CRA User Information: The Nine Items of Annex II
Updated 20 September 20263 min read
Under the Cyber Resilience Act, every product with digital elements must come with specific information and instructions for its users. The list is in Annex II. Several published summaries say it has eight items. It has nine.
The nine items
| # | What you must provide |
|---|---|
| 1 | Your identity: name, registered trade name or trademark, postal address, email or other digital contact, and website where available |
| 2 | The single point of contact where vulnerabilities can be reported and information received, and where your coordinated vulnerability disclosure policy can be found |
| 3 | The product's name, type and any information enabling its unique identification |
| 4 | Its intended purpose, including the security environment provided, its essential functionalities and information about its security properties |
| 5 | Any known or foreseeable circumstance, in intended use or reasonably foreseeable misuse, that may lead to significant cybersecurity risks |
| 6 | Where applicable, the internet address at which the EU declaration of conformity can be accessed |
| 7 | The type of technical security support offered, and the end date of the support period |
| 8 | Detailed instructions, or an internet address pointing to them, on six topics listed below |
| 9 | If you choose to make the software bill of materials available to users, where it can be accessed |
Item 8: the six topics
- (a) the measures needed at initial commissioning and throughout the product's lifetime to ensure its secure use;
- (b) how changes to the product can affect the security of data;
- (c) how security-relevant updates can be installed;
- (d) secure decommissioning, including how user data can be securely removed;
- (e) how the default setting that installs security updates automatically can be turned off;
- (f) where the product is intended for integration into other products, the information the integrator needs to comply with Annex I and Annex VII.
Three traps
1. The support end date belongs at the point of sale. Article 13(19) requires the end date of the support period, at least month and year, to be indicated at the time of purchase in a clear and understandable way, and a notification to users once it expires, where technically feasible (Commission guidance C(2026) 5252, paragraph 127).
2. Item 2 cannot be only a chatbot. Recital 63: the single point of contact must not rely exclusively on automated tools.
3. Item 9 is optional; the SBOM is not. You are not obliged to make your SBOM public (recital 77). But if you do share it with users, item 9 applies.
Where it sits in your technical file
Annex VII, item 1: the technical documentation includes the user information and instructions set out in Annex II. Same content, two audiences: the user reads it in the product documentation, the authority finds it in the file.
Sources
- Regulation (EU) 2024/2847, Annex II; Article 13(19); Annex VII item 1; recitals 63 and 77 — Official Journal of the European Union
- European Commission, Guidance on the application of the CRA, C(2026) 5252, paragraph 127
Position as at 20 September 2026. General information, not legal advice.