Skip to product information
1 of 3

Svenska Dokumentmallar

Cyber Resilience Act (CRA) Compliance 2026/2027 – Swedish + English | Risk Assessment, SBOM & Incident Reporting Word/PDF/Excel

Cyber Resilience Act (CRA) Compliance 2026/2027 – Swedish + English | Risk Assessment, SBOM & Incident Reporting Word/PDF/Excel

File format
DOCX, PDF, XLSX
Document language
Swedish
Number of files
15

Digital download. No physical product is shipped.

Regular price 79 SEK
Regular price Sale price 79 SEK
Sale Sold out
Taxes included.
View full details

About this template

Cyber Resilience Act (CRA) Compliance 2026/2027 – complete 2-in-1 package

A comprehensive compliance package for companies that manufacture, develop, or place products with digital elements on the EU market and need to prepare or document their efforts in accordance with Regulation (EU) 2024/2847 – Cyber Resilience Act (CRA).

The package combines Swedish and English work templates with an advanced Excel register for cybersecurity risks, SBOM, vulnerabilities, CRA reporting, and technical documentation.

Delivery: 7 Swedish + 7 English document templates in both Word and PDF formats, plus 1 Excel workbook – a total of 29 delivery files. The Word/PDF series comprises a total of 28 A4 pages per language version.

Legally and technically reviewed: October 5, 2026
The template package has been reviewed against the Cyber Resilience Act, Regulation (EU) 2024/2847, including Articles 13–14 as well as Annexes I, II, and VII, and against the European Commission's current implementation and reporting guidance. The package is designed for practical compliance work during 2026/2027.

Key CRA dates 2026–2027

The CRA is already in force, but different obligations become applicable at different times:

  • September 11, 2026: manufacturers' reporting obligations for actively exploited vulnerabilities and severe incidents became applicable.
  • December 11, 2027: the CRA's main product and cybersecurity requirements become fully applicable.

This means that organizations should not wait until 2027 to build risk assessments, vulnerability management, reporting routines, technical documentation, and evidence chains.

Included in the package

Template / Tool Swedish English Format
CRA Implementation & Compliance Plan 2 pages 2 pages Word + PDF
Cybersecurity Risk Assessment 2 pages 2 pages Word + PDF
Vulnerability Management & CVD Policy 2 pages 2 pages Word + PDF
Incident & Vulnerability Reporting 24h/72h 2 pages 2 pages Word + PDF
Technical Documentation & Conformity Checklist 2 pages 2 pages Word + PDF
User Information, Security Updates & Support Period 2 pages 2 pages Word + PDF
Detailed User Guide 2 pages 2 pages Word + PDF
CRA Compliance Register – Risk, SBOM, Vulnerability & Reporting Bilingual workbook Excel (XLSX)
Built for a complete CRA workflow
The CRA is not about a single policy. The company needs to be able to demonstrate how cybersecurity risks are identified and mitigated, how components and vulnerabilities are tracked, how actively exploited vulnerabilities and serious incidents are reported, how technical documentation is compiled, and how security updates are handled during the support period. Therefore, the package links together governance, risk assessment, SBOM, CVD, incident reporting, technical supporting documents, user information, and an Excel register.

Which companies are affected by the CRA?

The CRA targets products with digital elements made available on the EU market. This can include both hardware and software, as well as many connected or network-related products.

The package is primarily built for manufacturers, but the checklists and user guide also help identify issues that importers and distributors need to verify. The exact role must always be assessed based on the actual supply chain and the product.

Cybersecurity risk assessment – a core element of the CRA

The CRA requires the manufacturer to conduct a cybersecurity risk assessment for the product with digital elements and take the result into account during planning, design, development, production, delivery, and maintenance.

The risk template and the Excel register help the organization document:

  • product, version, and intended use,
  • assets and security-critical functions,
  • threat and misuse scenarios,
  • probability and consequence,
  • existing controls,
  • residual risk,
  • action plan, responsible party, and deadline,
  • link to the CRA's essential cybersecurity requirements.

SBOM, vulnerability management, and Coordinated Vulnerability Disclosure

The CRA's vulnerability requirements mean that the manufacturer must be able to identify and document vulnerabilities and components included in the product. Annex I stipulates, among other things, that vulnerabilities and components shall be identified and documented, including through a machine-readable SBOM that covers at least the product's top-level dependencies.

The package therefore contains:

  • SBOM register in Excel,
  • component/version/supplier/PURL/CPE,
  • direct or transitive dependency,
  • CVE/advisory and severity,
  • fixed version and review date,
  • CVD policy and external vulnerability contact,
  • triage, remediation, and disclosure routine.

CRA reporting: 24 hours, 72 hours, and final report

Since September 11, 2026, manufacturers have been required to report actively exploited vulnerabilities and serious incidents that affect the security of products with digital elements.

The European Commission's reporting guidance outlines the following main points:

  • within 24 hours: early warning after the organization has become aware,
  • within 72 hours: full notification,
  • actively exploited vulnerability: final report no later than 14 days after the corrective or mitigating measure has become available,
  • serious incident: final report within one month of the 72-hour notification.

The Excel file includes a specific sheet for reporting cases where the 24h and 72h deadlines are calculated automatically based on the awareness date and time.

