The fourteen artefacts that carry your Cyber Resilience Act technical documentation across five project phases.
The Cyber Resilience Act (CRA) requires technical documentation under Annex VII as evidence of conformity. This overview lists the fourteen mandatory artefacts across five project phases, each with purpose, content, location and refresh trigger.
The design phase lays the foundation for all later conformity evidence. Three artefacts must exist here, otherwise the technical documentation has no basis.
During development, the artefacts arise that show cybersecurity is anchored in the code itself, not only in the documentation. Three artefacts make this anchoring visible.
Verification is the point at which evidence emerges. Two artefacts turn tests and reviews into audit-ready proof.
Deployment is the transition from build to operation. Three artefacts must accompany the transition so that users and board know what they are engaging with.
After release, the longest part of the product life begins. Three artefacts carry compliance through the support period.
When an artefact is missing, Inspector spots the gap directly in your Jira and delivers the signed template through Cronos.
Install Inspector for JiraCe site n'utilise que des cookies strictement nécessaires et une analyse sans cookie respectueuse de la vie privée. Confidentialité