{
  "name": "CRA Software Evidence Map",
  "version": "1.0.0",
  "reviewed": "2026-09-07",
  "rulesetVersion": "cra-eu-2024-2847@2026-09-01.1",
  "url": "https://conformops.eu/research/cra-software-evidence-map",
  "creator": "ConformOps",
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "attribution": "ConformOps, CRA Software Evidence Map, version 1.0.0 (2026-09-07), https://conformops.eu/research/cra-software-evidence-map. CC BY 4.0. Indicate changes when adapting.",
  "licenseScope": "ConformOps' original mapping, commentary and dataset structure. Third-party legal texts and guidance remain subject to their own reuse terms; no ownership of them or official endorsement is claimed.",
  "methodology": [
    "Scope: one editorial row for each of the 16 ConformOps requirement IDs in the named ruleset. These are grouped product mappings, not the number of legal obligations and not an exhaustive clause-by-clause CRA checklist. Fifteen rows map binding law; one documents a non-binding source-handling convention.",
    "Method: compare each mapped subject with the cited legal text, identify plausible software-team records, then separate what can be inspected from what requires operational evidence or an accountable decision. Examples are illustrative, not observations from a sample of repositories or a list of files ConformOps necessarily parses.",
    "Legal references are editorially checked against the English EUR-Lex texts on the review date. They describe the subject of this public row and may refine the assessment catalogue's broader locators. Annex VII connections are our crosswalk, not extra obligations. Commission and ENISA explanatory guidance is non-binding; implementing regulations are binding law. No ENISA guidance supplies an additional requirement in this version.",
    "Automatically observable means inspectable from a repository snapshot: Yes means the bounded fact can be inspected directly; Partial means only supporting records or implementation clues are visible; No means the decisive fact requires external verification. It never means automatically satisfied. A repository may retain an external record without proving its authenticity or current validity.",
    "Strong evidence means comparatively stronger support for the stated claim after checking authenticity, date, product scope, release or build identity, completeness and reviewer authority. It is not a legal safe harbour. Missing evidence in a snapshot means unknown, not absent in the organisation; a successful scan or build is not proof of compliance.",
    "Human decision needed concerns the substantive manufacturer or reviewer judgment described in this dataset. It is separate from whether ConformOps implements a mandatory approval gate for that rule. A No on the editorial source-handling row means no separate legal decision is created by that convention.",
    "Maintenance: review legal sources and catalogue coverage before each release; increment the dataset version and review date for content changes, list affected IDs and reasons in the changelog, and retain prior released data files. These are dated editorial findings, not a promise of continuous legal monitoring. Corrections can be sent to help@conformops.eu with the row ID and supporting source."
  ],
  "vocabulary": [
    {
      "term": "Observable evidence",
      "definition": "A bounded fact directly inspectable in a particular source revision or retained artifact, such as a declared dependency or a configured test. Presence is not proof of effectiveness."
    },
    {
      "term": "Supporting evidence",
      "definition": "A record that helps substantiate a claim when its provenance, release relevance and scope are checked, such as a test report linked to a shipped build."
    },
    {
      "term": "Partial evidence",
      "definition": "Relevant information that leaves material parts of the claim unverified, such as a manifest without a build inventory."
    },
    {
      "term": "Human assertion/decision",
      "definition": "An attributed statement or accountable choice, such as product scope, risk acceptance or the support-period rationale. Storing it in Git does not turn it into an independently verified fact."
    },
    {
      "term": "Not observable from a repository",
      "definition": "A fact requiring evidence outside the source snapshot, such as whether a report was submitted, an inbox is monitored or a conformity procedure was completed."
    }
  ],
  "changelog": [
    {
      "version": "1.0.0",
      "date": "2026-09-07",
      "changes": "Initial publication of all 16 mapped requirement IDs, with independently checked legal locators, evidence boundaries, Annex VII connections, methodology and CC BY 4.0 downloads. No repository sampling or compliance scoring is performed."