Technical documentation – Annex VII

The CRA's technical documentation shall provide oversight and conformity evidence for the product. The package's technical documentation checklist includes, among other things:

  • product description and intended use,
  • architecture, component relationships, and secure development process,
  • SBOM and vulnerability handling,
  • cybersecurity risk assessment,
  • support period and justification,
  • applied standards/specifications,
  • test and verification evidence,
  • EU Declaration of Conformity and release gate.

User information – Annex II

User information needs, among other things, to enable the user to identify the manufacturer and product, find a contact point for vulnerabilities, understand the intended use and relevant security preconditions, and obtain instructions for secure installation, use, updating, and decommissioning.

The template therefore includes a dedicated worksheet for Annex II-like customer/user information and a clear field for the support period end date.

Support period and security updates

The manufacturer shall determine a support period that reflects how long the product is reasonably expected to be used, taking into account, among other things, the nature of the product, expected use, and relevant market conditions. The CRA's general rule is that the support period should normally be at least five years, unless the product is not reasonably expected to be used for a shorter period.

The package helps the organization document:

  • expected product lifetime,
  • decided support period,
  • justification and evidence,
  • security updates and distribution,
  • end date to be communicated to users.

The CRA also includes requirements on how long security updates must be kept available. Therefore, the organization should plan for both distribution and long-term availability of relevant updates.

Conformity assessment, EU Declaration, and CE

Which conformity assessment path is permitted depends, among other things, on the product's CRA classification. The package contains checkpoints for:

  • standard product/default category,
  • important product class I,
  • important product class II,
  • critical product,
  • applicable standards/specifications,
  • any notified body,
  • EU Declaration of Conformity,
  • CE release gate.

The template does not replace a formal product classification or external conformity assessment when such is required.

Excel register – more than a static checklist

The included XLSX file is a practical compliance register with separate tabs for:

  • Dashboard – key performance indicators and key CRA dates,
  • Product Register – products, versions, classification, and support period,
  • Risk Register – risk level and action plan,
  • SBOM – components, version data, and vulnerability link,
  • Vulnerability Register – CVE/advisories, severity, and status,
  • Reporting Deadlines – automatic 24h/72h deadlines,
  • Evidence Checklist – technical documentation and evidence chain,
  • Sources – key official CRA sources.

The workbook contains data validation, risk level formulas, and automated deadline calculations, but is designed so that the user can further build upon it.

CRA vs. NIS2 – different focus

The CRA and NIS2 can both be relevant to the same organization, but they have different focuses. The CRA is primarily a product regulation for cybersecurity in products with digital elements and their vulnerability management. NIS2/cybersecurity regulation focuses to a greater extent on organizations' risk management and incident reporting as entities providing essential or important services.

The new CRA package therefore complements the Mallbutiken existing NIS2 package rather than replacing it.

Sanctions – why documentation matters

The CRA contains significant administrative sanction levels. For certain central infringements, maximum administrative fines can amount to 15 million euros or 2.5 percent of total global annual turnover, whichever is higher and subject to the conditions and exemptions stipulated in the regulation.

Practical and dated documentation is therefore important not only for implementation but also to be able to demonstrate how the organization has actually worked with compliance.

Recommended workflow

  1. Identify products and economic operator role.
  2. Classify the product according to the CRA.
  3. Conduct and document the cybersecurity risk assessment.
  4. Build SBOM and CVD/vulnerability process.
  5. Determine support period and update strategy.
  6. Prepare technical documentation and user information.
  7. Set up 24h/72h reporting and chain of responsibility.
  8. Conduct conformity assessment and collect evidence.
  9. Keep registers updated after release and during the support period.

Frequently asked questions about the CRA

Are the reporting requirements already in effect?

Yes. Manufacturers' CRA reporting obligations for actively exploited vulnerabilities and serious incidents became applicable on September 11, 2026.

When does the main part of the CRA come into effect?

The main application begins on December 11, 2027.

Do we need an SBOM?

The CRA's vulnerability handling requirements include documentation of components and vulnerabilities, including a machine-readable SBOM that covers at least top-level dependencies.

Is the CRA the same thing as NIS2?

No. The CRA focuses on products with digital elements and the product's cybersecurity lifecycle. NIS2 has a different organizational and operational focus. A company may be affected by both.

Does the CRA only apply to hardware?

No. The regulation covers products with digital elements and can include both hardware and software depending on the product and market situation.

Are Swedish and English templates included?

Yes. All seven Word/PDF documents are available in both Swedish and English.

Is Excel included?

Yes. The package contains a separate XLSX workbook for product registers, risks, SBOM, vulnerabilities, reporting deadlines, and evidence.

Is this a certification?

No. The package is a professional documentation and work support tool. It does not replace a notified body, product testing, external cybersecurity testing, or individual legal assessment when such is required.

Format and delivery

  • 7 Swedish document templates + 7 English document templates.
  • 14 DOCX + 14 PDF + 1 XLSX = 29 files in total.
  • 28 A4 pages per Word/PDF format series.
  • Excel workbook with 8 compliance tabs.
  • Digital product – no physical goods are shipped.

Legal basis and official sources

Important: The CRA is a technical and legal product regulation. Product classification, conformity assessment, applicable standards, and reporting obligations must be verified based on the actual product, the role of the economic operator, and the distribution model. The template package is a structured working and documentation aid – not a guarantee of full compliance in every individual situation.