to be applied.\u003c\/p\u003e\n\u003cp\u003eIt is thus an English-language template based on Swedish law and not a British or American standard agreement.\u003c\/p\u003e\n\n\u003ch3\u003eDetailed user guide included\u003c\/h3\u003e\n\u003cp\u003eThe separate user guide covers:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ewhen a Supplier Agreement is the right form of contract,\u003c\/li\u003e\n\n\u003cli\u003ethe difference between Framework Agreements and Customer Agreements,\u003c\/li\u003e\n\n\u003cli\u003ethe Sale of Goods Act,\u003c\/li\u003e\n\n\u003cli\u003ethe 30-day rule in the Interest Act,\u003c\/li\u003e\n\n\u003cli\u003eCISG,\u003c\/li\u003e\n\n\u003cli\u003eGDPR\/DPA,\u003c\/li\u003e\n\n\u003cli\u003eGPSR and product-specific regulation,\u003c\/li\u003e\n\n\u003cli\u003eall 12 appendices,\u003c\/li\u003e\n\n\u003cli\u003ecommon mistakes to avoid,\u003c\/li\u003e\n\n\u003cli\u003efinal checklist before signing.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eReviewed for 2026\/2027\u003c\/h3\u003e\n\u003cp\u003eThe legal review is dated \u003cstrong\u003eOctober 4, 2026\u003c\/strong\u003e. The package has been checked against, among others:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003ethe Contracts Act (1915:218),\u003c\/li\u003e\n\n\u003cli\u003ethe Sale of Goods Act (1990:931),\u003c\/li\u003e\n\n\u003cli\u003ethe Interest Act (1975:635),\u003c\/li\u003e\n\n\u003cli\u003ethe Act (1987:822) on International Sales of Goods and CISG,\u003c\/li\u003e\n\n\u003cli\u003ethe General Data Protection Regulation (EU) 2016\/679 (GDPR),\u003c\/li\u003e\n\n\u003cli\u003ethe Regulation (EU) 2023\/988 on General Product Safety (GPSR), where applicable,\u003c\/li\u003e\n\n\u003cli\u003ethe Trade Secrets Act (2018:558).\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eFormat and delivery\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3 documents • 6 files • 37 pages • 12 appendices\/schedules\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eWord (DOCX)\u003c\/strong\u003e – fully editable.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003ePDF\u003c\/strong\u003e – for reference, printing, and layout control.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eSwedish + English main agreements\u003c\/strong\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eDigital download\u003c\/strong\u003e – no physical product is sent.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eImportant\u003c\/h3\u003e\n\u003cp\u003eThe template package is a professional general contractual basis and does not replace individual legal advice. Regulated products, medical technology, food, chemicals, vehicles, defense materiel, extensive IT outsourcing, complex international trade, or other high-risk deliveries may require product-specific or industry-specific clauses.\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55594926440790,"sku":"LEVERANTOR-2026-2027","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/leverantorsavtal-2026-2027-hero.png?v=1791087255"},{"product_id":"cyber-resilience-act-cra-compliance-2026-2027-svenska-english-riskbedomning-sbom-incidentrapportering-word-pdf-excel","title":"Cyber Resilience Act (CRA) Compliance 2026\/2027 – Swedish + English | Risk Assessment, SBOM \u0026 Incident Reporting Word\/PDF\/Excel","description":"\n\u003cdiv id=\"om-dokumentmallen\"\u003e\n\n\u003ch2\u003eCyber Resilience Act (CRA) Compliance 2026\/2027 – complete 2-in-1 package\u003c\/h2\u003e\n\n\u003cp\u003eA comprehensive compliance package for companies that \u003cstrong\u003emanufacture, develop, or place products with digital elements on the EU market\u003c\/strong\u003e and need to prepare or document their efforts in accordance with \u003cstrong\u003eRegulation (EU) 2024\/2847 – Cyber Resilience Act (CRA)\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003cp\u003eThe package combines Swedish and English work templates with an advanced Excel register for \u003cstrong\u003ecybersecurity risks, SBOM, vulnerabilities, CRA reporting, and technical documentation\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDelivery:\u003c\/strong\u003e 7 Swedish + 7 English document templates in both Word and PDF formats, plus 1 Excel workbook – a total of \u003cstrong\u003e29 delivery files\u003c\/strong\u003e. The Word\/PDF series comprises a total of \u003cstrong\u003e28 A4 pages per language version\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003cnav aria-label=\"About the document template\" style=\"border:1px solid #dbe4ea;padding:16px;border-radius:10px;background:#f7fafc;margin:18px 0;\"\u003e\n\u003cstrong\u003eAbout the document template\u003c\/strong\u003e\n\u003cul\u003e\n\n\u003cli\u003e\u003ca href=\"#granskad\"\u003eLegally \u0026amp; technically reviewed 2026\/2027\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#datum\"\u003eKey CRA dates 2026–2027\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#detta-ingar\"\u003eIncluded in the package\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#full-compliance\"\u003eBuilt for a complete CRA workflow\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#risk\"\u003eCybersecurity risk assessment\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#sbom\"\u003eSBOM, vulnerabilities \u0026amp; CVD\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#rapportering\"\u003e24h \/ 72h incident and vulnerability reporting\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#teknisk\"\u003eTechnical documentation \u0026amp; conformity\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#support\"\u003eSupport period \u0026amp; security updates\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#excel\"\u003eExcel register for CRA compliance\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#nis2\"\u003eCRA vs. NIS2\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#faq\"\u003eFrequently asked questions\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#kallor\"\u003eLegal basis \u0026amp; sources\u003c\/a\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003c\/nav\u003e\n\n\u003cdiv id=\"granskad\" style=\"border:1px solid #b7dec5;background:#e9f6ee;padding:18px;border-radius:10px;margin:18px 0;\"\u003e\n\n\u003cstrong\u003eLegally and technically reviewed: October 5, 2026\u003c\/strong\u003e\u003cbr\u003e\nThe template package has been reviewed against the Cyber Resilience Act, Regulation (EU) 2024\/2847, including Articles 13–14 as well as Annexes I, II, and VII, and against the European Commission's current implementation and reporting guidance. The package is designed for practical compliance work during \u003cstrong\u003e2026\/2027\u003c\/strong\u003e.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"datum\"\u003eKey CRA dates 2026–2027\u003c\/h2\u003e\n\n\u003cp\u003eThe CRA is already in force, but different obligations become applicable at different times:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSeptember 11, 2026:\u003c\/strong\u003e manufacturers' reporting obligations for actively exploited vulnerabilities and severe incidents became applicable.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDecember 11, 2027:\u003c\/strong\u003e the CRA's main product and cybersecurity requirements become fully applicable.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThis means that organizations should not wait until 2027 to build risk assessments, vulnerability management, reporting routines, technical documentation, and evidence chains.\u003c\/p\u003e\n\n\n\u003ch2 id=\"detta-ingar\"\u003eIncluded in the package\u003c\/h2\u003e\n\n\u003cdiv style=\"overflow-x:auto;\"\u003e\n\n\u003ctable style=\"width:100%;border-collapse:collapse;\"\u003e\n\n\u003cthead\u003e\n\n\u003ctr\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eTemplate \/ Tool\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eSwedish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eEnglish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eFormat\u003c\/th\u003e\n\n\n\u003c\/tr\u003e\n\n\n\u003c\/thead\u003e\n\n\u003ctbody\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCRA Implementation \u0026amp; Compliance Plan\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCybersecurity Risk Assessment\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eVulnerability Management \u0026amp; CVD Policy\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eIncident \u0026amp; Vulnerability Reporting 24h\/72h\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eTechnical Documentation \u0026amp; Conformity Checklist\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eUser Information, Security Updates \u0026amp; Support Period\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDetailed User Guide\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCRA Compliance Register – Risk, SBOM, Vulnerability \u0026amp; Reporting\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd colspan=\"2\" style=\"border:1px solid #d5dde3;padding:10px;\"\u003eBilingual workbook\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eExcel (XLSX)\u003c\/strong\u003e\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\n\u003c\/tbody\u003e\n\n\n\u003c\/table\u003e\n\n\n\u003c\/div\u003e\n\n\n\u003cdiv id=\"full-compliance\" style=\"background:#fff4cc;border-left:5px solid #d9a800;padding:20px;border-radius:8px;margin:22px 0;\"\u003e\n\n\u003cstrong style=\"font-size:1.1em;\"\u003eBuilt for a complete CRA workflow\u003c\/strong\u003e\u003cbr\u003e\nThe CRA is not about a single policy. The company needs to be able to demonstrate how cybersecurity risks are identified and mitigated, how components and vulnerabilities are tracked, how actively exploited vulnerabilities and serious incidents are reported, how technical documentation is compiled, and how security updates are handled during the support period. Therefore, the package links together \u003cstrong\u003egovernance, risk assessment, SBOM, CVD, incident reporting, technical supporting documents, user information, and an Excel register\u003c\/strong\u003e.