Skip to main content

Simplified Technical Documentation for Micro & Small Software Enterprises

The Cyber Resilience Act (CRA) acknowledges that the administrative load of full-scale technical documentation can be heavy, especially for smaller players in the software market. To address this, the CRA includes a provision specifically for micro and small enterprises.

Easing the Burden

Article 33, Paragraph 5, empowers the European Commission to specify a "simplified technical documentation form targeted at the needs of microenterprises and small enterprises". The goal is to ease the financial and administrative burden without compromising on the core compliance requirements.

Recital 93 explains that this simplified form will still cover all the applicable elements from Annex VII but will specify how a small company can provide the requested information in a more concise way.

What is a Micro or Small Enterprise?

The CRA uses the definitions from the EU's Recommendation 2003/361/EC. Broadly:

  • Microenterprise: Fewer than 10 employees and an annual turnover or balance sheet total of no more than €2 million.
  • Small Enterprise: Fewer than 50 employees and an annual turnover or balance sheet total of no more than €10 million. If your game studio or app development company fits these criteria, this simplification is for you.

How it Will Work

  • Commission Implementing Act: The Commission will adopt an implementing act that lays out this simplified form.
  • Optional Use: Micro and small enterprises can choose to use this form. You are not required to; you can still provide the full, extensive documentation if you prefer.
  • Accepted by Notified Bodies: If your software requires third-party assessment and you use the simplified form, notified bodies must accept it.

This measure is designed to provide legal certainty and reduce the effort needed for smaller software businesses to prove their CRA compliance.

Key Takeway

If you run a micro or small software enterprise, the CRA plans for a simplified technical documentation form to help you meet your obligations more concisely. Keep an eye out for the implementing act from the Commission that will define this form.