    }
  ],
  "rows": [
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-SCOPE-001",
      "requirement": "Establish product scope and economic-operator role",
      "craReference": "Articles 2 and 3",
      "repositoryEvidence": "README.md; docs/product-scope.md; architecture diagrams; licence and distribution notes.",
      "otherEvidence": "Commercial supply terms, EU distribution records and a manufacturer-approved product boundary.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "The snapshot describes intended functions, interfaces and stated distribution assumptions.",
      "strongEvidence": "A dated scope decision tied to the release, actual supply model and remote processing dependencies, with evidence for any exclusion.",
      "partialEvidence": "An architecture diagram or README describing only one repository in a larger product.",
      "insufficientByItself": "An open-source licence or a README saying the CRA does not apply.",
      "cannotInfer": "Whether the product is made available on the EU market, whether an exclusion applies, or which legal role an organisation actually holds.",
      "humanDecisionNeeded": true,
      "humanDecision": "Confirm the product boundary, market facts, role and any exclusion rationale.",
      "annexVIIConnection": "1(a) intended purpose; 2(a) architecture. These support scope analysis, not a legal scope determination."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-CLASS-001",
      "requirement": "Determine category and conformity-assessment route",
      "craReference": "Articles 7, 8, 27 and 32; Annexes III, IV and VIII",
      "repositoryEvidence": "docs/classification.md; functional specifications; architecture decisions; standards mapping.",
      "otherEvidence": "Applicable Official Journal standards references, certification scope and external conformity-assessment records where required.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Documented product functions and a proposed category or standards mapping.",
      "strongEvidence": "An approved comparison of actual core functions to legal categories, with a justified route and verified scope of applied standards or certification.",
      "partialEvidence": "A functional specification naming security features without the complete product context.",
      "insufficientByItself": "A dependency on a cryptography library, a security badge or an unsupported claim of Class I status.",
      "cannotInfer": "The final category, full application of a harmonised standard, entitlement to a conformity presumption or completion of the selected route.",
      "humanDecisionNeeded": true,
      "humanDecision": "Approve classification and the applicable route; obtain the external assessment or certification when required.",
      "annexVIIConnection": "1(a), 2(a) product functions and architecture; 5 standards and solutions; 7 declaration."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-CLASS-002",
      "requirement": "Compare core functions with binding technical category descriptions",
      "craReference": "CRA Articles 7(4) and 8(2); Implementing Regulation (EU) 2025/2392 Article 2, Annexes I and II",
      "repositoryEvidence": "docs/category-rationale.md; feature specifications; system-boundary diagrams.",
      "otherEvidence": "Product demonstrations, hardware specifications and the accountable classification review.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Descriptions of implemented functions that can be compared with the implementing act.",
      "strongEvidence": "A function-by-function comparison to the relevant technical description, supported by product evidence and an approved rationale.",
      "partialEvidence": "An architecture document naming a firewall or identity feature without establishing the product's core functionality.",
      "insufficientByItself": "A keyword match to a category name or a vendor's marketing label.",
      "cannotInfer": "That a product belongs to a category merely because its source contains similar terminology or imports a related component.",
      "humanDecisionNeeded": true,
      "humanDecision": "Judge the actual core functionality against the binding category descriptions.",
      "annexVIIConnection": "1(a) intended purpose and 2(a) architecture support the category rationale.",
      "additionalSource": "https://eur-lex.europa.eu/eli/reg_impl/2025/2392/oj/eng",
      "additionalSourceLabel": "Binding implementing regulation (EU) 2025/2392"
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-RISK-001",
      "requirement": "Document and maintain a product cybersecurity risk assessment",
      "craReference": "Article 13(2)-(4); Annex VII(3)",
      "repositoryEvidence": "docs/threat-model.md; risk-register.csv; security architecture decisions; release risk reviews.",
      "otherEvidence": "Operational context, user and misuse evidence, signed residual-risk decisions and external test findings.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Named assets, threats, assumptions, proposed treatments and recorded review history.",
      "strongEvidence": "A release-specific assessment linking realistic use and misuse cases to controls, test evidence, applicability decisions and accountable risk acceptance.",