\n\n\u003c\/div\u003e\n\n\n\u003ch2\u003eWhich companies are affected by the CRA?\u003c\/h2\u003e\n\n\u003cp\u003eThe CRA targets products with digital elements made available on the EU market. This can include both hardware and software, as well as many connected or network-related products.\u003c\/p\u003e\n\n\u003cp\u003eThe package is primarily built for \u003cstrong\u003emanufacturers\u003c\/strong\u003e, but the checklists and user guide also help identify issues that importers and distributors need to verify. The exact role must always be assessed based on the actual supply chain and the product.\u003c\/p\u003e\n\n\n\u003ch2 id=\"risk\"\u003eCybersecurity risk assessment – a core element of the CRA\u003c\/h2\u003e\n\n\u003cp\u003eThe CRA requires the manufacturer to conduct a cybersecurity risk assessment for the product with digital elements and take the result into account during planning, design, development, production, delivery, and maintenance.\u003c\/p\u003e\n\n\u003cp\u003eThe risk template and the Excel register help the organization document:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eproduct, version, and intended use,\u003c\/li\u003e\n\n\u003cli\u003eassets and security-critical functions,\u003c\/li\u003e\n\n\u003cli\u003ethreat and misuse scenarios,\u003c\/li\u003e\n\n\u003cli\u003eprobability and consequence,\u003c\/li\u003e\n\n\u003cli\u003eexisting controls,\u003c\/li\u003e\n\n\u003cli\u003eresidual risk,\u003c\/li\u003e\n\n\u003cli\u003eaction plan, responsible party, and deadline,\u003c\/li\u003e\n\n\u003cli\u003elink to the CRA's essential cybersecurity requirements.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"sbom\"\u003eSBOM, vulnerability management, and Coordinated Vulnerability Disclosure\u003c\/h2\u003e\n\n\u003cp\u003eThe CRA's vulnerability requirements mean that the manufacturer must be able to identify and document vulnerabilities and components included in the product. Annex I stipulates, among other things, that vulnerabilities and components shall be identified and documented, including through a \u003cstrong\u003emachine-readable SBOM\u003c\/strong\u003e that covers at least the product's top-level dependencies.\u003c\/p\u003e\n\n\u003cp\u003eThe package therefore contains:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eSBOM register in Excel,\u003c\/li\u003e\n\n\u003cli\u003ecomponent\/version\/supplier\/PURL\/CPE,\u003c\/li\u003e\n\n\u003cli\u003edirect or transitive dependency,\u003c\/li\u003e\n\n\u003cli\u003eCVE\/advisory and severity,\u003c\/li\u003e\n\n\u003cli\u003efixed version and review date,\u003c\/li\u003e\n\n\u003cli\u003eCVD policy and external vulnerability contact,\u003c\/li\u003e\n\n\u003cli\u003etriage, remediation, and disclosure routine.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"rapportering\"\u003eCRA reporting: 24 hours, 72 hours, and final report\u003c\/h2\u003e\n\n\u003cp\u003eSince September 11, 2026, manufacturers have been required to report \u003cstrong\u003eactively exploited vulnerabilities\u003c\/strong\u003e and \u003cstrong\u003eserious incidents\u003c\/strong\u003e that affect the security of products with digital elements.\u003c\/p\u003e\n\n\u003cp\u003eThe European Commission's reporting guidance outlines the following main points:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ewithin 24 hours:\u003c\/strong\u003e early warning after the organization has become aware,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ewithin 72 hours:\u003c\/strong\u003e full notification,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eactively exploited vulnerability:\u003c\/strong\u003e final report no later than 14 days after the corrective or mitigating measure has become available,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eserious incident:\u003c\/strong\u003e final report within one month of the 72-hour notification.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe Excel file includes a specific sheet for reporting cases where the 24h and 72h deadlines are calculated automatically based on the awareness date and time.\u003c\/p\u003e\n\n\n\u003ch2 id=\"teknisk\"\u003eTechnical documentation – Annex VII\u003c\/h2\u003e\n\n\u003cp\u003eThe CRA's technical documentation shall provide oversight and conformity evidence for the product. The package's technical documentation checklist includes, among other things:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eproduct description and intended use,\u003c\/li\u003e\n\n\u003cli\u003earchitecture, component relationships, and secure development process,\u003c\/li\u003e\n\n\u003cli\u003eSBOM and vulnerability handling,\u003c\/li\u003e\n\n\u003cli\u003ecybersecurity risk assessment,\u003c\/li\u003e\n\n\u003cli\u003esupport period and justification,\u003c\/li\u003e\n\n\u003cli\u003eapplied standards\/specifications,\u003c\/li\u003e\n\n\u003cli\u003etest and verification evidence,\u003c\/li\u003e\n\n\u003cli\u003eEU Declaration of Conformity and release gate.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2\u003eUser information – Annex II\u003c\/h2\u003e\n\n\u003cp\u003eUser information needs, among other things, to enable the user to identify the manufacturer and product, find a contact point for vulnerabilities, understand the intended use and relevant security preconditions, and obtain instructions for secure installation, use, updating, and decommissioning.\u003c\/p\u003e\n\n\u003cp\u003eThe template therefore includes a dedicated worksheet for Annex II-like customer\/user information and a clear field for the \u003cstrong\u003esupport period end date\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003ch2 id=\"support\"\u003eSupport period and security updates\u003c\/h2\u003e\n\n\u003cp\u003eThe manufacturer shall determine a support period that reflects how long the product is reasonably expected to be used, taking into account, among other things, the nature of the product, expected use, and relevant market conditions. The CRA's general rule is that the support period should normally be at least five years, unless the product is not reasonably expected to be used for a shorter period.\u003c\/p\u003e\n\n\u003cp\u003eThe package helps the organization document:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eexpected product lifetime,\u003c\/li\u003e\n\n\u003cli\u003edecided support period,\u003c\/li\u003e\n\n\u003cli\u003ejustification and evidence,\u003c\/li\u003e\n\n\u003cli\u003esecurity updates and distribution,\u003c\/li\u003e\n\n\u003cli\u003eend date to be communicated to users.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe CRA also includes requirements on how long security updates must be kept available. Therefore, the organization should plan for both distribution and long-term availability of relevant updates.\u003c\/p\u003e\n\n\n\u003ch2\u003eConformity assessment, EU Declaration, and CE\u003c\/h2\u003e\n\n\u003cp\u003eWhich conformity assessment path is permitted depends, among other things, on the product's CRA classification. The package contains checkpoints for:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003estandard product\/default category,\u003c\/li\u003e\n\n\u003cli\u003eimportant product class I,\u003c\/li\u003e\n\n\u003cli\u003eimportant product class II,\u003c\/li\u003e\n\n\u003cli\u003ecritical product,\u003c\/li\u003e\n\n\u003cli\u003eapplicable standards\/specifications,\u003c\/li\u003e\n\n\u003cli\u003eany notified body,\u003c\/li\u003e\n\n\u003cli\u003eEU Declaration of Conformity,\u003c\/li\u003e\n\n\u003cli\u003eCE release gate.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template does not replace a formal product classification or external conformity assessment when such is required.\u003c\/p\u003e\n\n\n\u003ch2 id=\"excel\"\u003eExcel register – more than a static checklist\u003c\/h2\u003e\n\n\u003cp\u003eThe included XLSX file is a practical compliance register with separate tabs for:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDashboard\u003c\/strong\u003e – key performance indicators and key CRA dates,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eProduct Register\u003c\/strong\u003e – products, versions, classification, and support period,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRisk Register\u003c\/strong\u003e – risk level and action plan,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSBOM\u003c\/strong\u003e – components, version data, and vulnerability link,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eVulnerability Register\u003c\/strong\u003e – CVE\/advisories, severity, and status,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eReporting Deadlines\u003c\/strong\u003e – automatic 24h\/72h deadlines,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eEvidence Checklist\u003c\/strong\u003e – technical documentation and evidence chain,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSources\u003c\/strong\u003e – key official CRA sources.