EU Cyber Resilience Act (CRA) Compliance Statement
Effective Date: September 2026
Entity: CoolR Group, Inc. (Delaware, USA)
1. Our Commitment
CoolR Group, Inc. ("CoolR") is aware of the EU Cyber Resilience Act, Regulation (EU) 2024/2847 (the "CRA"), and is committed to designing, developing, manufacturing, maintaining, and supporting our connected products - including our camera hardware and our connected intelligence platform - in compliance with the CRA's requirements, as and when those requirements become applicable to our products and to our role as manufacturer.
2. Regulatory Timeline
The CRA introduces its obligations in phases:
- September 2026 — reporting obligations take effect. Manufacturers must notify the relevant EU authorities of actively exploited vulnerabilities and severe security incidents affecting products with digital elements.
- December 2027 — the CRA's broader requirements take effect, including secure-by-design and essential cybersecurity requirements, conformity assessment, technical documentation, the EU Declaration of Conformity, Software Bill of Materials (SBOM) provisioning, and CE marking under the CRA.
CoolR is building out its compliance program to meet each of these deadlines as it arrives.
3. How We're Preparing
- Vulnerability management. We maintain a coordinated vulnerability disclosure (CVD) process, including a public channel for security researchers to report issues, defined triage and remediation timelines, and a commitment to working with researchers on coordinated, good-faith disclosure. Full details are in our Vulnerability Disclosure Policy.
- Incident and vulnerability reporting. In line with Article 14 of the CRA, we are establishing the processes needed to notify the relevant EU authorities of actively exploited vulnerabilities and severe security incidents within the regulatory timelines the CRA requires.
- Conformity assessment and CE marking. Where and once required under the CRA, our products will undergo the applicable conformity assessment procedure, be accompanied by the required technical documentation, and carry the appropriate CE marking.
- Security updates. We are committed to providing security updates and vulnerability remediation for our products for a minimum support period consistent with the CRA's requirements, generally no less than five years from the date a product is placed on the market.
- Ongoing program. CRA compliance is part of our broader security and compliance program, which we review and update as our program matures and as regulatory guidance develops.
4. Supporting Certifications
CoolR is pursuing ISO 27001 and SOC 2 Type II certification, both independently verified by third-party auditors. These certifications will further evidence our security controls and support our ongoing CRA compliance.
5. Questions
For questions about this statement or CoolR's security and compliance program, or to report a security vulnerability, contact support@coolr.ai or see our Vulnerability Disclosure Policy.
6. Changes
This statement is provided for general informational purposes and reflects CoolR's compliance program as of the effective date above. It may be updated from time to time as our compliance program develops. It should not be read as, and does not constitute, an EU Declaration of Conformity or other certification required under CRA.