      "partialEvidence": "A threat model for one service without the product's other components or operating environment.",
      "insufficientByItself": "An empty risk-register template or a vulnerability scanner's numerical score.",
      "cannotInfer": "That all material risks were identified, a likelihood estimate is justified, or residual risk is acceptable to the manufacturer.",
      "humanDecisionNeeded": true,
      "humanDecision": "Approve assumptions, requirement applicability, treatment and residual-risk acceptance.",
      "annexVIIConnection": "3 risk assessment; 2(a) design context; 6 test reports."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-ESS-001",
      "requirement": "Build risk-based security into the product and release defaults",
      "craReference": "Article 13(1)-(4); Annex I Part I(1), (2)(a)-(b); Part II(3)",
      "repositoryEvidence": "Secure coding guidance; default configuration; tests/security/; .github/workflows/ security and release checks.",
      "otherEvidence": "Release-bound security test reports, exploitable-vulnerability review and evidence of enforced release controls.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Configured checks, security-related implementation and defaults in the inspected revision.",
      "strongEvidence": "Risk-linked security tests run against the shipped build, reviewed findings, verified secure defaults and a recorded release decision.",
      "partialEvidence": "A configured SAST workflow without execution results or proof that release gates are enforced.",
      "insufficientByItself": "A green build badge, a passing unit test suite or zero scanner matches.",
      "cannotInfer": "That all known exploitable vulnerabilities are absent, tests cover every risk, or repository defaults match the distributed product.",
      "humanDecisionNeeded": true,
      "humanDecision": "Review test scope, exploitability, exceptions and whether release security criteria are met.",
      "annexVIIConnection": "2(a), 2(c) design and validated production processes; 3 risks; 6 tests."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-ESS-002",
      "requirement": "Protect access, confidentiality and integrity",
      "craReference": "Annex I Part I(2)(d)-(f); Article 13(2)-(4)",
      "repositoryEvidence": "Authentication and authorisation code; TLS and encryption settings; integrity checks; negative access tests.",
      "otherEvidence": "Deployed configuration evidence, key-management records and penetration-test results against the relevant release.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Specific access checks, cryptographic calls, integrity controls and test cases present in source.",
      "strongEvidence": "Threat-linked access and tampering tests on the released product, with verified deployment settings and reviewed key lifecycle controls.",
      "partialEvidence": "An authentication middleware implementation without proof that every protected entry point uses it.",
      "insufficientByItself": "An encryption dependency or a README claiming enterprise-grade security.",
      "cannotInfer": "That controls cannot be bypassed, secrets are managed safely in operation, or deployed data is protected end to end.",
      "humanDecisionNeeded": true,
      "humanDecision": "Determine risk-appropriate controls and assess the completeness of implementation and verification.",
      "annexVIIConnection": "2(a) architecture and controls; 3 risk-based applicability; 6 verification reports."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-ESS-003",
      "requirement": "Minimise data and attack surface, and limit disruption and incident impact",
      "craReference": "Annex I Part I(2)(g)-(l); Article 13(2)-(4)",
      "repositoryEvidence": "Data-flow inventories; retention settings; rate limits; service and privilege configuration; resilience tests; logging policies.",
      "otherEvidence": "Live exposure reviews, recovery exercises, traffic and failure testing, and operational data-retention verification.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Declared data use, exposed interfaces, mitigation code and configured logging or resilience mechanisms.",
      "strongEvidence": "A release-bound data and interface inventory with justified necessity, least-privilege review, failure testing and verified incident-containment behaviour.",
      "partialEvidence": "A rate-limit configuration or backup script without a demonstrated recovery or load test.",
      "insufficientByItself": "A statement that only necessary data is collected, or that backups exist.",
      "cannotInfer": "That deployed interfaces match source, collected data is necessary, recovery works, or connected systems remain available during an attack.",
      "humanDecisionNeeded": true,
      "humanDecision": "Justify data necessity and applicability; review resilience, exposure and incident-impact evidence.",
      "annexVIIConnection": "2(a), 2(c) architecture and monitoring; 3 risk assessment; 6 tests."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-VULN-001",
      "requirement": "Operate vulnerability handling and coordinated disclosure",
      "craReference": "Article 13(6)-(8), (17); Annex I Part II(2)-(6)",
      "repositoryEvidence": "SECURITY.md; security.txt source; disclosure policy; triage runbook; advisory templates and remediation history.",