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe workbook contains data validation, risk level formulas, and automated deadline calculations, but is designed so that the user can further build upon it.\u003c\/p\u003e\n\n\n\u003ch2 id=\"nis2\"\u003eCRA vs. NIS2 – different focus\u003c\/h2\u003e\n\n\u003cp\u003eThe CRA and NIS2 can both be relevant to the same organization, but they have different focuses. The CRA is primarily a \u003cstrong\u003eproduct regulation\u003c\/strong\u003e for cybersecurity in products with digital elements and their vulnerability management. NIS2\/cybersecurity regulation focuses to a greater extent on organizations' risk management and incident reporting as entities providing essential or important services.\u003c\/p\u003e\n\n\u003cp\u003eThe new CRA package therefore complements the Mallbutiken existing NIS2 package rather than replacing it.\u003c\/p\u003e\n\n\n\u003ch2\u003eSanctions – why documentation matters\u003c\/h2\u003e\n\n\u003cp\u003eThe CRA contains significant administrative sanction levels. For certain central infringements, maximum administrative fines can amount to \u003cstrong\u003e15 million euros or 2.5 percent of total global annual turnover\u003c\/strong\u003e, whichever is higher and subject to the conditions and exemptions stipulated in the regulation.\u003c\/p\u003e\n\n\u003cp\u003ePractical and dated documentation is therefore important not only for implementation but also to be able to demonstrate how the organization has actually worked with compliance.\u003c\/p\u003e\n\n\n\u003ch2\u003eRecommended workflow\u003c\/h2\u003e\n\n\u003col\u003e\n\n\u003cli\u003eIdentify products and economic operator role.\u003c\/li\u003e\n\n\u003cli\u003eClassify the product according to the CRA.\u003c\/li\u003e\n\n\u003cli\u003eConduct and document the cybersecurity risk assessment.\u003c\/li\u003e\n\n\u003cli\u003eBuild SBOM and CVD\/vulnerability process.\u003c\/li\u003e\n\n\u003cli\u003eDetermine support period and update strategy.\u003c\/li\u003e\n\n\u003cli\u003ePrepare technical documentation and user information.\u003c\/li\u003e\n\n\u003cli\u003eSet up 24h\/72h reporting and chain of responsibility.\u003c\/li\u003e\n\n\u003cli\u003eConduct conformity assessment and collect evidence.\u003c\/li\u003e\n\n\u003cli\u003eKeep registers updated after release and during the support period.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003c\/li\u003e\n\u003c\/ol\u003e\n\n\n\u003ch2 id=\"faq\"\u003eFrequently asked questions about the CRA\u003c\/h2\u003e\n\n\u003ch3\u003eAre the reporting requirements already in effect?\u003c\/h3\u003e\n\n\u003cp\u003eYes. Manufacturers' CRA reporting obligations for actively exploited vulnerabilities and serious incidents became applicable on September 11, 2026.\u003c\/p\u003e\n\n\n\u003ch3\u003eWhen does the main part of the CRA come into effect?\u003c\/h3\u003e\n\n\u003cp\u003eThe main application begins on December 11, 2027.\u003c\/p\u003e\n\n\n\u003ch3\u003eDo we need an SBOM?\u003c\/h3\u003e\n\n\u003cp\u003eThe CRA's vulnerability handling requirements include documentation of components and vulnerabilities, including a machine-readable SBOM that covers at least top-level dependencies.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs the CRA the same thing as NIS2?\u003c\/h3\u003e\n\n\u003cp\u003eNo. The CRA focuses on products with digital elements and the product's cybersecurity lifecycle. NIS2 has a different organizational and operational focus. A company may be affected by both.\u003c\/p\u003e\n\n\n\u003ch3\u003eDoes the CRA only apply to hardware?\u003c\/h3\u003e\n\n\u003cp\u003eNo. The regulation covers products with digital elements and can include both hardware and software depending on the product and market situation.\u003c\/p\u003e\n\n\n\u003ch3\u003eAre Swedish and English templates included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. All seven Word\/PDF documents are available in both Swedish and English.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs Excel included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. The package contains a separate XLSX workbook for product registers, risks, SBOM, vulnerabilities, reporting deadlines, and evidence.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs this a certification?\u003c\/h3\u003e\n\n\u003cp\u003eNo. The package is a professional documentation and work support tool. It does not replace a notified body, product testing, external cybersecurity testing, or individual legal assessment when such is required.\u003c\/p\u003e\n\n\n\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\u003cstrong\u003e7 Swedish document templates + 7 English document templates.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e14 DOCX + 14 PDF + 1 XLSX = 29 files in total.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e28 A4 pages per Word\/PDF format series.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eExcel workbook with 8 compliance tabs.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eDigital product – no physical goods are shipped.\u003c\/strong\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"kallor\"\u003eLegal basis and official sources\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2024\/2847 – Cyber Resilience Act.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-summary\"\u003eEuropean Commission – Cyber Resilience Act summary\u003c\/a\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-reporting\"\u003eEuropean Commission – CRA reporting obligations\u003c\/a\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/factpages\/cyber-resilience-act-implementation\"\u003eEuropean Commission – CRA implementation\u003c\/a\u003e.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003ca href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/2847\/oj\"\u003eEUR-Lex – Regulation (EU) 2024\/2847\u003c\/a\u003e.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003cdiv style=\"background:#f3f5f7;border:1px solid #d5dde3;padding:16px;border-radius:8px;margin-top:20px;\"\u003e\n\n\u003cstrong\u003eImportant:\u003c\/strong\u003e The CRA is a technical and legal product regulation. Product classification, conformity assessment, applicable standards, and reporting obligations must be verified based on the actual product, the role of the economic operator, and the distribution model. The template package is a structured working and documentation aid – not a guarantee of full compliance in every individual situation.\n\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55614949949782,"sku":"CRA-COMPLIANCE-2026-2027","price":79.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/cra-compliance-mallpaket-2026-2027.png?v=1791238292"},{"product_id":"gpsr-produktsakerhet-recall-compliance-2026-2027-svenska-english-riskbedomning-safety-gate-guide-word-pdf-excel","title":"GPSR Product Safety \u0026 Recall Compliance 2026\/2027 – Swedish + English | Risk Assessment, Safety Gate \u0026 Guide Word\/PDF\/Excel","description":"\n\u003cdiv id=\"om-dokumentmallen\"\u003e\n\n\u003ch2\u003eGPSR Product Safety \u0026amp; Recall Compliance 2026\/2027 – complete template package\u003c\/h2\u003e\n\n\u003cp\u003eA complete compliance package for companies that manufacture, import, distribute, or sell consumer products in the EU in accordance with the \u003cstrong\u003eGeneral Product Safety Regulation (EU) 2023\/988 – GPSR\u003c\/strong\u003e. The package is built for practical work with product safety before products are placed on the market and after they have started being sold.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e2-in-1 Swedish + English:\u003c\/strong\u003e 7 Swedish and 7 English document templates in Word and PDF, as well as an advanced Excel register for product portfolios, risks, traceability, online offers, accidents, corrective actions, and recalls. A total of \u003cstrong\u003e29 delivery files\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003cnav aria-label=\"About the document template\" style=\"border:1px solid #dbe4ea;padding:16px;border-radius:10px;background:#f7fafc;margin:18px 0;\"\u003e\n\u003cstrong\u003eAbout the document template\u003c\/strong\u003e\n\u003cul\u003e\n\n\u003cli\u003e\u003ca href=\"#granskad\"\u003eLegally and operationally reviewed 2026\/2027\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#detta-ingar\"\u003eIncluded in the package\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#byggd-for\"\u003eBuilt for a complete GPSR workflow\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#riskanalys\"\u003eInternal product safety risk assessment\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#artikel19\"\u003eArticle 19 – e-commerce and distance selling\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#olyckor\"\u003eAccidents \u0026amp; Safety Business Gateway\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#recall\"\u003eRecall, Article 36, and remedies under Article 37\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#excel\"\u003eExcel register and operational follow-up\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#faq\"\u003eFrequently Asked Questions\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#kallor\"\u003eLegal basis and official sources\u003c\/a\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003c\/nav\u003e\n\n\u003cdiv id=\"granskad\" style=\"border:1px solid #b7dec5;background:#e9f6ee;padding:18px;border-radius:10px;margin:18px 0;\"\u003e\n\n\u003cstrong\u003eLegally and operationally reviewed: October 5, 2026\u003c\/strong\u003e\u003cbr\u003e\nThe package has been reviewed against the consolidated version of \u003cstrong\u003eRegulation (EU) 2023\/988\u003c\/strong\u003e and the European Commission's current guidance on product safety. The GPSR has been applied since \u003cstrong\u003eDecember 13, 2024\u003c\/strong\u003e. The templates are designed for work during 2026\/2027 but must always be adapted to the product category, any sector-specific EU legislation, and the company's economic role.