Skarp CRA

Sample

What your agent produces

One product, worked through. It has missed 2 statutory reporting deadlines. 18 of the 22 Annex I requirements apply to it, and 6 of those have nothing recorded against them yet.

It describes a product that does not exist and is not evidence of anything. Yours would carry a content hash tying it to the state it came from.

Start free See pricing

1. Where the product stands

The console, on opening

Reporting — 2 obligations overdue

Early warning
incident sample-incident-1
31 h late
Notification
incident sample-incident-1
7 h late
Early warning
incident sample-incident-2
14 h left

Filed by you on ENISA's Single Reporting Platform. This service drafts and records; it never submits.

Annex I applicable

18 of 22

2 found not applicable, 2 still undetermined.

Recorded as implemented

12 of 18

Progress against what applies, not a compliance score.

The risk assessment is marked stale. Annex I Part I applies on the basis of it, and the regulation expects it to be kept current for the support period. This does not mean nothing is due.

Determination

Recorded through your agent

ScopeIn scope
ClassImportant class I
Conformity routeNotified body
Economic operatorManufacturer
LifecyclePlaced on market
Risk assessmentVersion 3, Confirmed · stale
Annex I — applies?applicable: 18, not applicable: 2, undetermined: 2
Annex I — progressverified: 5, implemented: 7, in progress: 3, not started: 7

Why this classification

Ships a network-facing management plane and performs authentication for downstream services, which places it in the Annex III important class I category rather than the default.

2. The 22 essential requirements

All 22, with what is recorded against each

Annex I essential requirements for Atlas Gateway 4.2 — sample
AnchorRequirementApplicabilityStatusEvidence
Annex I Pt I(1)Designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks.ApplicableVerified4
Annex I Pt I(2)(a)Made available on the market without known exploitable vulnerabilities.ApplicableVerified2
Annex I Pt I(2)(b)Secure by default configuration, including the ability to reset the product to its original state — unless otherwise agreed between manufacturer and business user for a tailor-made product.ApplicableImplemented3
Annex I Pt I(2)(c)Vulnerabilities can be addressed through security updates, including automatic updates where applicable, with opt-out and the option to postpone.ApplicableImplemented1
Annex I Pt I(2)(d)Protection from unauthorised access by appropriate control mechanisms, including authentication and access management, and reporting of possible unauthorised access.ApplicableVerified5
Annex I Pt I(2)(e)Confidentiality of stored, transmitted or processed data, such as by state-of-the-art encryption at rest and in transit.ApplicableImplemented2
Annex I Pt I(2)(f)Integrity of stored, transmitted or processed data, commands, programs and configuration against unauthorised manipulation, and reporting of corruption.ApplicableIn progress1
Annex I Pt I(2)(g)Data minimisation — process only data adequate, relevant and limited to what is necessary for the intended purpose.ApplicableIn progress1
Annex I Pt I(2)(h)Availability of essential and basic functions, including resilience and mitigation against denial-of-service.ApplicableNot started0
Annex I Pt I(2)(i)Minimise the product's negative impact on the availability of services provided by other devices or networks.Not applicable
Annex I Pt I(2)(j)Limit attack surfaces, including external interfaces.ApplicableImplemented2
Annex I Pt I(2)(k)Reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques.ApplicableNot started0
Annex I Pt I(2)(l)Provide security-related information by recording and monitoring relevant internal activity, with an opt-out for the user.ApplicableImplemented3
Annex I Pt I(2)(m)Allow users to securely and permanently remove all data and settings, and to transfer data securely where that is possible.Not applicable
Annex I Pt II(1)Identify and document vulnerabilities and components, including a software bill of materials in a commonly used machine-readable format covering at least the top-level dependencies.ApplicableVerified1
Annex I Pt II(2)Address and remediate vulnerabilities without delay, providing security updates separately from functionality updates where technically feasible.ApplicableImplemented2
Annex I Pt II(3)Apply effective and regular tests and reviews of product security.ApplicableIn progress4
Annex I Pt II(4)Once a security update is available, publicly disclose information about fixed vulnerabilities — description, affected versions, impact, severity, and how users remediate.UndeterminedNot started0
Annex I Pt II(5)Put in place and enforce a coordinated vulnerability disclosure policy.ApplicableImplemented1
Annex I Pt II(6)Facilitate sharing of information about potential vulnerabilities, including a contact address for reporting vulnerabilities found in the product.ApplicableVerified1
Annex I Pt II(7)Provide mechanisms to securely distribute updates so vulnerabilities are fixed or mitigated in a timely and, where applicable, automated manner.UndeterminedNot started0
Annex I Pt II(8)Disseminate security updates without delay and free of charge, with advisory messages telling users what action to take.ApplicableNot started0

22 shown of 22. 8 would leave a hole in the technical file.

