CRA Assurance Packs

This is the index for Stella Ops’ EU Cyber Resilience Act (CRA) support. It is for operators and product teams who need CRA evidence — either for Stella as a manufacturer or for a customer’s released product. For the wider Assurance framing and claim-boundary wording, see the parent Assurance and Compliance Packs index.

CRA support is split into two optional Assurance packs because the underlying product responsibilities are different.

PackClaim boundaryPurpose
CRA Product Security Packmanufacturer-selfStella’s own vulnerability intake, advisory publication, support lifecycle, and public publication preflight.
CRA Technical Documentation Packmanufacturer-customer-supportDeterministic technical-file and conformity-dossier exports for Stella releases or customer products.

Evidence scopes:

Pack Surfaces

ExportCenter Profiles

Profile idPackCompatibility route
cra.technical-fileCRA Technical Documentation Packstella export cra-tech-file
cra.conformity-dossierCRA Technical Documentation Packstella export conformity-dossier

Reporting Timeline Profiles

Profile idPackRuntime route
cra.article14.incidentCRA Product Security PackGET /api/v1/assurance/reporting-timeline-profiles/cra.article14.incident

Source Contracts And Module Docs

Product Boundary

Do not collapse CRA product-security obligations and customer technical-file support into one “CRA mode.” A local signed export can be ready while live public publication remains blocked by mailbox, key, route, or lifecycle preflight.

ExportCenter therefore reports signedExportReady and livePublicationReady separately for CRA Assurance profiles.

Notify reports Article 14 timeline readiness separately as operatorHandoffReady and autoSubmitReady. The default path is a local signed handoff; auto-submit remains explicit opt-in and must not be presented as live regulator receipt.

Change Log

Date (UTC)Update
2026-06-16Reconciled to verified code. Confirmed cra.technical-file and cra.conformity-dossier profiles registered in AssuranceExportProfileRegistry; tech-file/conformity adapters shipped under src/ExportCenter/StellaOps.ExportCenter.Adapters.Cra/. Claim boundary unchanged. Open residuals are tracked in cra-gap-closure-plan.md: ENISA SRP auto-submit transport remains a stub (default = operator filesystem handoff), the EU DoC is emitted as a stub (operator’s legal act), and no HTTP run-trigger exists yet for CRA bundle materialization.