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"detta-ingar\"\u003eIncluded in the package\u003c\/h2\u003e\n\n\u003cdiv style=\"overflow-x:auto;\"\u003e\n\n\u003ctable style=\"width:100%;border-collapse:collapse;\"\u003e\n\n\u003cthead\u003e\u003ctr\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eDocument \/ tool\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eSwedish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eEnglish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003ePurpose\u003c\/th\u003e\n\n\n\u003c\/tr\u003e\u003c\/thead\u003e\n\n\u003ctbody\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCompliance plan \u0026amp; role assessment\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eScope, economic role, responsible person, release gate, and implementation.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eProduct safety risk assessment\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eHazards, probability, severity, controls, and residual risk.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eTraceability \u0026amp; online sales\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eProduct ID, economic operators, and Article 19 checklist for e-commerce.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eAccident report \u0026amp; Safety Business Gateway\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 20 intake, trigger assessment, official reporting, and follow-up.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eRecall plan \u0026amp; recall notice\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eDirect consumer contact, Article 36 format, remedies, and effectiveness.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eTechnical documentation \u0026amp; evidence checklist\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 9 documentation, test evidence, labeling, complaints, and retention.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDetailed user guide\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eWord + PDF\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eStep-by-step from scope to recall and specialist escalation.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eGPSR Product Safety \u0026amp; Recall Register\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd colspan=\"2\" style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eExcel (XLSX)\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e9 worksheets for KPI, products, risks, traceability, online audit, accidents, corrective actions, recall, and evidence.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\n\u003c\/tbody\u003e\n\n\n\u003c\/table\u003e\n\n\n\u003c\/div\u003e\n\n\n\u003cdiv id=\"byggd-for\" style=\"background:#fff4cc;border-left:5px solid #d9a800;padding:20px;border-radius:8px;margin:22px 0;\"\u003e\n\n\u003cstrong style=\"font-size:1.1em;\"\u003eBuilt for a complete GPSR workflow\u003c\/strong\u003e\u003cbr\u003e\nThe GPSR is not just a recall regulation. The regulation requires companies to work in a structured manner even \u003cstrong\u003ebefore market release\u003c\/strong\u003e with safety, internal risk analysis, technical documentation, product identification, and responsible economic operators – and subsequently with complaints, accidents, corrective actions, online information, and recalls. The package ties the entire process together in the same document structure.\n\n\u003c\/div\u003e\n\n\n\u003ch2\u003eWhich companies can benefit from the package?\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eManufacturers of consumer products,\u003c\/li\u003e\n\n\u003cli\u003eImporters from countries outside the EU,\u003c\/li\u003e\n\n\u003cli\u003eDistributors and wholesalers,\u003c\/li\u003e\n\n\u003cli\u003eE-retailers and D2C brands,\u003c\/li\u003e\n\n\u003cli\u003eCompanies that sell via marketplaces,\u003c\/li\u003e\n\n\u003cli\u003eCompliance, quality, and product safety teams,\u003c\/li\u003e\n\n\u003cli\u003eCompanies that need to document a responsible economic operator in the EU.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe package is particularly relevant for non-food products where the GPSR applies directly or serves as a safety net alongside other sector-specific product legislation.\u003c\/p\u003e\n\n\n\u003ch2\u003eThe GPSR has applied since December 13, 2024\u003c\/h2\u003e\n\n\u003cp\u003eThe General Product Safety Regulation replaced the older General Product Safety Directive and modernized the EU's rules for safe consumer products. The framework explicitly takes greater account of e-commerce, direct imports, digital features, traceability, accident reporting, and more effective recalls.\u003c\/p\u003e\n\n\u003cp\u003eCompanies should therefore not use older product safety routines without verifying that they cover the new GPSR requirements.\u003c\/p\u003e\n\n\n\u003ch2 id=\"riskanalys\"\u003eInternal risk analysis and technical documentation – Article 9\u003c\/h2\u003e\n\n\u003cp\u003eBefore a manufacturer places a product on the market, an \u003cstrong\u003einternal risk analysis\u003c\/strong\u003e must be conducted and technical documentation established. The documentation must at least contain a general product description and the characteristics relevant for the safety assessment.\u003c\/p\u003e\n\n\u003cp\u003eWhen the risks of the product warrant it, the documentation shall, among other things:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eidentify hazards and risk scenarios,\u003c\/li\u003e\n\n\u003cli\u003edocument solutions that eliminate or reduce risk,\u003c\/li\u003e\n\n\u003cli\u003einclude relevant test results,\u003c\/li\u003e\n\n\u003cli\u003estate applied European standards or other relevant safety documentation,\u003c\/li\u003e\n\n\u003cli\u003edocument residual risk and the decision on an acceptable safety level.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe technical documentation must be kept up to date and be available to market surveillance authorities for \u003cstrong\u003e10 years after market release\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003ch2\u003eProduct identification and economic operator in the EU\u003c\/h2\u003e\n\n\u003cp\u003eProducts must be identifiable through, for example, type, batch, or serial number or other identifiers. The manufacturer must also provide their name\/brand and contact details.\u003c\/p\u003e\n\n\u003cp\u003eThe GPSR also contains requirements that there must be a \u003cstrong\u003eresponsible economic operator established in the EU\u003c\/strong\u003e for products covered by the regulation. When the manufacturer is outside the EU, this control becomes particularly important for importers and e-retailers.\u003c\/p\u003e\n\n\n\u003ch2 id=\"artikel19\"\u003eArticle 19 – specific requirements for e-commerce and distance selling\u003c\/h2\u003e\n\n\u003cp\u003eThe GPSR requires that an online offer clearly and visibly displays certain information. The package's Article 19 audit and Excel register help companies verify that the product listing contains:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ethe manufacturer's name\/registered trade name or brand,\u003c\/li\u003e\n\n\u003cli\u003ethe manufacturer's postal address and electronic address,\u003c\/li\u003e\n\n\u003cli\u003eif the manufacturer is outside the EU: the name of the responsible person and their postal and electronic address,\u003c\/li\u003e\n\n\u003cli\u003eproduct image, type, and other identification information,\u003c\/li\u003e\n\n\u003cli\u003erelevant warnings and safety information in a language that the consumer can understand.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThis is particularly relevant for Shopify, marketplaces, and other e-commerce channels because a correct physical label does not automatically mean that the online offer fulfills Article 19.\u003c\/p\u003e\n\n\n\u003ch2\u003eComplaints and after-market monitoring\u003c\/h2\u003e\n\n\u003cp\u003eProduct safety work does not end when the product is launched. Companies need functioning contact paths and internal registers for safety-related complaints and signals from customers, distributors, importers, and other actors.\u003c\/p\u003e\n\n\u003cp\u003eThe package helps link a complaint to the correct product, batch, and risk assessment and determine whether corrective action, sales stop, withdrawal, safety warning, or recall needs to be considered.\u003c\/p\u003e\n\n\n\u003ch2 id=\"olyckor\"\u003eAccidents and Safety Business Gateway – Article 20\u003c\/h2\u003e\n\n\u003cp\u003eWhen a product made available on the market causes a relevant accident, the manufacturer must ensure that the accident is reported via the \u003cstrong\u003eSafety Business Gateway\u003c\/strong\u003e to the competent authority in the member state where the accident occurred, without undue delay after the manufacturer becomes aware of it.