> For the complete documentation index, see [llms.txt](https://www.headlesslaw.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.headlesslaw.com/cra/annexes/annex-ii.md).

# Annex II

*In force · Consolidated version of 20 November 2024 · Checked against EUR-Lex on 2 Oct 2026 ·* [*Official source*](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R2847-20241120)

#### INFORMATION AND INSTRUCTIONS TO THE USER

At minimum, the product with digital elements shall be accompanied by:

**1.** the name, registered trade name or registered trademark of the manufacturer, and the postal address, the email address or other digital contact as well as, where available, the website at which the manufacturer can be contacted;

**2.** the single point of contact where information about vulnerabilities of the product with digital elements can be reported and received, and where the manufacturer’s policy on coordinated vulnerability disclosure can be found;

**3.** name and type and any additional information enabling the unique identification of the product with digital elements;

**4.** the intended purpose of the product with digital elements, including the security environment provided by the manufacturer, as well as the product’s essential functionalities and information about the security properties;

**5.** any known or foreseeable circumstance, related to the use of the product with digital elements in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to significant cybersecurity risks;

**6.** where applicable, the internet address at which the EU declaration of conformity can be accessed;

**7.** the type of technical security support offered by the manufacturer and the end-date of the support period during which users can expect vulnerabilities to be handled and to receive security updates;

**8.** detailed instructions or an internet address referring to such detailed instructions and information on:

**(a)** the necessary measures during initial commissioning and throughout the lifetime of the product with digital elements to ensure its secure use;

**(b)** how changes to the product with digital elements can affect the security of data;

**(c)** how security-relevant updates can be installed;

**(d)** the secure decommissioning of the product with digital elements, including information on how user data can be securely removed;

**(e)** how the default setting enabling the automatic installation of security updates, as required by Part I, point (2)(c), of Annex I, can be turned off;

**(f)** where the product with digital elements is intended for integration into other products with digital elements, the information necessary for the integrator to comply with the essential cybersecurity requirements set out in Annex I and the documentation requirements set out in Annex VII.

**9.** If the manufacturer decides to make available the software bill of materials to the user, information on where the software bill of materials can be accessed.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.headlesslaw.com/cra/annexes/annex-ii.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
