What this service is
CRA Bureau is a documentation tool. It helps a manufacturer produce the artefacts that Regulation (EU) 2024/2847 requires: a scope determination, a cybersecurity risk assessment, a software bill of materials, a coordinated vulnerability disclosure policy, an Annex VII technical file, an EU declaration of conformity, an Article 14 reporting record, and a tamper-evident audit trail.
It works from the information you supply and from the dependency manifests you point it at. The quality of what it produces is bounded by the quality of what you put in.
What it is not
It is not legal advice. It summarises and applies a Regulation, and reasonable people can differ on how a provision applies to a particular product. Where this service and the Regulation disagree, the Regulation governs.
It is not a conformity assessment body and it is not a notified body. It cannot carry out the third-party conformity assessment that Annex III Class II and Annex IV products require, and it does not certify anything.
It is not affiliated with, endorsed by, or operated on behalf of the European Commission, ENISA, any national CSIRT, any notified body, or any market surveillance authority.
It does not submit reports to authorities on your behalf. The Article 14 workflow records what you sent and when; you submit through your national CSIRT’s own channel and the ENISA single reporting platform.
Your responsibility
Drawing up an EU declaration of conformity means assuming responsibility for the compliance of the product (Article 28(1)). That responsibility is yours and cannot be delegated to a tool.
This service will decline to issue a declaration while a blocking requirement is unmet, and it flags gaps in generated documents rather than hiding them. That is a safeguard, not a guarantee: a document can be complete in structure and still contain statements that are not true of your product.
What data we hold
Only what the service needs to do its job.
- Account details: your email address, name, and the organisation details you enter. The organisation details are the ones that appear on your declaration of conformity, so they are necessarily identifying.
- Product records: everything you type into the workspace — descriptions, risk assessments, requirement implementations, evidence notes.
- Dependency data: component names and versions parsed from the manifests you supply. We do not read, store or transmit your source code.
- Generated documents: the PDFs and SBOMs produced, with their SHA-256 hashes.
- The audit trail: a hash-chained record of compliance-relevant actions, including who performed them and when.
- Free tool submissions: the answers given to the scope checker and the results of a public SBOM scan, so the document can be regenerated without re-running the scan.
Third parties
Vulnerability data comes from OSV.dev. When you run a scan, the names and versions of your components are sent to OSV in order to look them up. No other information about you or your product is included.
When you scan a public repository, we fetch dependency manifests from GitHub or GitLab over their public APIs.
Payment is processed by Paddle, who act as merchant of record and handle EU VAT. Card details never reach this service — we only ever hold a Paddle customer reference.
Retention, and why you cannot simply be deleted
Article 31(3) requires you to keep the technical documentation and the declaration of conformity at the disposal of market surveillance authorities for ten years after the product is placed on the market, or for the support period, whichever is longer.
That is your obligation, not ours, and it outlives any subscription. So cancelling does not delete your documents: they and the audit trail remain downloadable. If you ask us to delete your account entirely we will, but we will tell you first what you are giving up, and we recommend exporting everything before you do.
Availability and liability
This is a tool, supplied as is. We do not warrant that it will be available without interruption, that vulnerability data will be complete, or that a document it produces will satisfy any particular assessor.
Nothing here excludes liability that cannot lawfully be excluded. Subject to that, our liability is limited to the fees you have paid in the twelve months before the claim.
Changes
The Regulation is new, harmonised standards are still being developed, and Commission guidance continues to be issued. We will change how this service interprets provisions as that happens, and we will say so when we do rather than quietly editing.