wolfssl-examples/cra-kit/wolfssl-inc-auditor-packet/00-INDEX.md

2.2 KiB

wolfSSL Inc. CRA filings — index

File CRA reference Status
classification-statement.md Annex III / IV Decided — default category (not Annex III/IV), self-certification
conformity-assessment-route.md Art. 32, Annex VIII Module A self-assessment
declaration-of-conformity.template.md Art. 28 🟡 Template ready; signature pending product release alignment
eu-authorised-representative.md Art. 18 🟠 In progress — appointment underway
support-period-policy.md Art. 13(2), 13(8) Decided — 5-year minimum, longer for LTS lines
vulnerability-handling-process.md Art. 13, 14 🟡 Process documented; public SLA pending leadership approval
technical-documentation-outline.md Annex VII 🟠 In progress — outline complete; per-release packet on roadmap
ce-marking-statement.md Art. 30 🟡 Will affix on first CRA-applicable release after 11 Dec 2027

Reading order for new customers

  1. classification-statement.md — what wolfSSL is (and isn't) under Annex III/IV
  2. conformity-assessment-route.md — why Module A self-assessment fits this classification
  3. vulnerability-handling-process.md — the only continuous obligation
  4. support-period-policy.md — what we commit to maintain, for how long
  5. eu-authorised-representative.md — how a US-established manufacturer satisfies Art. 18
  6. declaration-of-conformity.template.md + technical-documentation-outline.md + ce-marking-statement.md — the formal output

CRA timeline anchors

  • 11 Sep 2026 — Art. 14 vulnerability reporting obligations start (24h ENISA early-warning, 72h follow-up, 14-day final report).
  • 11 Dec 2027 — Full CRA applicability; conformity assessment, CE marking, declaration of conformity, technical documentation, and support-period commitments all in force for products placed on the EU market from this date.