CRAnotify Documentation

CRA controls and evidence

A product's Evidence tab answers one question: for the requirements that apply to this product, what is there and what is missing. It counts objects and gives no mark: the presence of evidence fills a box, it does not close an obligation, and a single summary figure would be read as a judgement even when it is only a ratio.

Where it lives

The Evidence tab of a product's page (/prodotto?id=…&tab=evidenze). Three panels: coverage per domain, the list of applicable controls with the gesture next to each one, and the most recent collected evidence.

Controls follow the confirmed roles

Which requirements appear depends on who you are with respect to that product. A merely suggested role adds no requirements: showing a distributor the manufacturer's controls is a mistake the reader has no way of catching.

If no CRA role has been confirmed for the product, no control is listed, and the tab says so. It does not mean there are none: it means the product does not yet declare who you are. Start from Your CRA role for each product.

ControlLegal sourceFor which role
Software bill of materials (SBOM) of the productAnnex I Part II point 1Manufacturer
Declared support periodArt. 13(8)Manufacturer
Documented vulnerability handling processAnnex I Part IIManufacturer
Published vulnerability reporting channelAnnex I Part II point 5Manufacturer
Technical documentation of the productArt. 31 and Annex VIIManufacturer
Identity and contact of the upstream manufacturerArt. 19Importer
Evidence of the check on marking and documentationArt. 19 and Art. 20Importer, distributor

The list is deliberately minimal and every row cites a verifiable article. A long list of invented requirements would give the impression of a coverage that is not there. It is not the complete list of the Regulation's duties: it is the set of controls this product can follow with evidence.

The states of a control

All of them describe the state of the collection. None is a judgement, except "not applicable", which is the only one that is a person's declaration — and its label says so.

Evidence presentAt least one collected or reviewed item covers the control.
Evidence missingNothing of the expected type has arrived.
Human review requiredSomething arrived but nobody has looked at it yet. It is the state anything from the supplier portal enters.
Not applicable · declaredA person declared that the requirement does not concern this product, with their name and a reason.
PendingA not-applicable declaration has been revoked: the control is back among those to be covered.

Coverage per domain

The first panel groups controls by question — bill of materials, vulnerability handling, technical documentation, lifecycle and support, supplier documentation — and shows a ratio such as "2 / 3". There is no percentage next to it, and that is deliberate: a ratio can be recounted, a mark cannot.

Watch two states that look alike and are not the same thing: "No applicable control" says no confirmed role requires those requirements, while "Not applicable" says a person assessed and declared. The first is a missing configuration, the second an assessment.

Declaring a control not applicable

Next to every control there is Declare not applicable. The form opens on the row of the control it refers to, not on a domain: a declaration wider than the one you meant to give is the one that later cannot be defended.

The reason is mandatory, and the check is on the server: "not applicable" without a why cannot be defended before anyone. Write why that requirement does not concern this product — not why in general you feel you need not cover it.

The declaration stays visible on the row with who made it, when, and the reason in full: whoever re-reads it should not have to dig it out of the registry. The Revoke the declaration button withdraws it, and the control returns among those to be covered; the revocation is a recorded gesture too, with its author.

The system can notice that a control has no evidence; it cannot conclude that none was needed. That is why the gesture exists and is yours.

Where evidence comes from

Evidence always carries its own provenance: knowing where it comes from is half its value.

Bill of materialsUploaded by hand or pushed by a connected tool: see Bill of materials and SBOM tools.
IntegrationsA connected tool brings in a document or the state of a process. An integration is a sensor: it proposes, it does not conclude.
Supplier portalWhoever is upstream files it themselves. What arrives is born "to be reviewed" and no path moves it to "reviewed" on its own.
Documents and casesMaterial produced by the compliance flow and attached to the product.

The list at the bottom of the tab shows the most recent evidence with the state it is in — where each document has got to in its path, never what it proves.

What it is for, afterwards

Covered controls are what the technical documentation file cites as evidence, each with the date the system learned it. Remaining work appears in the action queue. And to reconstruct what was on record on a given date — when an authority's question arrives — there is Reconstruction as of a date.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu