ConformanceHouse

If you sell software or a connected device in the EU, you now need a security file.

Five documents, signed by you, kept for ten years. We write them from a questionnaire and keep them current as the rules change. We expect the rules to change at least three times before the deadline. €390 a year, one product.

This is you

  • A sensor, controller, meter or instrument you make
  • Any hardware with software inside it
  • An app, desktop program or firmware people install
  • A component or library other manufacturers build on
  • You import into the EU, or rebrand someone else’s hardware

This isn’t you

  • Pure SaaS — nothing installed, sold as a service
  • Medical devices, cars, aircraft, boats
  • Defence and national security kit
  • Anything you don’t sell into the EU

Get the one-page checklist

Every document the CRA asks for, what each one has to contain, and the date it is due. Free, and the only email you get is that one.

No newsletter. No sales calls — we don’t make any.

Not sure whether it applies to you? Take the two-minute check — eight questions, no email needed.

Applicability check

Does the Cyber Resilience Act apply to your product?

Eight questions, about two minutes. You get your conformity route, every document that applies to you, and the Article each requirement comes from. No email needed, and nothing is stored against you.

In force since 11 September 2026

Sell a device or an app in the EU? You now have 24 hours to report an exploited flaw. Could you file one today?

Filing needs an account on an EU platform, two-factor set up, a named person at your company, and a decision about which national team you report to. None of it can be done retrospectively once a clock is running — and most manufacturers have not done any of it.

24hEarly warning, from the moment you know
72hFull notification with an assessment
14dFinal report, once a fix exists

The five documents

Blank templates for these are free in several places. What a template cannot do is fill itself in for your product, or change when the law underneath it changes.

Annex VII Technical file Your architecture, how you handle vulnerabilities, your list of software components, and your security decisions written down against each requirement.
Annex V Declaration of conformity The document your CE marking rests on, so the first one an inspector reads. You sign it yourself.
Annex II Information for your customers Nine things that ship with the product, including where to report a hole and the date your security updates stop.
Annex I Disclosure policy A policy you publish so researchers know how to tell you about a problem, plus the contact address that goes with it.
Article 13 Support period reasoning Not the date — the reasoning behind it. Minimum five years unless the product genuinely won’t be used that long.

Your file goes out of date on its own

The technical standards your file has to cite mostly don’t exist yet. Three batches are due between now and the deadline, and those dates have already moved once.

So a file written today is wrong by January, and nothing tells you that it happened. That is the part we do for you, and the reason this is a subscription rather than a one-off download.

11 Sep 2026Reporting starts. Done.
31 Oct 2026First batch of standards expected
31 Dec 2026Second batch
30 Oct 2027Third batch
11 Dec 2027No file, no CE mark, no EU sales
€15m or 2.5% of turnover The ceiling on fines for these obligations, whichever is higher. Enforcement is national and proportionate, so a small manufacturer is not looking at €15m — but that is the number in the regulation.

€390 a year, one product

Published, because you shouldn’t have to book a call to find out what a document costs. Every version of every document is kept and dated, because the law wants ten years of them and a folder of PDFs on your laptop won’t survive that.

Your archive is yours. One button, any time, no conditions — including if you cancel, and including if we ever stop operating.