CRA Assurance Packs
This is the index for Stella Ops’ EU Cyber Resilience Act (CRA) support. It is for operators and product teams who need CRA evidence — either for Stella as a manufacturer or for a customer’s released product. For the wider Assurance framing and claim-boundary wording, see the parent Assurance and Compliance Packs index.
CRA support is split into two optional Assurance packs because the underlying product responsibilities are different.
| Pack | Claim boundary | Purpose |
|---|---|---|
| CRA Product Security Pack | manufacturer-self | Stella’s own vulnerability intake, advisory publication, support lifecycle, and public publication preflight. |
| CRA Technical Documentation Pack | manufacturer-customer-support | Deterministic technical-file and conformity-dossier exports for Stella releases or customer products. |
Evidence scopes:
- CRA Product Security Pack uses
stella-productand can exportstella-supplierevidence for customers that deploy Stella. - CRA Technical Documentation Pack uses
operator-suppliedmanufacturer evidence plus signed Stella evidence services.
Pack Surfaces
ExportCenter Profiles
| Profile id | Pack | Compatibility route |
|---|---|---|
cra.technical-file | CRA Technical Documentation Pack | stella export cra-tech-file |
cra.conformity-dossier | CRA Technical Documentation Pack | stella export conformity-dossier |
Reporting Timeline Profiles
| Profile id | Pack | Runtime route |
|---|---|---|
cra.article14.incident | CRA Product Security Pack | GET /api/v1/assurance/reporting-timeline-profiles/cra.article14.incident |
Source Contracts And Module Docs
- Assurance Runtime
- Assurance Scope Model
- Assurance Pack v1
- Assurance Evidence Export v1
- Assurance Setup Prerequisites v1
- CRA Technical File v1
- CRA Conformity Dossier v1
- Stella Product CSAF Advisory Contract v1
- Stella Supplier Evidence Profile v1
- ENISA Incident Reporting Contract v1
- ExportCenter architecture
- CLI export command guide
Product Boundary
Do not collapse CRA product-security obligations and customer technical-file support into one “CRA mode.” A local signed export can be ready while live public publication remains blocked by mailbox, key, route, or lifecycle preflight.
ExportCenter therefore reports signedExportReady and livePublicationReady separately for CRA Assurance profiles.
Notify reports Article 14 timeline readiness separately as operatorHandoffReady and autoSubmitReady. The default path is a local signed handoff; auto-submit remains explicit opt-in and must not be presented as live regulator receipt.
Change Log
| Date (UTC) | Update |
|---|---|
| 2026-06-16 | Reconciled to verified code. Confirmed cra.technical-file and cra.conformity-dossier profiles registered in AssuranceExportProfileRegistry; tech-file/conformity adapters shipped under src/ExportCenter/StellaOps.ExportCenter.Adapters.Cra/. Claim boundary unchanged. Open residuals are tracked in cra-gap-closure-plan.md: ENISA SRP auto-submit transport remains a stub (default = operator filesystem handoff), the EU DoC is emitted as a stub (operator’s legal act), and no HTTP run-trigger exists yet for CRA bundle materialization. |
