Prepare Your Products to Meet the Requirements of the Cyber Resilience Act (CRA)

The Cyber Resilience Act introduces new cybersecurity requirements for software, hardware, and other products with digital components.

We’ll help you determine how the CRA affects your products, what you’re missing, and how to implement the necessary measures.

CRA Timeline

Does the CRA apply to your products as well?

The Cyber Resilience Act applies to software, hardware, and other products with digital components placed on the market in the European Union.

These may include, for example, applications, IoT devices, network components, security solutions, industrial equipment, embedded software, or components sold separately. Your specific obligations also depend on your role in relation to the product.

Manufacturer

You develop or market, under your own brand, software or hardware with digital components, such as an application, an IoT device, a network component, or an industrial device with firmware.

According to the CRA, manufacturers have the most extensive obligations.

Importer

You are placing a digital product from a manufacturer outside the European Union on the EU market, such as a network device, an IoT product, or another connected device.

You must verify compliance with the CRA’s established requirements.

Distributor

You sell or resell software, connected devices, or other products with digital components from another manufacturer to customers.

According to the CRA, distributors also have specific monitoring and reporting obligations.

Not sure if the CRA applies to you?

During the initial consultation, we’ll discuss your products, how they’re provided, and how CRA requirements might affect you. If the CRA is relevant to your products, we will follow up with a detailed assessment of the CRA’s impact and a GAP analysis, which will identify specific requirements, the current status, and areas that need to be addressed.

What will you need to deal with?

The Cyber Resilience Act does not merely entail a one-time inspection before a product is brought to market. Cybersecurity must be managed throughout the entire product lifecycle.

Risk Management

Identification and assessment of a product's cyber risks.

SBOM and Components

Overview of the software components used and their dependencies.

Secure Development

Safety as an integral part of design, development, testing, and maintenance.

Documentation and Conformity Assessment

Documentation of compliance with requirements and the corresponding conformity assessment.

Vulnerability Management

Identification, tracking, and resolution of vulnerabilities in the product and its components.

Incidents and Reporting

Assessment and reporting of relevant vulnerabilities and security incidents.

Reporting begins as early as September 11, 2026
Vendors must be prepared to actively report actively exploited vulnerabilities and serious security incidents. An initial notification must be submitted within 24 hours, and a follow-up notification within 72 hours.

How does the CRA classify products?

Not all products with digital elements are subject to the same regulations. The CRA classifies products as common, important, and critical based on their significance in terms of cybersecurity. A product’s classification is particularly important because it affects the method of conformity assessment and whether the manufacturer can conduct it internally or must involve an independent third party.

Everyday Products

Most products with digital components fall under the basic regime. As a rule, the manufacturer may conduct an internal conformity assessment (self-assessment) for these products.

For example, memory chips, mobile apps, smart speakers, computer games…

Important Products

The CRA further categorizes them into Class I and Class II. For Class I products, an internal assessment may be possible under certain conditions, while Class II products require a more rigorous process involving a third party.

For example, operating systems, antivirus software, routers…

Critical Products

For selected products of the highest safety significance, the CRA establishes the most stringent conformity assessment regime, which requires independent verification or appropriate certification.

For example, smart cards, secure components…

Correct product classification is therefore one of the first steps in preparing for the CRA. It affects not only the method of conformity assessment, but also the scope of preparation, documentation, and other obligations.

Learn more about product categorization and conformity assessment under the CRA.

How can we help you with the CRA?

We will guide you through the entire CRA preparation process—from impact assessment and GAP analysis to the design of specific measures, and on to their implementation and long-term management.

If you are also addressing compliance with the Cybersecurity Act, DORA, ISO 27001, or other regulatory and security requirements, the cybreg platform allows you to integrate these areas, leverage common measures, and manage risks, tasks, responsibilities, and compliance all in one place.

We can also supplement your team with experienced cybersecurity experts as part of our CISO as a Serviceservice.

Impact Assessment and GAP Analysis

We’ll determine how the CRA affects your products and what needs to be addressed.

  • Assessment of the CRA’s Scope of Application to Your Products
  • Identification of Relevant Requirements and Obligations
  • GAP Analysis of the Current Situation
  • Proposed Priorities and Specific Measures

Implementation of CRA Requirements

We will help translate the CRA’s requirements into specific processes and measures.

  • Risk Management and Safety Measures
  • Vulnerability Management and Incident Reporting
  • Support in defining roles, responsibilities, and processes
  • Preparation of the necessary records and documentation

Manage CRA compliance, risks, and related activities in a clear and organized manner, all in one place.

  • Record of CRA Requirements and the Status of Their Implementation
  • Risk Management and Safety Measures
  • Tasks, Deadlines, Responsibilities, and Documentation
  • Reporting and Management Overview

Long-term expert support for cybersecurity management and compliance.

  • Ongoing Coordination of CRA and Security Activities
  • Risk Management, Measures, and Open Tasks
  • Support for Internal Teams and Management
  • Regular reviews and reporting on compliance status

Frequently Asked Questions

Everything You Need to Know About the Cyber Resilience Act in the Cybreg Environment.

The CRA primarily applies to manufacturers, importers, and distributors of products with digital elements placed on the European Union market. These may include, for example, software, applications, IoT devices, network components, or industrial equipment with firmware.

The specific product, the manner in which it is provided, and your company’s role are the key factors. Therefore, a good first step is to conduct a CRA impact assessment to determine which products and obligations are relevant to you.

Yes, the CRA also applies to software. However, for SaaS and cloud solutions, it is necessary to assess the specific way the service operates and is provided.

Not every SaaS solution automatically falls under the scope of the CRA. For example, remote data processing that is part of a product’s functionality and for which the manufacturer is responsible may be relevant. Therefore, we recommend assessing the scope of the CRA on a product-by-product basis.

The main requirements of the Cyber Resilience Act will take full effect on December 11, 2027. However, the first significant obligations will take effect as early as September 11, 2026.

As of this date, manufacturers must report actively exploited vulnerabilities and serious security incidents. An initial notification must be submitted within 24 hours, and a follow-up report within 72 hours. Companies must therefore have their responsibilities, vulnerability management, incident management, and reporting processes in place in a timely manner.

The CRA GAP analysis compares the requirements of the regulation with your current status.

Typically, the assessment covers risk management, secure development, vulnerability management, SBOM, security incidents, reporting, technical documentation, responsibilities, and other relevant processes.

The result should not be merely a list of shortcomings, but also priorities and specific measures that need to be implemented. If it is not yet clear which requirements apply to your products, we recommend conducting a CRA impact assessment before performing a GAP analysis.

Not necessarily. Many existing processes for managing risks, incidents, suppliers, security measures, or documentation can also be applied to CRA.

However, the CRA introduces specific requirements focused directly on products with digital elements, their development, vulnerabilities, components, and lifecycle. The goal, therefore, is not to reinvent everything, but to identify common areas and fill actual gaps.

The Cybreg platform allows you to manage CRA in accordance with the Cybersecurity Act, DORA, ISO 27001, and other requirements—all in one place.

We recommend proceeding step by step. First, determine which products fall under the scope of the CRA and what obligations apply to them. Next, conduct a GAP analysis, identify priorities, and propose specific measures.

The next step is to implement the necessary processes and manage them over the long term. This includes, for example, managing risks, vulnerabilities, incidents, responsibilities, tasks, and documentation.

If you lack the necessary internal resources, you can also supplement your own team with cybersecurity experts through the CISO as a Service offering.