Gap Analysis
A CRA gap analysis compares the current product and manufacturer processes with the CRA requirements that apply to that product. The term is an implementation method, not a separate duty named by the Regulation.
Legal basis for the comparison
The comparison should start from the source structure, not from a generic security checklist. For a product with digital elements, the core sources are Article 6, Article 13, Annex I, Annex II, Annex VII, Article 32, and the applicable standards or other technical specifications.
- Article 6 and Annex I decide the product and vulnerability-handling requirements.
- Article 13 requires the cybersecurity risk assessment and support-period reasoning.
- Annex II lists user information and instructions.
- Annex VII lists technical-documentation content.
- Article 32 decides the conformity assessment route after classification.
- Harmonised standards or other technical specifications can help show how requirements are met, but their legal effect depends on status.
What a gap means
A gap is not simply a missing document. A gap can be a missing product property, an incomplete vulnerability-handling process, weak evidence, an unsupported standards claim, or an unclear classification route.
Requirement gap
The product or process does not yet meet an applicable requirement.
Evidence gap
The product may have the measure, but the technical documentation does not show it clearly.
Analysis gap
The risk assessment or applicability reasoning is missing or too broad for the product.
Route gap
The standards, certification, or conformity-assessment route is assumed but not supported by source status or product category.
Boundaries
Gap analysis should not rewrite the legal test. Scope, product classification, technical descriptions, standards status, and conformity assessment each have their own page because they answer different questions.
The risk assessment is the main input for deciding which Annex I product requirements apply. The technical documentation is where the result and evidence are collected. See Cybersecurity Risk Assessment and Technical Documentation.