The CRA puts security-by-design obligations directly on manufacturers, importers and distributors of hardware and software with digital elements — including embedded and IoT products. Conformity assessment, vulnerability handling and a support-period commitment are now product requirements.
Free readiness call
Thirty minutes, with a specialist who holds a credential in CRA — not a generalist account manager.
Product classification — default, important, or critical category
Essential requirements gap assessment against Annex I
Software Bill of Materials (SBOM) readiness
Vulnerability disclosure and handling process design
Conformity assessment routing — self-assessment vs. notified body
Pure SaaS with no distributed product component generally sits outside CRA's product scope — but any distributed client, agent or on-prem component brings it back in.
The CRA phases in over several years post-entry-into-force, with reporting obligations landing before the full compliance deadline — we'll confirm exact dates against your product category.
Thirty minutes, free, with someone who holds a credential in the framework you're asking about.
Book a free 30-minute call