Stavenor

Guides

CRA User Information: The Nine Items of Annex II

Updated 20 September 20263 min read

Under the Cyber Resilience Act, every product with digital elements must come with specific information and instructions for its users. The list is in Annex II. Several published summaries say it has eight items. It has nine.


The nine items

# What you must provide
1 Your identity: name, registered trade name or trademark, postal address, email or other digital contact, and website where available
2 The single point of contact where vulnerabilities can be reported and information received, and where your coordinated vulnerability disclosure policy can be found
3 The product's name, type and any information enabling its unique identification
4 Its intended purpose, including the security environment provided, its essential functionalities and information about its security properties
5 Any known or foreseeable circumstance, in intended use or reasonably foreseeable misuse, that may lead to significant cybersecurity risks
6 Where applicable, the internet address at which the EU declaration of conformity can be accessed
7 The type of technical security support offered, and the end date of the support period
8 Detailed instructions, or an internet address pointing to them, on six topics listed below
9 If you choose to make the software bill of materials available to users, where it can be accessed

Item 8: the six topics


Three traps

1. The support end date belongs at the point of sale. Article 13(19) requires the end date of the support period, at least month and year, to be indicated at the time of purchase in a clear and understandable way, and a notification to users once it expires, where technically feasible (Commission guidance C(2026) 5252, paragraph 127).

2. Item 2 cannot be only a chatbot. Recital 63: the single point of contact must not rely exclusively on automated tools.

3. Item 9 is optional; the SBOM is not. You are not obliged to make your SBOM public (recital 77). But if you do share it with users, item 9 applies.


Where it sits in your technical file

Annex VII, item 1: the technical documentation includes the user information and instructions set out in Annex II. Same content, two audiences: the user reads it in the product documentation, the authority finds it in the file.

Sources

Position as at 20 September 2026. General information, not legal advice.