NIS2 — transposed Oct 2024 DORA — enforced Jan 2025 EU AI ACT — Art.50 transparency 2 Aug 2026 CRA — reporting obligations from Sep 2026 ISO 42001 — certification live GDPR — ongoing enforcement NIS2 — transposed Oct 2024 DORA — enforced Jan 2025 EU AI ACT — Art.50 transparency 2 Aug 2026 CRA — reporting obligations from Sep 2026 ISO 42001 — certification live GDPR — ongoing enforcement
Home/Services/Cyber Resilience Act (CRA) Compliance
CRA

Cyber Resilience Act (CRA) Compliance

The CRA puts security-by-design obligations directly on manufacturers, importers and distributors of hardware and software with digital elements — including embedded and IoT products. Conformity assessment, vulnerability handling and a support-period commitment are now product requirements.

  • Product risk classification (default/important/critical)
  • Annex I essential requirements gap assessment
  • Software Bill of Materials (SBOM) readiness
  • Vulnerability disclosure process design

Free readiness call

Request a CRA scoping call

Thirty minutes, with a specialist who holds a credential in CRA — not a generalist account manager.

No obligation. No spam. One reply, from a specialist.

What's included

1

Product classification — default, important, or critical category

2

Essential requirements gap assessment against Annex I

3

Software Bill of Materials (SBOM) readiness

4

Vulnerability disclosure and handling process design

5

Conformity assessment routing — self-assessment vs. notified body

Our process

01

Classify the product

02

Assess against Annex I essential requirements

03

Remediate design and documentation gaps

04

Route to the correct conformity assessment path

Frequently asked

Does the CRA apply to software we only sell as SaaS?

Pure SaaS with no distributed product component generally sits outside CRA's product scope — but any distributed client, agent or on-prem component brings it back in.

When do obligations actually start?

The CRA phases in over several years post-entry-into-force, with reporting obligations landing before the full compliance deadline — we'll confirm exact dates against your product category.

Get a straight answer on where you stand

Thirty minutes, free, with someone who holds a credential in the framework you're asking about.

Book a free 30-minute call