User Information and Instructions
CRA user information is the material that accompanies the product and helps users install, operate, update, report vulnerabilities in, and retire the product securely. It is written for users, integrators, owners, and operators, not only for the manufacturer's internal file.
Information for users
Manufacturers shall ensure that products with digital elements are accompanied by the information and instructions to the user set out in Annex II, in paper or electronic form. Such information and instructions shall be provided in a language which can be easily understood by users and market surveillance authorities. They shall be clear, understandable, intelligible and legible. They shall allow for the secure installation, operation and use of products with digital elements. Manufacturers shall keep the information and instructions to the user set out in Annex II at the disposal of users and market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Where such information and instructions are provided online, manufacturers shall ensure that they are accessible, user-friendly and available online for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.
Regulation (EU) 2024/2847, Article 13(18)
The information can be in paper or electronic form. It must be in a language that users and market surveillance authorities can easily understand. If it is online, it must stay accessible and user-friendly for the required period.
User-facing material
It explains secure use, support, updates, contact routes, and risk information users need.
Part of the evidence file
Annex VII also places the Annex II user information inside the technical documentation.
Annex II contents
Annex II is the minimum content list. It combines product identity, support information, secure-use instructions, and vulnerability contact information.
Annex II asks for the manufacturer's name, contact details, website if available, and enough product information to identify the product uniquely.
Users must be told how vulnerability information can be reported and received, and how to find the coordinated vulnerability disclosure policy.
The information must describe the intended purpose, security environment, essential functions, security properties, and any known or foreseeable circumstance that may lead to significant cybersecurity risks.
Annex II asks for the type of technical security support and the support-period end date. It also asks for instructions on installing security-relevant updates.
Annex II asks for secure commissioning, secure lifetime use, secure decommissioning, data removal, automatic-update settings, and integration information when the product is intended for integration into another product.
Secure-use instructions
The CRA does not ask for generic security advice. The instructions should match the product, its intended purpose, its foreseeable use, and the users who will install or operate it.
Annex II point 8 is the most practical part of the list. It asks for instructions, or a link to them, on:
- measures needed during initial commissioning and throughout the product lifetime;
- how product changes can affect data security;
- how security-relevant updates can be installed;
- secure decommissioning and secure removal of user data;
- how to turn off automatic security updates if they are enabled by default;
- integration information needed by another manufacturer or integrator.
Clear instructions do not replace design
User information can explain assumptions and residual risks. It cannot be used to leave product security requirements unaddressed.
Support date at purchase
Article 13(19) requires the support-period end date to be clear at the time of purchase. The date must include at least the month and year. If technically feasible, users must also be notified when the product reaches the end of support.
At purchase
Users should see the support end date before they rely on the product.
During use
Users need update instructions that match the product's actual update method.
Technical documentation boundary
User information and technical documentation have different audiences. User information is for secure use. Technical documentation is the evidence file used to show conformity with the CRA.
Annex VII includes the Annex II user information inside the technical documentation, but it also asks for internal evidence such as design information, architecture, vulnerability-handling process information, the cybersecurity risk assessment, support-period reasoning, standards used, and test reports.