A requirement with nothing recorded against it is not a finding against your product. It means nothing has been recorded here. It does not mean the work has not been done.

Reconciled against the published text on 2026-08-06 (oldest of the catalogue files). The summaries are still paraphrases, not quotations — cite the link for authoritative wording. Article 7(4) delegated acts can amend the annexes, so this is true as of that date.

3. The Annex VII technical file

The page that gets printed and forwarded

Annex VII technical documentation — gap report

SAMPLE — not generated from recorded state

Atlas Gateway 4.2 — sample

Economic operator
Manufacturer

Product class
Important class I

Conformity route
Notified body

This is a sample document. It describes a product that does not exist.
It is published so you can see the shape of an Annex VII gap report before signing up. Nothing in it was recorded by anyone, it is not evidence of anything, and it must not be filed or forwarded as though it were.

A gap here means “not recorded in this service”. It does not mean the requirement is unmet.
Slots marked not recorded may well be satisfied by material held elsewhere. Read this document as an inventory of what this service holds, not as an assessment of the product.

3 mandatory section(s) still open.

Annex VII(1) General description of the product

intended purpose; versions of software affecting compliance with the essential requirements; for hardware, photographs or illustrations showing external features, marking and internal layout; user information and instructions (Annex II)

RECORDED

3 record(s)

Annex VII(2) Design, development, production and vulnerability handling processes

design and development information, including system architecture and how components integrate; vulnerability handling process specifications, including the SBOM, the coordinated vulnerability disclosure policy, the reporting contact address, and how security updates are securely distributed; production and monitoring processes, and their validation

RECORDED

5 record(s)

Annex VII(3) Cybersecurity risk assessment

the Article 13 risk assessment; how each Annex I Part I requirement applies to this product; how each applicable requirement is implemented

RECORDED

2 record(s)

Annex VII(4) Support period determination

information taken into account in determining the support period (Article 13(8))

Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.4', ...).

NOT RECORDED

Mandatory

Annex VII(5) Standards and specifications applied

harmonised standards applied in full or in part; other technical specifications or common specifications applied; where standards were not applied, a description of the solutions adopted to meet the essential requirements

Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.5', ...).

NOT RECORDED

Mandatory

Annex VII(6) Test reports

reports of the tests carried out to verify conformity of the product; reports of the tests carried out on the vulnerability handling processes

Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.6', ...).

NOT RECORDED

Mandatory

Annex VII(7) EU Declaration of Conformity

a copy of the EU declaration of conformity

Filled last, by design: freeze the file, draw up the declaration against it, then re-freeze so this section contains a copy.

FILLED LAST

By design

Annex VII(8) Software bill of materials

the SBOM, where requested by a market surveillance authority

Nothing attached. Use attach_evidence(subject_ref='technical_file:tf.8', ...).

NOT RECORDED

Optional

Content hashNone. A hash ties a copy to the state it came from; this document came from no state, so there is nothing to tie it to.
GeneratedNever. A real report carries the moment it was assembled, and regenerating it is how a reader checks a printed copy against current state.
RetentionUntil 2036-04-18 — Article 13(13) keeps the technical documentation and the EU declaration of conformity for 10 years from placing on the market.
StateNot frozen — this is a working view, not a signed version.
StatusAssembled from what you have recorded. This is not a conformity assessment and cannot certify that the product is compliant; where your product class requires a notified body, only that body can assess conformity.
CatalogueReconciled against the published text on 2026-08-06 (oldest of the catalogue files). The summaries are still paraphrases, not quotations — cite the link for authoritative wording. Article 7(4) delegated acts can amend the annexes, so this is true as of that date.

The rest happens in the agent

This console is read-only. The work happens in your coding agent, in the repository the answers come from: settling scope, deciding each risk, attaching evidence with its provenance, recording a vulnerability as actively exploited, drafting the ENISA report. A browser cannot see your repository, which is why this is an MCP server rather than a portal.

Daily SBOM scanning against OSV and CISA KEV, the Article 14 clocks that opened the obligations above, and the audit trail behind every row on this page all run there too.

Start free Back to the homepage