\u003c\/p\u003e\n\n\u003cp\u003eArticle 20 covers, among other things, events that have led to:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003edeath, or\u003c\/li\u003e\n\n\u003cli\u003eserious permanent or temporary adverse effects on a person's health or safety.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eImporters and distributors who become aware of such an accident must inform the manufacturer without undue delay. The accident template in the package is therefore structured around time of awareness, product ID, country, injury report, trigger assessment, reporting reference, and corrective action.\u003c\/p\u003e\n\n\n\u003ch2\u003eSafety Gate and Safety Business Gateway – not the same thing\u003c\/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eSafety Gate\u003c\/strong\u003e is the EU's rapid alert system and public ecosystem for dangerous non-food products. \u003cstrong\u003eSafety Business Gateway\u003c\/strong\u003e is the business-oriented channel for submitting certain product safety information to authorities.\u003c\/p\u003e\n\n\u003cp\u003eThe user guide explains the difference so that regulatory authority reporting is not confused with public consumer communication.\u003c\/p\u003e\n\n\n\u003ch2 id=\"recall\"\u003eRecall and direct consumer contact – Article 35\u003c\/h2\u003e\n\n\u003cp\u003eIn the event of a product safety recall or safety warning, identifiable affected consumers must be contacted \u003cstrong\u003edirectly and without undue delay\u003c\/strong\u003e. Companies that have customer data must use it for recalls and safety warnings in accordance with the conditions stated in the GPSR.\u003c\/p\u003e\n\n\u003cp\u003eIf not all affected consumers can be reached directly, the information must be disseminated clearly through other appropriate channels for the greatest possible reach, for example, websites, social media, newsletters, stores, or other communication channels.\u003c\/p\u003e\n\n\n\u003ch2\u003eArticle 36 – what a recall notice must contain\u003c\/h2\u003e\n\n\u003cp\u003eWhen written recall information is provided, it must be formulated as a \u003cstrong\u003eproduct safety recall notice\u003c\/strong\u003e. The package contains a separate work template that helps the company include:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ethe headline Product safety recall,\u003c\/li\u003e\n\n\u003cli\u003eproduct image, name, and brand,\u003c\/li\u003e\n\n\u003cli\u003ebatch\/serial number and instructions on where the identifier is found,\u003c\/li\u003e\n\n\u003cli\u003einformation on when, where,  and by whom the product was sold, when such information is available,\u003c\/li\u003e\n\n\u003cli\u003ea clear description of the hazard,\u003c\/li\u003e\n\n\u003cli\u003einstructions to immediately stop using the product,\u003c\/li\u003e\n\n\u003cli\u003ethe remedies offered,\u003c\/li\u003e\n\n\u003cli\u003ea toll-free phone number or interactive online service,\u003c\/li\u003e\n\n\u003cli\u003ea request to spread the recall information when appropriate.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe GPSR also states that phrasing that downplays the perception of risk should be avoided in the recall notice.\u003c\/p\u003e\n\n\n\u003ch2\u003eArticle 37 – repair, replacement, or refund\u003c\/h2\u003e\n\n\u003cp\u003eIn the event of a product safety recall, the consumer must be offered an \u003cstrong\u003eeffective, free, and fast remedy\u003c\/strong\u003e. As a general rule, the consumer must be able to choose between at least two of the following:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003erepair of the recalled product,\u003c\/li\u003e\n\n\u003cli\u003ereplacement with a safe product of the same type and at least the same value and quality,\u003c\/li\u003e\n\n\u003cli\u003eadequate refund that at least corresponds to the price the consumer paid.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eExceptions exist when other alternatives are impossible or would entail disproportionate costs in accordance with the regulation's conditions.\u003c\/p\u003e\n\n\n\u003ch2 id=\"excel\"\u003eExcel register – operational GPSR control\u003c\/h2\u003e\n\n\u003cp\u003eThe package's XLSX workbook is built as a living compliance tool and contains nine worksheets:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDashboard\u003c\/strong\u003e – KPI for products, open risks, incidents, and recalls.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eProduct Register\u003c\/strong\u003e – economic role, markets, and GPSR scope.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRisk Register\u003c\/strong\u003e – likelihood × severity with automatic risk classification.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eTraceability\u003c\/strong\u003e – suppliers, importers, distributors, and product ID.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eOnline Offer Audit\u003c\/strong\u003e – Article 19 control for product listings.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eAccidents \u0026amp; Incidents\u003c\/strong\u003e – time of awareness, Article 20, and Safety Business Gateway.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eCorrective Actions\u003c\/strong\u003e – stop sale, withdrawal, warning, and recall.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eRecall Notice Checklist\u003c\/strong\u003e – Article 36 and Article 37.\u003c\/li\u003e\n\n\u003cli\u003e\n\u003cstrong\u003eEvidence Checklist \/ Sources\u003c\/strong\u003e – evidence documentation and legal sources.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2\u003eThe difference between GPSR and CE marking\u003c\/h2\u003e\n\n\u003cp\u003eThe GPSR does not automatically replace sector-specific EU harmonization legislation. Many product groups are covered by specific rules, including CE-related requirements. At the same time, the GPSR can serve as a safety net for risks that are not fully regulated by such special legislation.\u003c\/p\u003e\n\n\u003cp\u003eTherefore, the package's compliance plan always begins with a \u003cstrong\u003escope and regulatory assessment\u003c\/strong\u003e before risk checklists are used.\u003c\/p\u003e\n\n\n\u003ch2\u003eThe difference between GPSR and supplier agreements\u003c\/h2\u003e\n\n\u003cp\u003eThe template shop's supplier agreements can regulate product compliance, quality requirements, recall, and liability between two companies. This GPSR package has a different purpose: to help the organization document and manage its \u003cstrong\u003eown regulatory product safety process\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003ch2 id=\"faq\"\u003eFrequently asked questions about GPSR\u003c\/h2\u003e\n\n\u003ch3\u003eWhen did the GPSR start to apply?\u003c\/h3\u003e\n\n\u003cp\u003eThe regulation has been applied since December 13, 2024.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs the GPSR only for manufacturers?\u003c\/h3\u003e\n\n\u003cp\u003eNo. Manufacturers have central obligations, but importers, distributors, responsible persons in the EU, and online marketplaces may also be covered by specific GPSR requirements.\u003c\/p\u003e\n\n\n\u003ch3\u003eMust we have a risk assessment?\u003c\/h3\u003e\n\n\u003cp\u003eManufacturers must conduct an internal risk analysis before the product is placed on the market and establish relevant technical documentation.\u003c\/p\u003e\n\n\n\u003ch3\u003eDoes Article 19 also apply to a Shopify store?\u003c\/h3\u003e\n\n\u003cp\u003eIf products are offered online or through other distance selling, the offer is covered by Article 19. The product information therefore needs to be reviewed as an online offer, not just as physical labeling.\u003c\/p\u003e\n\n\n\u003ch3\u003eWhat is the Safety Business Gateway?\u003c\/h3\u003e\n\n\u003cp\u003eIt is the EU's business channel for certain product safety reporting to competent authorities, including relevant accident reporting according to Article 20.\u003c\/p\u003e\n\n\n\u003ch3\u003eMust we contact customers directly during a recall?\u003c\/h3\u003e\n\n\u003cp\u003eIdentifiable affected consumers must be contacted directly and without undue delay during a recall\/safety warning according to Article 35.\u003c\/p\u003e\n\n\n\u003ch3\u003eHow long should technical documentation be saved?\u003c\/h3\u003e\n\n\u003cp\u003eThe manufacturer's technical documentation must be kept available for market surveillance authorities for 10 years after the product has been placed on the market.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs Excel included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. The Excel register is a central part of the package and is used for operational follow-up.\u003c\/p\u003e\n\n\n\u003ch3\u003eAre English documents included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. All seven documents are available in both Swedish and English versions.\u003c\/p\u003e\n\n\n\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003e14 document templates\u003c\/strong\u003e – 7 Swedish + 7 English.\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e28 Word\/PDF files.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e1 Excel register.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e29 files total.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e28 A4 pages per format series across both language versions.