Software & SaaS · Product Security · Engineering · EU Compliance
Create the cryptography evidence index for a CRA product technical file
Can every material cryptographic design claim be traced to implementation, test evidence, lifecycle support, and residual risk?
Operational pain
Product files become narrative collections that omit embedded libraries, default settings, signing infrastructure, vulnerability handling, and unsupported deployment assumptions.
Trigger
EU market entry, a substantial product modification, or CRA readiness review.
QNSI contribution
Connect the decision to a controlled security path
Export scoped QNSI inventory, algorithm policy, provenance, control mappings, and conformance links as an indexed evidence input.
Decision artifact
A CRA cryptography annex mapping product components and claims to evidence owners, versions, tests, and open gaps.
What still requires validation
The manufacturer and counsel determine product scope, conformity route, essential requirements, support period, and declaration content.
External problem context
Primary sources
These sources establish the external requirement or risk context. They do not endorse HEOSSI or prove that QNSI completed this scenario.
Evidence boundary
What this page does—and does not—prove
This is a product evaluation pattern, not a customer case study, certification, legal opinion, regulator endorsement, or claim that a production deployment completed the described work.