This page reflects our reading of Cyber Resilience Act, Article 14 and related guidance as of . It is not legal advice. Review process.
Any page in the Compliance Hub, and any how-to or explanation page that states a legal deadline, obligation, or interpretation, carries a disclaimer directly under its heading. This page is what that disclaimer links to.
What the disclaimer means
It states three things: which primary source the page's claims rest on, the date that source was last checked, and that the page is not legal advice. It is placed at the top of the page, not in a footer, because a reader under deadline pressure should see it before anything else on the page.
What counsel review status actually is
Declara's underlying legal template content — the packet fields, the deadline interpretations, and the reporting-obligation framing throughout these docs and the product — is not yet reviewed by outside counsel. This is stated plainly here rather than softened: every regulatory claim on this site reflects an internal reading of the Cyber Resilience Act and ENISA guidance, checked against primary sources, but not yet signed off by a lawyer. Treat it as a well-researched starting point, not a legal opinion.
How a regulatory page qualifies as reviewed
A page carrying the disclaimer is considered current when all three of the following hold:
- It cites a primary source — EUR-Lex text or ENISA/EC guidance — with a checked-on date.
- That check is recorded as an entry in the regulatory changelog.
- It has been re-reviewed since the last time the SRP field glossary version bumped, or since ENISA last updated SRP guidance — whichever is more recent.
When a page gets re-reviewed
Automatically triggered by two things: a version bump to the SRP field glossary that the report packet fields are drawn from, and any update to ENISA's own SRP guidance. Outside of those triggers, regulatory pages are reviewed on the same cadence as the rest of the docs — at minimum every six months, or sooner if a feature they describe changes.