      "otherEvidence": "Published contact and policy, monitored inbox records, case timelines, upstream notifications and user advisories.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "A stated reporting channel, policy, handling steps and any retained issue or advisory records.",
      "strongEvidence": "A published CVD policy and usable contact, with attributable case records showing triage, remediation, upstream coordination and justified disclosure timing.",
      "partialEvidence": "SECURITY.md names a contact and response target but has no evidence of actual handling.",
      "insufficientByItself": "A security email address or a policy template copied into the repository.",
      "cannotInfer": "That the contact is monitored, the policy is enforced, reports are handled without delay or affected users received advisories.",
      "humanDecisionNeeded": true,
      "humanDecision": "Assign operational ownership, assess reports and approve remediation and disclosure decisions.",
      "annexVIIConnection": "2(b) vulnerability processes, CVD policy and contact evidence; 6 process tests."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-SBOM-001",
      "requirement": "Identify release components and document an SBOM",
      "craReference": "Annex I Part II(1); Article 13(5)",
      "repositoryEvidence": "packages.lock.json; package-lock.json; pom.xml; other manifests and lockfiles; supplied CycloneDX or SPDX JSON.",
      "otherEvidence": "Build output, SCA-generated SBOM, artifact digests and supplier component records.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Declared or locked dependencies and the contents and structural usability of a supplied SBOM.",
      "strongEvidence": "A release-bound CycloneDX or SPDX SBOM generated from the shipped build, with verified artifact identity and a reviewed inventory including at least top-level dependencies.",
      "partialEvidence": "A dependency manifest: ranges do not identify shipped versions, and even a lockfile may include development-only components.",
      "insufficientByItself": "A README saying we track dependencies, or an empty generated SBOM.",
      "cannotInfer": "That all shipped components are present, a supplied SBOM is accurate, or the product has no vulnerabilities. Presence, structural usability and completeness are different claims.",
      "humanDecisionNeeded": true,
      "humanDecision": "Confirm release linkage and inventory completeness, investigate divergences and assess component vulnerabilities.",
      "annexVIIConnection": "2(b) SBOM within vulnerability-process documentation; 8 supply to authorities where applicable following a reasoned request. This is not a general duty to publish the SBOM."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-UPDATE-001",
      "requirement": "Justify the support period and securely deliver security updates",
      "craReference": "Article 13(8), (9), (19); Annex I Part I(2)(c), Part II(2), (7)-(8)",
      "repositoryEvidence": "SUPPORT.md; end-of-support policy; release workflow; signing and update verification code; update-user guidance.",
      "otherEvidence": "Expected-use and lifecycle evidence, support commitments, signed release artifacts, delivery tests and update availability records.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "A proposed support end date, configured update mechanisms and stated distribution process.",
      "strongEvidence": "An approved support-period rationale tied to expected product use, with authenticated release artifacts, tested distribution and retained availability evidence.",
      "partialEvidence": "A release-signing workflow or end-of-support date without execution, delivery or lifecycle evidence.",
      "insufficientByItself": "A promise of lifetime updates or a signed Git tag without a verified update chain.",
      "cannotInfer": "That the chosen duration is justified, users can obtain and install updates, signing keys are controlled, or updates remain available for the required period.",
      "humanDecisionNeeded": true,
      "humanDecision": "Approve the support rationale, applicable exceptions and the adequacy of delivery and retention arrangements.",
      "annexVIIConnection": "2(b) secure update distribution; 4 support-period rationale; 1(d) user instructions."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-REPORT-001",
      "requirement": "Prepare and make required actively exploited vulnerability reports",
      "craReference": "Article 14(1)-(2), (8); Article 16",
      "repositoryEvidence": "Article 14 runbook; reporting templates; escalation and backup-owner records; drill notes.",
      "otherEvidence": "Awareness timestamps, exploitation and affectedness evidence, submission receipts and affected-user communications.",
      "automaticallyObservable": "No",
      "observableEvidence": "The presence of a runbook or retained drill record can be inspected; an actual reporting obligation and submission require external facts.",
      "strongEvidence": "An accountable case decision and timestamped reports with platform receipts linked to the relevant vulnerability, plus user-notification records where applicable.",
      "partialEvidence": "A rehearsed runbook with named owners and the 24-hour, 72-hour and applicable final-report steps.",
