Applicability & role
Which products are “products with digital elements”, which exemptions apply, and whether you act as manufacturer, importer or distributor.
Cybersecurity & compliance
The Cyber Resilience Act sets binding cybersecurity requirements for hardware and software sold in the EU. Reporting obligations already apply since September 2026; the full requirements follow in December 2027. We help you understand what applies to your products and build the processes your teams need to meet it.
The CRA is a product law, not a management-system standard. It reaches into development, product management, support and legal at the same time.
From the first applicability check to the processes that keep your products compliant over their lifetime.
Which products are “products with digital elements”, which exemptions apply, and whether you act as manufacturer, importer or distributor.
Default, important (class I/II) or critical — and what that means for the conformity assessment route.
Your products and processes compared with the essential cybersecurity and vulnerability-handling requirements.
A documented cybersecurity risk assessment per product that drives design decisions.
A software bill of materials process for your own and third-party components, integrated into your build pipeline.
A coordinated vulnerability disclosure policy, intake, triage, fixes and security updates.
24-hour early warning, 72-hour notification and final report to ENISA’s single reporting platform and the national CSIRT.
Technical documentation, support period, EU declaration of conformity and preparation for the conformity assessment and CE marking.
Inventory of products and versions on the EU market, your role and the product classes.
Compare products, development and support processes with the CRA requirements.
Reporting readiness first (already in force), then the requirements for December 2027.
Secure development, SBOM, vulnerability handling and reporting — with your development and product teams.
Technical documentation, risk assessments and declarations that hold up in a market surveillance review.
Keep it running for every release and throughout the support period — ideally inside your ISMS.
Build on your ISMS instead of starting a parallel project
Many CRA requirements — risk management, secure development, supplier and vulnerability management, incident handling — already exist in an ISO/IEC 27001 ISMS. We connect the CRA to those structures so your teams do not have to run two systems.
Implementation support, not legal advice
We translate CRA requirements into processes, controls and documentation and implement them with your teams. Binding legal assessments — for example on scope, product classification or liability — should be confirmed by legal counsel. We do not perform conformity assessments ourselves; for classes that require third-party assessment, a notified body is involved.
Timeline
Reporting obligations already apply — the remaining requirements follow at the end of 2027.
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements — hardware and software — placed on the EU market. It covers security by design, vulnerability handling, security updates, documentation and reporting across the product lifecycle.
The CRA entered into force in December 2024. The obligation to report actively exploited vulnerabilities and severe incidents has applied since 11 September 2026. Most other requirements apply from 11 December 2027.
Manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products: an early warning within 24 hours, a notification within 72 hours and a final report afterwards — via ENISA’s single reporting platform to the responsible CSIRT.
Standalone software sold in the EU is a product with digital elements. Pure SaaS is generally covered by NIS2 rather than the CRA, but remote data processing that is necessary for a product to function can be in scope. We help you sort out which of your offerings fall where.
ISO/IEC 27001 manages information security in your organization; NIS2 regulates entities; the CRA regulates products. An ISMS gives you much of the foundation — risk management, secure development, supplier and incident management — on which CRA product processes can be built.
Violations of the essential requirements and manufacturer obligations can be fined up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Market surveillance authorities can also restrict or withdraw non-compliant products.
Understand which cybersecurity regulations apply, identify the gaps and implement practical technical and organizational measures.
Develop a clear incident response plan with your team: roles, escalation, communication, reporting and lessons learned.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
What an incident response plan must contain: roles, escalation, communication, NIS2 and CRA reporting deadlines, evidence and lessons learned.
NIS2, the Cyber Resilience Act and the EU AI Act explained: who is affected, which 2026 deadlines apply and how one ISMS covers shared requirements.
Recap of the IHK Darmstadt IT managers meeting: FeldmannCyber on IT security monitoring along the Cyber Kill Chain — scans, monitoring and SIEM.
Tell us about your products. We help you work out what the CRA means for them and where to start.