II

Annex II

INFORMATION AND INSTRUCTIONS TO THE USER

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

Quick Answer for Manufacturers

Annex II defines the mandatory information manufacturers must provide to users: manufacturer identity, contact for vulnerabilities, intended use, risks, support period, secure decommissioning.

This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.

At minimum, the product with digital elements shall be accompanied by:

1.

the name, registered trade name or registered trademark of the manufacturer, and the postal address, the email address or other digital contact as well as, where available, the website at which the manufacturer can be contacted;

2.

the single point of contact where information about vulnerabilities of the product with digital elements can be reported and received, and where the manufacturer’s policy on coordinated vulnerability disclosure can be found;

3.

name and type and any additional information enabling the unique identification of the product with digital elements;

4.

the intended purpose of the product with digital elements, including the security environment provided by the manufacturer, as well as the product’s essential functionalities and information about the security properties;

5.

any known or foreseeable circumstance, related to the use of the product with digital elements in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to significant cybersecurity risks;

6.

where applicable, the internet address at which the EU declaration of conformity can be accessed;

7.

the type of technical security support offered by the manufacturer and the end-date of the support period during which users can expect vulnerabilities to be handled and to receive security updates;

8.

detailed instructions or an internet address referring to such detailed instructions and information on:

a)

the necessary measures during initial commissioning and throughout the lifetime of the product with digital elements to ensure its secure use;

b)

how changes to the product with digital elements can affect the security of data;

c)

how security-relevant updates can be installed;

d)

the secure decommissioning of the product with digital elements, including information on how user data can be securely removed;

e)

how the default setting enabling the automatic installation of security updates, as required by Part I, point (2)(c), of Annex I, can be turned off;

f)

where the product with digital elements is intended for integration into other products with digital elements, the information necessary for the integrator to comply with the essential cybersecurity requirements set out in Annex I and the documentation requirements set out in Annex VII.

9.

If the manufacturer decides to make available the software bill of materials to the user, information on where the software bill of materials can be accessed.

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 2.6Complex systems and interoperability constraints

Complex systems with long development cycles, legacy components and interoperability constraints are not excluded from the CRA — but those constraints feed into the risk-based approach. Where specific essential requirements cannot (fully) be met (see recital 55), manufacturers must document the constraints, assess the risks and implement compensatory measures.

Key takeaways

  • A less secure legacy protocol may be implemented where necessary for interoperability, provided the risks are mitigated by other means; where the product supports both protocols, the secure one must be the default (Example 10).
  • Constraints, risks and mitigations must be transparently described in the technical documentation (Art. 31, Annex VII) and user information (Annex II).
  • Constraints must be periodically reassessed during the support period; where they can be lifted, the product should be updated accordingly.
  • Components purchased before the CRA applies may be integrated where the risk assessment identifies no specific risks and the product as a whole meets the requirements (Example 11).

In practice

Create a constraint dossier for every requirement you cannot (fully) meet: why it is not implementable (e.g. interoperability constraints), what risk arises, which compensatory measure applies — and schedule the reassessment. This is exactly the documentation market surveillance will want to see.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Common Manufacturer Questions

What information must be provided to users?

Manufacturer name and address, unique product identifier, intended use, secure initial setup, security update mechanism, support period end date, contact for vulnerability reports, reference to the EU declaration of conformity.

Is information in the user manual sufficient?

Not always. Some information must be readily accessible — on the product itself, in the packaging, or electronically. Annex II specifies this per item.

In which language must the information be?

In a language easily understandable for end users in the destination country. For EU-wide marketing, typically multilingual or in the language of each market.

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex