Independent information resource Product security · EU CRA
User information and security communications / 01

What Cybersecurity Information Must CRA Products Provide?

A point-by-point guide to the minimum cybersecurity information CRA products must provide under Annex II, including contacts, product identity, intended purpose, security properties, risks, support, updates and decommissioning instructions.

IN BRIEF

A CRA product information package should let a user answer practical security questions: who made this product, how can a vulnerability be reported, exactly which product is this, how is it meant to be used securely, what important risks should be understood, how long is security support provided, and how should the product be updated or retired safely?

01 / 10

Annex II Sets a Minimum Information Baseline

Article 13(18) requires products with digital elements to be accompanied by the user information and instructions listed in Annex II. Annex II uses a minimum-information structure, so manufacturers should treat its eight numbered points as a baseline rather than assuming that any product can be documented with only a generic quick-start guide.

  • Map each Annex II point to a user-facing location.
  • Identify which information is product-specific.
  • Keep the information understandable and accessible.
  • Review the package when the product changes.
02 / 10

1. Manufacturer Identity and Contact Information

Annex II point 1 requires the manufacturer's name, registered trade name or registered trademark, together with the postal address, an email address or other digital contact and, where available, a website where the manufacturer can be contacted. The contact information should correspond to the legal manufacturer responsible for the product rather than only a reseller or marketplace listing.

  • Manufacturer legal or registered trade identity.
  • Postal address.
  • Email address or other digital contact.
  • Website where available.
03 / 10

2. Vulnerability Reporting Contact and CVD Policy

Annex II point 2 requires the single point of contact where vulnerability information can be reported and received and where the manufacturer's coordinated vulnerability disclosure policy can be found. This should be a real product-security intake route, not a generic mailbox that cannot reliably reach the people responsible for vulnerability handling.

  • Single vulnerability-reporting point of contact.
  • Route for receiving vulnerability information.
  • Location of the CVD policy.
  • Clear distinction from ordinary sales or billing support.
04 / 10

3. Unique Product Identification

Annex II point 3 requires the product name and type together with additional information enabling unique identification. The correct level of detail depends on the product. A manufacturer may need to include a model number, software version, hardware revision, build identifier or another identifier so users can connect security information to the exact product they operate.

  • Name and type.
  • Model or version where relevant.
  • Build or hardware revision where relevant.
  • Identifier consistent with security advisories.
05 / 10

4. Intended Purpose, Security Environment and Security Properties

Annex II point 4 requires the intended purpose, including the security environment provided by the manufacturer, together with the product's essential functionalities and information about the security properties. This information should explain the assumptions users need to preserve for secure operation, such as expected network placement, authentication model, supported integrations or security-sensitive operating conditions.

  • Intended purpose.
  • Security environment.
  • Essential functionalities.
  • Security properties relevant to use.
06 / 10

5. Known or Foreseeable Circumstances Creating Significant Cybersecurity Risks

Annex II point 5 requires information about known or foreseeable circumstances related to intended use or reasonably foreseeable misuse that may lead to significant cybersecurity risks. The manufacturer should focus on material conditions users can understand and act on. Examples can include insecure exposure of a management interface, use of unsupported configurations or security-sensitive deployment outside the intended environment.

  • Known risk-producing circumstances.
  • Reasonably foreseeable misuse.
  • Material security assumptions.
  • Actionable user precautions.
07 / 10

6. Access to the EU Declaration of Conformity Where Applicable

Annex II point 6 requires, where applicable, the internet address at which the EU declaration of conformity can be accessed. If the declaration is made available online, manufacturers should use a durable location that remains connected to the identifiable product rather than a temporary campaign or download page.

  • Provide the internet address where applicable.
  • Connect the declaration to the correct product.
  • Use a durable document location.
  • Keep version information consistent.
08 / 10

7. Technical Security Support and Support End Date

Annex II point 7 requires the type of technical security support offered and the end date of the support period during which users can expect vulnerabilities to be handled and security updates to be provided. This security-support statement should be clear enough that users can distinguish active vulnerability support from unrelated commercial warranty, feature support or customer-service arrangements.

  • Type of technical security support.
  • Support-period end date.
  • Expectation of vulnerability handling.
  • Expectation of security updates.
09 / 10

8. Detailed Security Instructions

Annex II point 8 requires detailed instructions or an internet address referring to them. The instructions must cover secure commissioning and lifetime use, the security effect of product changes, installation of security-relevant updates, secure decommissioning and data removal, how the default automatic security-update setting can be turned off, and integrator information where the product is intended to be integrated into another product with digital elements.

  • Secure commissioning and use.
  • Security effects of changes.
  • Security-update installation.
  • Secure decommissioning and data removal.
  • Automatic-update control.
  • Integrator information where applicable.
10 / 10

Make the Information Version-Specific and Maintainable

The minimum Annex II checklist still needs product-specific implementation. A software update can change the secure configuration, supported environment, known risks or update procedure. Manufacturers should therefore connect user information to release management and preserve historical instructions where older supported versions remain in use.

  • Tie information to product versions.
  • Review after security-relevant changes.
  • Preserve historical supported instructions.
  • Keep public information consistent with engineering records.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.