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eDigital product – no physical item is sent.\u003c\/strong\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"kallor\"\u003eLegal basis and official sources\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:02023R0988-20260529\"\u003eEUR-Lex – Regulation (EU) 2023\/988, consolidated version\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/commission.europa.eu\/topics\/business-and-industry\/product-safety_en\"\u003eEuropean Commission – Product safety\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"https:\/\/ec.europa.eu\/safety-gate\/\"\u003eSafety Gate\u003c\/a\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003cdiv style=\"background:#f3f5f7;border:1px solid #d5dde3;padding:16px;border-radius:8px;margin-top:20px;\"\u003e\n\n\u003cstrong\u003eImportant:\u003c\/strong\u003e These are general compliance and document templates and do not replace individual legal, technical, or product safety advice. High-risk products, sector-specific CE regulations, serious accidents, regulatory matters, or multinational recalls should be handled with relevant specialist expertise.\n\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55615049007446,"sku":"GPSR-COMPLIANCE-2026-2027","price":79.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/gpsr-produktsakerhet-compliance-2026-2027.png?v=1791239783"},{"product_id":"eudr-due-diligence-2026-2027-svenska-english-geolokalisering-riskbedomning-dds-word-pdf-excel","title":"EUDR Due Diligence 2026\/2027 – Swedish + English | Geolocation, Risk Assessment \u0026 DDS Word\/PDF\/Excel","description":"\n\u003cdiv id=\"om-dokumentmallen\"\u003e\n\n\u003ch2\u003eEUDR Due Diligence 2026\/2027 – complete compliance package in Swedish + English\u003c\/h2\u003e\n\n\u003cp\u003eThis is a complete work and document package for companies that need to prepare for or implement compliance with the \u003cstrong\u003eEU Deforestation Regulation, EUDR – Regulation (EU) 2023\/1115\u003c\/strong\u003e. The package is built for the \u003cstrong\u003ecurrent 2026\/2027 legal model\u003c\/strong\u003e and takes into account the simplifications and amendments introduced after the original regulation.\u003c\/p\u003e\n\n\n\u003cp\u003eThe package helps the business move from product and role assessment to information gathering, geolocation, country benchmarking, risk assessment, risk mitigation, Due Diligence Statement (DDS) or simplified declaration where applicable, as well as downstream\/trader traceability and five-year documentation.\u003c\/p\u003e\n\n\n\u003cp\u003e\u003cstrong\u003e2-in-1 + Excel:\u003c\/strong\u003e you receive \u003cstrong\u003e7 Swedish + 7 English document templates\u003c\/strong\u003e, all in both Word (DOCX) and PDF, as well as a separate professional Excel register. A total of \u003cstrong\u003e29 delivery files\u003c\/strong\u003e and \u003cstrong\u003e42 A4 pages per format series across Swedish + English\u003c\/strong\u003e.\u003c\/p\u003e\n\n\n\u003cnav aria-label=\"About the document template\" style=\"border:1px solid #dbe4ea;padding:16px;border-radius:10px;background:#f7fafc;margin:18px 0;\"\u003e\n\u003cstrong\u003eAbout the document template\u003c\/strong\u003e\n\u003cul\u003e\n\n\u003cli\u003e\u003ca href=\"#granskad\"\u003eLegally reviewed 2026\/2027\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#detta-ingar\"\u003eIncluded in the package\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#tidskritiskt\"\u003eApplication date 30 December 2026 \/ 30 June 2027\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#roller\"\u003eWhat is the company's EUDR role?\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#scope\"\u003eProducts and commodities covered\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#artikel9\"\u003eArticle 9 – information and geolocation\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#risk\"\u003eRisk assessment, country benchmarking, and risk mitigation\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#dds\"\u003eDDS and simplified Article 4a declaration\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#downstream\"\u003eDownstream operators and traders\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#excel\"\u003eExcel – operational EUDR register\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#faq\"\u003eFrequently asked questions\u003c\/a\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003ca href=\"#kallor\"\u003eLegal basis and regulatory sources\u003c\/a\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003c\/nav\u003e\n\n\u003cdiv id=\"granskad\" style=\"border:1px solid #b7dec5;background:#e9f6ee;padding:18px;border-radius:10px;margin:18px 0;\"\u003e\n\n\u003cstrong\u003eLegally and regulatorily reviewed: 6 October 2026\u003c\/strong\u003e\u003cbr\u003e\nThe template package is updated according to the consolidated EUDR regulation and the amendments applicable in 2026\/2027, including amended application dates, simplified obligations for micro and small primary producers, the revised model for downstream operators and traders, current country benchmarking, and the updated product scope. The content is intended as a structured compliance basis – the actual assessment of products, CN codes, countries, and suppliers must always be performed by the business itself.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"detta-ingar\"\u003eIncluded in the package\u003c\/h2\u003e\n\n\u003cdiv style=\"overflow-x:auto;\"\u003e\n\n\u003ctable style=\"width:100%;border-collapse:collapse;\"\u003e\n\n\u003cthead\u003e\u003ctr\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eTemplate \/ Register\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eSwedish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eEnglish\u003c\/th\u003e\n\n\u003cth style=\"text-align:left;border:1px solid #d5dde3;padding:10px;background:#15324b;color:#fff;\"\u003eUsage\u003c\/th\u003e\n\n\n\u003c\/tr\u003e\u003c\/thead\u003e\n\n\u003ctbody\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eCompliance Plan \u0026amp; Role Assessment\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eScope, role, company size, application date, and responsibility.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eInformation Gathering \u0026amp; Geolocation\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 9 data, plots\/establishments, production time, suppliers, and evidence.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eRisk Assessment \u0026amp; Country Benchmarking\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 10, country risk, supply chain, mixing risk, and decision log.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eRisk Mitigation \u0026amp; Supplier Requirements\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eArticle 11, supplementary data, audit, geospatial verification, and corrective actions.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDDS \u0026amp; Simplified Declaration\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e3 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003ePreparation basis for DDS and Article 4a regime.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDownstream\/Trader Traceability\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e2 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eSuppliers, customers, DDS\/declaration ID, and five-year retention.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eDetailed User Guide\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e4 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e4 pages\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eStep-by-step from CN code and role to documented release.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\u003ctr\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003e\u003cstrong\u003eEUDR Excel Register\u003c\/strong\u003e\u003c\/td\u003e\n\n\u003ctd colspan=\"2\" style=\"border:1px solid #d5dde3;padding:10px;\"\u003e1 XLSX\u003c\/td\u003e\n\n\u003ctd style=\"border:1px solid #d5dde3;padding:10px;\"\u003eDashboard, products, suppliers, geolocation, risk, mitigation, DDS, and downstream traceability.\u003c\/td\u003e\n\n\n\u003c\/tr\u003e\n\n\n\u003c\/tbody\u003e\n\n\n\u003c\/table\u003e\n\n\n\u003c\/div\u003e\n\n\n\u003cdiv id=\"tidskritiskt\" style=\"background:#fff4cc;border-left:5px solid #d9a800;padding:20px;border-radius:8px;margin:22px 0;\"\u003e\n\n\u003cstrong style=\"font-size:1.1em;\"\u003eTime-critical – two key dates\u003c\/strong\u003e\u003cbr\u003e\nFor \u003cstrong\u003elarge and medium-sized entities\u003c\/strong\u003e, as well as micro\/small entities that were already covered by the EU Timber Regulation, the key application date is \u003cstrong\u003e30 December 2026\u003c\/strong\u003e. For most other \u003cstrong\u003emicro and small entities\u003c\/strong\u003e, the application date is \u003cstrong\u003e30 June 2027\u003c\/strong\u003e. The package therefore has a specific flow for roles and company size, and the Excel register calculates which date should normally be used as a starting point.