CRA document templates
Four editable files, with the Official Journal wording already in place and every item cited to its Article or Annex. €39 once. Download immediately, no account.
What this saves you. Not the thinking — the structure and the transcription. You stop reading the Regulation to work out what a document is supposed to contain, and start answering questions that are already laid out in the right order.
Roughly a day of work, for most people.
The four files
| File | What it is | Why it is shaped that way |
|---|---|---|
| Risk assessment Excel |
One row per requirement in Annex I — the chapeau plus the thirteen lettered requirements in Part I, and the eight vulnerability handling requirements in Part II. Each row carries the Official Journal wording, a column for whether it applies, one for how your product meets it, and one for where the evidence lives. A worked example row in each sheet shows the expected level of detail. | Article 13(3) requires the assessment to indicate whether and, if so in what manner each Part I requirement applies, and how it is implemented. One row per requirement is the only shape that cannot silently skip one. |
| Declaration of conformity Word |
The eight items Annex V requires, in order, each with the Annex wording quoted above the blanks so you can see what is being asked for. | Including the oddity: Annex V point 3 in the Official Journal says the declaration is issued under the sole responsibility of the provider, while Article 28 and the rest of Annex V say manufacturer. We flag it rather than quietly normalising it. |
| Vulnerability disclosure policy Word |
The policy Annex I Part II point 5 requires, with the decisions you actually have to make laid out as blanks: scope, contact address, acknowledgement and triage times, severity scheme, remediation targets by severity, and the disclosure window. | Point 5 requires you to put a policy in place and enforce it. Every timeline you publish becomes a commitment you are measured against, so the template pushes you to write numbers you can actually hit. |
| Reporting readiness Word |
Articles 14 and 16: both tracks, all four deadlines, the Article 14(7) rule for working out which CSIRT you report to, what ENISA’s platform needs from you in advance, and a pre-incident checklist. | This duty is already in force — since 11 September 2026 — and under Article 69(3) it reaches products you placed on the market before December 2027. It is the one file in the pack with a live deadline behind it. |
Plus a README explaining where every quoted passage comes from and what the files are not.
What these templates will not do
Worth saying plainly, because the limits of a template are not obvious until you are three months past buying one.
- They do not fill themselves in. The reasoning is the part an assessor reads, and it has to be about your product. The files give you the questions in the right order; the answers are yours.
- They do not update when the law underneath them moves. No harmonised standard for this Regulation has had its reference published in the Official Journal yet. When that changes — and it will, which changes what Annex V point 6 should say — a file on your disk will not know.
- They do not keep your versions. Article 13(13) requires the technical documentation and the declaration to be retained for at least ten years after the product is placed on the market, or the support period, whichever is longer. The version that governed the units you already shipped is the one you must be able to produce, and a folder of files does not survive a decade of staff changes and migrations.
Those three things are what the subscription does. This page is not a trick funnel into it — if the structure and the wording are all you wanted, these four files are yours to keep and you need nothing further from us.
Who this is for
| Buy this if | Don’t buy this if |
|---|---|
| You have decided the CRA applies to you and you are ready to start writing, but you do not want to spend a day working out what each document has to contain. | You are not sure whether the regulation applies to your product. Do the free check first — it takes two minutes and costs nothing, and it may tell you that you are out of scope. |
| You want the requirement wording quoted from the Official Journal rather than paraphrased by somebody’s content team. | You want the documents produced for you from answers, kept current and version-retained. That is the subscription, not this. |
| You are happy to maintain the files yourself from here. | You need legal advice on a borderline classification. Nothing here is legal advice, and a template cannot give you one. |
€39, once
Including VAT. One payment, no subscription, no account. Stripe handles the payment on its own page — card details never touch this site — and the download link appears immediately afterwards, with a copy in the receipt Stripe emails you.
Four files, €39
The Annex I risk assessment, the Annex V declaration, the disclosure policy and the reporting readiness sheet. Editable Word and Excel. Yours to keep and edit, for your own products.
Not sure the regulation applies to your product? Take the two-minute check first. If it says you are out of scope, do not buy this.
Nothing in the pack is legal advice, and filling the files in does not make a product compliant. We are not a law firm and not a notified body. If you find something wrong in them, write to andy@graycord.com quoting the provision — corrections get made and recorded on the about page.