Appendix: Forms & Templates
Overview
This appendix contains ready-to-use templates for the regulatory obligations under the CRA. The templates cover three areas:
- ENISA Reporting Obligations (Art. 14 CRA) -- Time-bound notifications to ENISA / CSIRT
- Incident Documentation -- Internal and external Incident Reports
- Compliance Documentation -- Risk Assessment, Declaration of Conformity, Product Security Information
APPLICATION NOTE
All templates must be completed on a product-specific basis. Placeholders in square brackets [...] shall be replaced with the actual values. Completed templates are archived in the respective incident ticket or in the product directory (docs/products/<product-name>/).
The ENISA notification templates are to be used operationally from 11 September 2026 onwards (-> 5.3 ENISA Reporting Process).
ENISA Notification Templates (Art. 14 CRA)
| Template | Deadline | CRA Reference | Usage |
|---|---|---|---|
| ENISA Early Warning | 24 hours | Art. 14(2)(a) | Initial notification in case of an actively exploited vulnerability / severe incident |
| ENISA Notification | 72 hours | Art. 14(2)(b) | Detailed vulnerability notification with technical details |
| ENISA Final Report | 14 days | Art. 14(2)(c) | Final analysis, Root Cause, Lessons Learned |
Incident Templates
| Template | Usage | Trigger |
|---|---|---|
| Incident Report (Internal) | Internal documentation of a security incident | Every SEV-1 to SEV-4 incident |
| Vulnerability Report (External) | User notification regarding a vulnerability | Art. 14(8): Without undue delay for ENISA-reportable events |
Compliance Templates
| Template | CRA Reference | Usage | Frequency |
|---|---|---|---|
| Risk Assessment | Art. 10(2), Annex VII No. 2 | Cybersecurity Risk Assessment per product | Before placing on the market + upon substantial changes |
| EU Declaration of Conformity | Art. 28, Annex V | Formal Declaration of Conformity per product | Before placing on the market + upon new versions |
| Product Security Information | Annex II | Security information for end users | Per product, updated upon version changes |
Templates in the Technical Documentation
In addition to the templates listed here, the 7.1 Product Description (Template) serves as a template for the product-specific technical documentation pursuant to Annex VII CRA.