CRA controls and evidence
A product's Evidence tab answers one question: for the requirements that apply to this product, what is there and what is missing. It counts objects and gives no mark: the presence of evidence fills a box, it does not close an obligation, and a single summary figure would be read as a judgement even when it is only a ratio.
Where it lives
The Evidence tab of a product's page (/prodotto?id=…&tab=evidenze). Three panels: coverage per domain, the list of applicable controls with the gesture next to each one, and the most recent collected evidence.
Controls follow the confirmed roles
Which requirements appear depends on who you are with respect to that product. A merely suggested role adds no requirements: showing a distributor the manufacturer's controls is a mistake the reader has no way of catching.
If no CRA role has been confirmed for the product, no control is listed, and the tab says so. It does not mean there are none: it means the product does not yet declare who you are. Start from Your CRA role for each product.
| Control | Legal source | For which role |
|---|---|---|
| Software bill of materials (SBOM) of the product | Annex I Part II point 1 | Manufacturer |
| Declared support period | Art. 13(8) | Manufacturer |
| Documented vulnerability handling process | Annex I Part II | Manufacturer |
| Published vulnerability reporting channel | Annex I Part II point 5 | Manufacturer |
| Technical documentation of the product | Art. 31 and Annex VII | Manufacturer |
| Identity and contact of the upstream manufacturer | Art. 19 | Importer |
| Evidence of the check on marking and documentation | Art. 19 and Art. 20 | Importer, distributor |
The list is deliberately minimal and every row cites a verifiable article. A long list of invented requirements would give the impression of a coverage that is not there. It is not the complete list of the Regulation's duties: it is the set of controls this product can follow with evidence.
The states of a control
All of them describe the state of the collection. None is a judgement, except "not applicable", which is the only one that is a person's declaration — and its label says so.
Coverage per domain
The first panel groups controls by question — bill of materials, vulnerability handling, technical documentation, lifecycle and support, supplier documentation — and shows a ratio such as "2 / 3". There is no percentage next to it, and that is deliberate: a ratio can be recounted, a mark cannot.
Watch two states that look alike and are not the same thing: "No applicable control" says no confirmed role requires those requirements, while "Not applicable" says a person assessed and declared. The first is a missing configuration, the second an assessment.
Declaring a control not applicable
Next to every control there is Declare not applicable. The form opens on the row of the control it refers to, not on a domain: a declaration wider than the one you meant to give is the one that later cannot be defended.
The reason is mandatory, and the check is on the server: "not applicable" without a why cannot be defended before anyone. Write why that requirement does not concern this product — not why in general you feel you need not cover it.
The declaration stays visible on the row with who made it, when, and the reason in full: whoever re-reads it should not have to dig it out of the registry. The Revoke the declaration button withdraws it, and the control returns among those to be covered; the revocation is a recorded gesture too, with its author.
The system can notice that a control has no evidence; it cannot conclude that none was needed. That is why the gesture exists and is yours.
Where evidence comes from
Evidence always carries its own provenance: knowing where it comes from is half its value.
The list at the bottom of the tab shows the most recent evidence with the state it is in — where each document has got to in its path, never what it proves.
What it is for, afterwards
Covered controls are what the technical documentation file cites as evidence, each with the date the system learned it. Remaining work appears in the action queue. And to reconstruct what was on record on a given date — when an authority's question arrives — there is Reconstruction as of a date.