      "insufficientByItself": "A CVE or KEV match, an internal issue marked reported, or a successful drill presented as a real submission.",
      "cannotInfer": "That this product is actively exploited, when awareness arose, whether reporting is required, or whether the authority received a timely report.",
      "humanDecisionNeeded": true,
      "humanDecision": "Assess the reporting trigger and awareness facts; make and record required reports and user communications.",
      "annexVIIConnection": "2(b) related vulnerability-handling process context. Annex VII documentation is not an Article 14 submission."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-REPORT-002",
      "requirement": "Prepare and make required severe-incident reports",
      "craReference": "Article 14(3)-(5), (8); Article 16",
      "repositoryEvidence": "Incident reporting runbook; severity criteria; report templates; escalation roster; drill results.",
      "otherEvidence": "Incident impact and awareness records, accountable severity decisions, platform receipts and affected-user notices.",
      "automaticallyObservable": "No",
      "observableEvidence": "A written process can be inspected, but actual incident severity and reporting performance require incident and submission evidence.",
      "strongEvidence": "A documented severity assessment, awareness timeline and retained receipts for the early warning, incident notification and applicable final report.",
      "partialEvidence": "A drill demonstrating the reporting process and backup ownership without a real incident record.",
      "insufficientByItself": "A generic incident policy or an internal severity label without the Article 14 threshold analysis.",
      "cannotInfer": "That an incident meets the legal severity threshold, deadlines were met, or a final report was received by the reporting platform.",
      "humanDecisionNeeded": true,
      "humanDecision": "Assess severity and awareness, own submissions, and determine affected-user communications.",
      "annexVIIConnection": "2(b), 2(c) related handling and monitoring process context; does not replace Article 14 reporting."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-TECH-001",
      "requirement": "Prepare, maintain and retain technical documentation",
      "craReference": "Articles 13(12)-(13) and 31; Annex VII",
      "repositoryEvidence": "docs/technical-file/; architecture and design records; standards register; test reports; release-document index.",
      "otherEvidence": "Controlled technical-file package, production-validation records, approved risk and support rationale, signed declaration and retention controls.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Available documentation sections, named versions and links to retained supporting records.",
      "strongEvidence": "A controlled release-specific file covering all applicable Annex VII elements, with traceable sources, responsible review, retained tests and a copy of the declaration.",
      "partialEvidence": "An architecture document and generated technical-file draft with missing production, testing or approval records.",
      "insufficientByItself": "An Annex VII folder, a populated template or a generated export labelled complete.",
      "cannotInfer": "That the technical file is complete, current, authentic, retained for the required period or sufficient for a conformity assessment.",
      "humanDecisionNeeded": true,
      "humanDecision": "Review every applicable section and its evidence, resolve omissions and control release and retention of the file.",
      "annexVIIConnection": "1 product and instructions; 2 design, production and vulnerability processes; 3 risks; 4 support rationale; 5 standards; 6 tests; 7 declaration; 8 SBOM on qualifying authority request."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-INFO-001",
      "requirement": "Provide product and security information to users",
      "craReference": "Article 13(18)-(20); Annex II",
      "repositoryEvidence": "User manual source; secure installation and configuration guides; update and decommissioning instructions; support and contact pages.",
      "otherEvidence": "The instructions actually supplied with the release, language and accessibility review, and publication or distribution evidence.",
      "automaticallyObservable": "Partial",
      "observableEvidence": "Written instructions, stated security properties and contact or support details in the snapshot.",
      "strongEvidence": "Release-matched instructions checked against the product and Annex II, delivered in the required form and language with verified contact and support information.",
      "partialEvidence": "A developer README with installation steps but no user-specific security or decommissioning guidance.",
      "insufficientByItself": "A documentation URL or a statement that users should configure the product securely.",
      "cannotInfer": "That the instructions reach users, are understandable in the required language, or accurately describe the distributed product and its support arrangements.",
      "humanDecisionNeeded": true,
      "humanDecision": "Review accuracy, audience, language and delivery for the relevant market and release.",
      "annexVIIConnection": "1(d) information and instructions required by Annex II."