\n\n\u003c\/div\u003e\n\n\n\u003ch2 id=\"roller\"\u003eStart with the right EUDR role – not a generic questionnaire\u003c\/h2\u003e\n\n\u003cp\u003eThe revised EUDR model makes role assessment crucial. The package distinguishes between, among others:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eoperator\u003c\/strong\u003e – the entity that first places a relevant product on the Union market or exports it,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003emicro\/small primary producers\u003c\/strong\u003e that may be covered by the specific simplified Article 4a regime,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003edownstream operator\u003c\/strong\u003e,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003etrader\u003c\/strong\u003e,\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eauthorized representative\u003c\/strong\u003e, where relevant.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThis is important because obligations are no longer the same for all actors in the supply chain. It is primarily the first operator that carries out the full due diligence process and submits the DDS, while downstream actors and traders in the revised model primarily work with traceability, reference data, and the management of new information or substantiated concerns.\u003c\/p\u003e\n\n\n\u003ch2 id=\"scope\"\u003eWhich commodities and products are covered?\u003c\/h2\u003e\n\n\u003cp\u003eEUDR is still based on seven central commodity groups:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ecattle,\u003c\/li\u003e\n\n\u003cli\u003ecocoa,\u003c\/li\u003e\n\n\u003cli\u003ecoffee,\u003c\/li\u003e\n\n\u003cli\u003eoil palm,\u003c\/li\u003e\n\n\u003cli\u003erubber,\u003c\/li\u003e\n\n\u003cli\u003esoy,\u003c\/li\u003e\n\n\u003cli\u003ewood.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eHowever, it is not enough to just ask if a product \"contains wood\" or \"contains coffee.\" The legal product scope is governed by \u003cstrong\u003eAnnex I and the relevant CN\/HS codes\u003c\/strong\u003e. The package therefore contains product and code fields so that the business can document why a product has been assessed as covered or not covered.\u003c\/p\u003e\n\n\n\u003ch3\u003eThe product scope has changed during 2026\u003c\/h3\u003e\n\n\u003cp\u003eThe updated Annex I has changed which derived products are covered. Some products have been removed and others added. Newly added products according to the 2026 update have a later application date. Therefore, the user should always check the current CN code against the applicable annex and not rely on an old product list from 2023 or 2024.\u003c\/p\u003e\n\n\n\u003ch2\u003eThree core requirements for relevant products\u003c\/h2\u003e\n\n\u003cp\u003eThe regulation is fundamentally based on the premise that a relevant product must be:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003edeforestation-free\u003c\/strong\u003e,\u003c\/li\u003e\n\n\u003cli\u003eproduced in accordance with the \u003cstrong\u003erelevant legislation of the country of production\u003c\/strong\u003e, and\u003c\/li\u003e\n\n\u003cli\u003ecovered by the documentation and due diligence required for the actor in question.\u003c\/li\u003e\n\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eDeforestation-free status is assessed against the regulation's central cut-off date of \u003cstrong\u003e31 December 2020\u003c\/strong\u003e. The package's evidence checklists therefore link both geolocation, production time, and deforestation-free proof to each product\/batch.\u003c\/p\u003e\n\n\n\u003ch2 id=\"artikel9\"\u003eArticle 9 – information gathering and geolocation\u003c\/h2\u003e\n\n\u003cp\u003eThe separate Article 9 basis helps the business collect and link, among other things:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eproduct description and quantity,\u003c\/li\u003e\n\n\u003cli\u003ecountry and, where relevant, region of production,\u003c\/li\u003e\n\n\u003cli\u003eproduction date or period,\u003c\/li\u003e\n\n\u003cli\u003esupplier and customer information,\u003c\/li\u003e\n\n\u003cli\u003egeolocation for relevant production areas or establishments,\u003c\/li\u003e\n\n\u003cli\u003eproof that the product is deforestation-free,\u003c\/li\u003e\n\n\u003cli\u003eproof of compliance with relevant legislation in the country of production.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch3\u003eGeolocation – point, polygon, or establishment\u003c\/h3\u003e\n\n\u003cp\u003eGeolocation must be sufficiently precise to link the commodity to the plot where it was produced. The package and the Excel register have separate fields for latitude\/longitude, polygon\/GeoJSON reference, and cattle-related establishments.\u003c\/p\u003e\n\n\u003cp\u003eFor land plots  over four hectares used for relevant commodities other than cattle, geolocation generally needs to be described by polygon. For cattle, the focus is on the establishments where the animals have been kept.\u003c\/p\u003e\n\n\n\u003ch3\u003eSpecific relief for certain micro\/small primary producers\u003c\/h3\u003e\n\n\u003cp\u003eThe simplified Article 4a regime allows certain micro and small primary producers to submit a simplified declaration instead of a normal DDS. In that specific situation, the rules may also allow the use of a postal address instead of geolocation when the statutory requirements are met. The package treats this as an \u003cstrong\u003eexception with specific conditions\u003c\/strong\u003e, not as a general EUDR rule.\u003c\/p\u003e\n\n\n\u003ch2 id=\"risk\"\u003eRisk assessment according to Article 10\u003c\/h2\u003e\n\n\u003cp\u003eIt is not enough for a supplier to answer \"yes\" to a compliance question. The risk assessment must document why the risk can be considered non-existent or negligible. The template package therefore includes a structured assessment of, for example:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ethe country's current benchmarking classification,\u003c\/li\u003e\n\n\u003cli\u003epresence of forest and deforestation,\u003c\/li\u003e\n\n\u003cli\u003erights of indigenous peoples and other affected groups where relevant,\u003c\/li\u003e\n\n\u003cli\u003ereliability and traceability of documentation,\u003c\/li\u003e\n\n\u003cli\u003ecomplexity of the supply chain,\u003c\/li\u003e\n\n\u003cli\u003erisk of mixing with products of unknown origin,\u003c\/li\u003e\n\n\u003cli\u003erisk of circumvention or misleading supply chains,\u003c\/li\u003e\n\n\u003cli\u003esubstantiated concerns and other relevant information.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch3\u003eCountry benchmarking – low, standard, and high risk\u003c\/h3\u003e\n\n\u003cp\u003eThe Excel register includes support for the EU's current country benchmarking. Under the current classification, \u003cstrong\u003eBelarus, the Democratic People's Republic of Korea, Myanmar, and the Russian Federation\u003c\/strong\u003e, among others, are classified as high-risk countries. Countries not explicitly classified as low or high risk are treated as standard risk.\u003c\/p\u003e\n\n\u003cp\u003eA low country risk does not automatically mean that documentation can be skipped. The Article 13 simplified due diligence can only be used when its conditions are met, and the business still needs to manage, for example, the risk of circumvention and mixing.\u003c\/p\u003e\n\n\n\u003ch2\u003eRisk mitigation according to Article 11\u003c\/h2\u003e\n\n\u003cp\u003eIf the risk assessment does not show non-existent or negligible risk, the business must take adequate risk-mitigation measures before the relevant product is placed on the market or exported. The package's mitigation plan supports, among other things:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eadditional supplier information,\u003c\/li\u003e\n\n\u003cli\u003eindependent audit or verification,\u003c\/li\u003e\n\n\u003cli\u003egeospatial control,\u003c\/li\u003e\n\n\u003cli\u003elot\/batch segregation,\u003c\/li\u003e\n\n\u003cli\u003esupplier requirements and corrective actions,\u003c\/li\u003e\n\n\u003cli\u003ecapacity support for suppliers,\u003c\/li\u003e\n\n\u003cli\u003ealternative sourcing when risk cannot be mitigated to an acceptable level.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"dds\"\u003eDDS – Due Diligence Statement\u003c\/h2\u003e\n\n\u003cp\u003eThe standard operator process concludes with a \u003cstrong\u003eDue Diligence Statement\u003c\/strong\u003e submitted via the EU information system before the relevant product is placed on the market or exported. The package's DDS basis helps the user collect the data and internal approvals that need to be ready before the electronic submission.\u003c\/p\u003e\n\n\u003cp\u003eThe Excel register stores, among other things, product ID, declaration type, submission date, DDS reference\/declaration ID, country, risk result, and estimated document retention.\u003c\/p\u003e\n\n\n\u003ch3\u003eSimplified declaration according to Article 4a\u003c\/h3\u003e\n\n\u003cp\u003eFor micro and small primary producers that meet the requirements, there is a separate simplified declaration model. It is a different legal path than a normal DDS and should therefore be documented separately. The package has its own template fields and Excel options for this regime.\u003c\/p\u003e\n\n\n\u003ch2 id=\"downstream\"\u003eDownstream operators and traders – the new model\u003c\/h2\u003e\n\n\u003cp\u003eAn important change is that downstream operators and traders are not generally required to duplicate the first operator's full due diligence or submit a new DDS for the same upstream basis. Instead, the obligations focus on traceability and the verification of relevant reference data.