Cybersecurity & compliance

Cyber Resilience Act: make your products CRA-ready — step by step

The Cyber Resilience Act sets binding cybersecurity requirements for hardware and software sold in the EU. Reporting obligations already apply since September 2026; the full requirements follow in December 2027. We help you understand what applies to your products and build the processes your teams need to meet it.

Why the CRA is hard to get started with

The CRA is a product law, not a management-system standard. It reaches into development, product management, support and legal at the same time.

  • It is unclear which products are in scope and in which class they fall
  • Nobody owns the CRA: is it security, development, product management or legal?
  • There is no complete overview of third-party and open-source components
  • Vulnerability handling happens ad hoc instead of through a defined process
  • The 24-hour reporting deadline for actively exploited vulnerabilities cannot be met with today’s processes
  • Technical documentation, support periods and update policies are not defined

What we work on together

From the first applicability check to the processes that keep your products compliant over their lifetime.

Applicability & role

Which products are “products with digital elements”, which exemptions apply, and whether you act as manufacturer, importer or distributor.

Product classification

Default, important (class I/II) or critical — and what that means for the conformity assessment route.

Gap analysis against Annex I

Your products and processes compared with the essential cybersecurity and vulnerability-handling requirements.

Product risk assessment

A documented cybersecurity risk assessment per product that drives design decisions.

SBOM & components

A software bill of materials process for your own and third-party components, integrated into your build pipeline.

Vulnerability handling & CVD

A coordinated vulnerability disclosure policy, intake, triage, fixes and security updates.

Reporting process

24-hour early warning, 72-hour notification and final report to ENISA’s single reporting platform and the national CSIRT.

Documentation & conformity

Technical documentation, support period, EU declaration of conformity and preparation for the conformity assessment and CE marking.

How we approach CRA readiness

  1. Scope

    Inventory of products and versions on the EU market, your role and the product classes.

  2. Gap analysis

    Compare products, development and support processes with the CRA requirements.

  3. Prioritize

    Reporting readiness first (already in force), then the requirements for December 2027.

  4. Build processes together

    Secure development, SBOM, vulnerability handling and reporting — with your development and product teams.

  5. Document

    Technical documentation, risk assessments and declarations that hold up in a market surveillance review.

  6. Operate

    Keep it running for every release and throughout the support period — ideally inside your ISMS.

Build on your ISMS instead of starting a parallel project

Many CRA requirements — risk management, secure development, supplier and vulnerability management, incident handling — already exist in an ISO/IEC 27001 ISMS. We connect the CRA to those structures so your teams do not have to run two systems.

Implementation support, not legal advice

We translate CRA requirements into processes, controls and documentation and implement them with your teams. Binding legal assessments — for example on scope, product classification or liability — should be confirmed by legal counsel. We do not perform conformity assessments ourselves; for classes that require third-party assessment, a notified body is involved.

Timeline

Key CRA dates

Reporting obligations already apply — the remaining requirements follow at the end of 2027.

  1. 10 Dec 2024: Entry into force
  2. 11 Jun 2026: Rules for notified bodies
  3. 11 Sep 2026: Reporting obligations (24 h / 72 h)
  4. 11 Dec 2027: Full application

What you get out of it

  • Clarity on which products are affected and what they need
  • A reporting process that meets the 24-hour deadline
  • Vulnerability handling and SBOM as part of normal development
  • Documentation ready for conformity assessment and CE marking

Frequently asked questions

What is the Cyber Resilience Act?

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements — hardware and software — placed on the EU market. It covers security by design, vulnerability handling, security updates, documentation and reporting across the product lifecycle.

When does the CRA apply?

The CRA entered into force in December 2024. The obligation to report actively exploited vulnerabilities and severe incidents has applied since 11 September 2026. Most other requirements apply from 11 December 2027.

What must be reported, and how fast?

Manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products: an early warning within 24 hours, a notification within 72 hours and a final report afterwards — via ENISA’s single reporting platform to the responsible CSIRT.

Does the CRA apply to software and SaaS?

Standalone software sold in the EU is a product with digital elements. Pure SaaS is generally covered by NIS2 rather than the CRA, but remote data processing that is necessary for a product to function can be in scope. We help you sort out which of your offerings fall where.

How does the CRA relate to ISO 27001 and NIS2?

ISO/IEC 27001 manages information security in your organization; NIS2 regulates entities; the CRA regulates products. An ISMS gives you much of the foundation — risk management, secure development, supplier and incident management — on which CRA product processes can be built.

What are the penalties?

Violations of the essential requirements and manufacturer obligations can be fined up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Market surveillance authorities can also restrict or withdraw non-compliant products.

Related services

Related reading

Selling products with digital elements in the EU?

Tell us about your products. We help you work out what the CRA means for them and where to start.

contact@feldmanncyber.com · +49 (0)151 6275 6121