    },
    {
      "authorityKind": "Binding law",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-DOC-001",
      "requirement": "Complete conformity assessment, declaration and CE marking",
      "craReference": "Article 13(12); Articles 28-30 and 32; Annex V",
      "repositoryEvidence": "Declaration draft; conformity-procedure index; CE artwork; references to certificates and sign-off records.",
      "otherEvidence": "An authorised signed declaration, completed conformity-assessment records, valid external certificates where required and marking evidence.",
      "automaticallyObservable": "No",
      "observableEvidence": "A declaration file or marking asset can be found, but authority, route completion and actual marking require verification beyond source.",
      "strongEvidence": "An authenticated signed declaration identifying the product and applicable legislation, backed by the completed route and verified marking on the distributed product as applicable.",
      "partialEvidence": "A filled Annex V working draft or a certificate reference without scope and validity checks.",
      "insufficientByItself": "A generated declaration, a CE logo in the repository or a passing evidence check.",
      "cannotInfer": "That the manufacturer has completed conformity assessment, an authorised person signed, the certificate covers this release or CE marking was correctly affixed.",
      "humanDecisionNeeded": true,
      "humanDecision": "Complete the applicable procedure; an authorised signatory issues the declaration and the manufacturer controls marking.",
      "annexVIIConnection": "7 copy of the EU declaration; 5 standards and specifications; 6 test reports."
    },
    {
      "authorityKind": "Non-binding editorial convention",
      "officialSource": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
      "lastReviewed": "2026-09-07",
      "id": "CRA-GUIDE-001",
      "requirement": "Distinguish binding law from explanatory guidance",
      "craReference": "Editorial convention, not a separate CRA obligation. Legal context: Article 31 and Annex VII.",
      "repositoryEvidence": "Source register; citations with authority labels and review dates; methodology documentation.",
      "otherEvidence": "Current official publications and an editorial review of any interpretation drawn from them.",
      "automaticallyObservable": "Yes",
      "observableEvidence": "Whether source entries contain a URL, date and binding or non-binding label.",
      "strongEvidence": "A reviewed source register linking legal propositions to EUR-Lex and separately labelling Commission or ENISA explanatory material.",
      "partialEvidence": "A useful guidance link without a date or distinction between explanation and legal text.",
      "insufficientByItself": "A Commission or ENISA logo, or a statement that guidance is legally binding.",
      "cannotInfer": "That guidance changes the Regulation, creates an additional obligation or validates a legal conclusion. This row is an editorial safeguard, not a compliance requirement.",
      "humanDecisionNeeded": false,
      "humanDecision": "No separate legal approval is created by this convention; an editor still checks source status and interpretation.",
      "annexVIIConnection": "No standalone Annex VII requirement to use this labelling convention; source traceability supports documentation review.",
      "additionalSource": "https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act",
      "additionalSourceLabel": "Non-binding Commission policy overview"
    }
  ]
}