\u003c\/p\u003e\n\n\u003cp\u003eThe downstream\/trader template and the Excel register therefore document:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003ewho the product was purchased from,\u003c\/li\u003e\n\n\u003cli\u003ewho it was supplied to when the information must be preserved,\u003c\/li\u003e\n\n\u003cli\u003econtact information,\u003c\/li\u003e\n\n\u003cli\u003eDDS reference or simplified declaration identifier,\u003c\/li\u003e\n\n\u003cli\u003etransaction\/availability date,\u003c\/li\u003e\n\n\u003cli\u003eany new information about lack of compliance,\u003c\/li\u003e\n\n\u003cli\u003ewhether the competent authority has been informed when required,\u003c\/li\u003e\n\n\u003cli\u003efive-year retention period.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"dokumentation\"\u003eFive years of documentation\u003c\/h2\u003e\n\n\u003cp\u003eEUDR sets extensive requirements for provable documentation. The package uses five-year retention as a central control point for DDS\/declaration basis, the due diligence system, and relevant downstream\/trader traceability information. The Excel register therefore automatically calculates retention dates from registered event dates.\u003c\/p\u003e\n\n\n\u003ch2 id=\"excel\"\u003eExcel – an operational EUDR register, not just an empty list\u003c\/h2\u003e\n\n\u003cp\u003eThe included XLSX file is built to actually be used as a simpler EUDR control register. It contains the following worksheets:\u003c\/p\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDashboard\u003c\/strong\u003e – KPIs for products, plots, risks, mitigation, and declarations.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eProduct Register\u003c\/strong\u003e – CN\/HS code, commodity, role, company size, and automatic application date.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSuppliers\u003c\/strong\u003e – producers, suppliers, and audit status.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003ePlots \u0026amp; Geolocation\u003c\/strong\u003e – coordinates, polygon references, production time, and Article 4a relief.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eCountry Benchmarking\u003c\/strong\u003e – current low\/standard\/high-risk logic.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eRisk Register\u003c\/strong\u003e – automatic risk level from probability × impact.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eMitigation Log\u003c\/strong\u003e – measures, deadlines, residual risk, and evidence.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDDS \u0026amp; Declarations\u003c\/strong\u003e – DDS, Article 4a declarations, and five-year retention.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eDownstream Traceability\u003c\/strong\u003e – upstream\/downstream operators and reference numbers.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eEvidence Checklist\u003c\/strong\u003e – basis for Article 9, deforestation-free, legality, risk, and governance.\u003c\/li\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003eSources\u003c\/strong\u003e – central legal sources and EU resources.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"arbetsflode\"\u003ePractical workflow\u003c\/h2\u003e\n\n\u003cp\u003eA typical usage is:\u003c\/p\u003e\n\n\u003col\u003e\n\n\u003cli\u003eCheck the product's CN\/HS code and whether it is covered by the current Annex I.\u003c\/li\u003e\n\n\u003cli\u003eDetermine the company's role and size as well as the application date.\u003c\/li\u003e\n\n\u003cli\u003eMap the producer, suppliers, products\/batches, and production locations.\u003c\/li\u003e\n\n\u003cli\u003eCollect Article 9 information and geolocation.\u003c\/li\u003e\n\n\u003cli\u003eCheck country benchmarking and perform the Article 10 risk assessment.\u003c\/li\u003e\n\n\u003cli\u003ePerform Article 11 risk mitigation if the risk is not non-existent\/negligible.\u003c\/li\u003e\n\n\u003cli\u003ePrepare and submit a DDS or simplified Article 4a declaration when the legal model requires it.\u003c\/li\u003e\n\n\u003cli\u003eDocument downstream traceability and preserve relevant documentation for five years.\u003c\/li\u003e\n\n\n\u003c\/ol\u003e\n\n\n\u003ch2 id=\"faq\"\u003eFrequently asked questions about EUDR\u003c\/h2\u003e\n\n\n\u003ch3\u003eWhen does EUDR start to apply to companies?\u003c\/h3\u003e\n\n\u003cp\u003eFor large and medium-sized entities, the central obligations apply from 30 December 2026. For most other micro and small entities, 30 June 2027 applies. Micro\/small companies that were already covered by the EU Timber Regulation follow the earlier 30 December 2026 date.\u003c\/p\u003e\n\n\n\u003ch3\u003eWhich commodities are covered?\u003c\/h3\u003e\n\n\u003cp\u003eThe scope of the EUDR includes cattle, cocoa, coffee, oil palm, rubber, soy, and wood, as well as the derived products listed in the current Annex I. The exact CN code must therefore be verified.\u003c\/p\u003e\n\n\n\u003ch3\u003eMust all companies submit a DDS?\u003c\/h3\u003e\n\n\u003cp\u003eNo. Following recent regulatory changes, it is primarily the first operator that conducts full due diligence and submits the DDS. Downstream operators and traders have a different traceability model. Micro\/small primary producers may, under certain conditions, use a simplified declaration in accordance with Article 4a.\u003c\/p\u003e\n\n\n\u003ch3\u003eMust geolocation always be provided?\u003c\/h3\u003e\n\n\u003cp\u003eFull due diligence requires geolocation data in accordance with Article 9. The specific Article 4a regime may in some cases allow for a postal address instead, but this is a limited exception and should not be used for other actors.\u003c\/p\u003e\n\n\n\u003ch3\u003eWhat is country benchmarking?\u003c\/h3\u003e\n\n\u003cp\u003eThe EU classifies countries or parts of countries as low, standard, or high risk. The classification affects the level of control and the possibility of simplified due diligence but does not replace the company's documentation obligation.\u003c\/p\u003e\n\n\n\u003ch3\u003eWhat happens if the risk is not negligible?\u003c\/h3\u003e\n\n\u003cp\u003eThe product must not be placed on the market or exported on the basis of an incomplete risk assessment. Risk mitigation measures must be implemented until the conclusion can be justified and documented according to applicable rules.\u003c\/p\u003e\n\n\n\u003ch3\u003eAre Swedish and English documents included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. All seven document templates are available in both a Swedish and a separate English version.\u003c\/p\u003e\n\n\n\u003ch3\u003eIs Excel included?\u003c\/h3\u003e\n\n\u003cp\u003eYes. The package includes a comprehensive EUDR register in Excel with a dashboard, product\/supplier register, geolocation, country benchmarking, risk, mitigation, DDS\/declarations, and downstream traceability.\u003c\/p\u003e\n\n\n\u003ch2\u003eFormat and delivery\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003e\n\n\u003cstrong\u003e14 document templates\u003c\/strong\u003e – 7 Swedish + 7 English.\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e1 advanced Excel register.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e29 delivery files in total.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eWord (DOCX) + PDF + Excel (XLSX).\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003e42 A4 pages per format series across both language versions.\u003c\/strong\u003e\u003c\/li\u003e\n\n\u003cli\u003e\u003cstrong\u003eDigital product – no physical item is sent.\u003c\/strong\u003e\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003ch2 id=\"kallor\"\u003eLegal basis and official EU sources\u003c\/h2\u003e\n\n\u003cul\u003e\n\n\u003cli\u003eRegulation (EU) 2023\/1115 on deforestation-free products – consolidated version 2026.\u003c\/li\u003e\n\n\u003cli\u003eRegulation (EU) 2025\/2650 – amended and simplified obligations, including Article 4a and the downstream model.\u003c\/li\u003e\n\n\u003cli\u003eImplementing Regulation (EU) 2025\/1093 – country benchmarking.\u003c\/li\u003e\n\n\u003cli\u003eImplementing Regulation (EU) 2026\/1565 – EUDR Information System.\u003c\/li\u003e\n\n\u003cli\u003eDelegated Regulation (EU) 2026\/2102 – updated product scope in Annex I.\u003c\/li\u003e\n\n\u003cli\u003eEuropean Commission's current EUDR guidance and FAQ.\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\n\u003cdiv style=\"background:#f3f5f7;border:1px solid #d5dde3;padding:16px;border-radius:8px;margin-top:20px;\"\u003e\n\n\u003cstrong\u003eImportant:\u003c\/strong\u003e The EUDR is specific to products, roles, countries, and supply chains. The template package is a structured working tool and does not replace individual legal advice, CN classification, geospatial analysis, or authority decisions. In the event of an unclear product code, complicated sourcing, a high-risk country, a substantiated concern, or uncertainty regarding Article 4a, a specialist assessment should be performed before placing on the market or exporting.\n\n\u003c\/div\u003e\n\n\n\u003c\/div\u003e","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55615168807254,"sku":"EUDR-DUE-DILIGENCE-2026-2027","price":79.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/eudr-due-diligence-2026-2027-svenska-english.png?v=1791242429"}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/collections\/cra-compliance-mallpaket-2026-2027.png?v=1791238326","url":"https:\/\/mallbutiken.se\/en\/collections\/eu-compliance-produktregler-mallar.oembed","provider":"Mallbutiken","version":"1.0","type":"link"}