Cyber Resilience Act
Cyber Resilience Act (CRA) readiness
If you manufacture, or market under your own name, software or a device with digital elements covered by the Cyber Resilience Act, since 11 September 2026 you must report actively exploited vulnerabilities and severe incidents. We help you set up the process now and prepare the product for December 2027.
Scope and price are confirmed in writing before work starts.
Discuss your caseThe benefit for your organisation
- You can report within 24 hours when a vulnerability in your product is exploited.
- You know what the product still lacks before December 2027 and how much time you have.
- Your EU customers get a product with documented security.
Reporting readiness
An Article 14 reporting procedure, roles and decisions, templates for the three reports, a coordinated vulnerability disclosure policy and a reporting channel. A short exercise.
from €2 400usually 1–2 weeks
CRA product assessment
Product classification, a comparison with the essential requirements and vulnerability-handling requirements, an SBOM process, gaps in the technical documentation and a plan to December 2027.
from €5 900one product · 3–5 weeks
What the Regulation requires
- Regulation (EU) 2024/2847. Reporting obligations (Art. 14) apply from 11 September 2026; the Regulation applies in full from 11 December 2027 (Art. 71).
- Deadlines run from becoming aware. Actively exploited vulnerability: an early warning within 24 hours, a notification within 72 hours and a final report within 14 days after a corrective measure is available. Severe incident: an early warning within 24 hours, a notification within 72 hours and a final report within one month after the notification.
- Reports go through the single reporting platform to the CSIRT designated as coordinator and to ENISA. The manufacturer also informs affected users.
- Vulnerability-handling requirements include a software bill of materials (SBOM) covering at least top-level dependencies and a coordinated vulnerability disclosure policy (Annex I, Part II).
- The support period for security updates is at least five years unless the product is expected to be in use for less (Art. 13).
Who it is for
For manufacturers of software, apps and devices with digital elements placed on the EU market, including software companies selling their own product. Importers and distributors have their own obligations. Some products are excluded because they have their own rules (for example medical devices and vehicles). We check the product’s classification, because the conformity assessment route depends on it. Product coverage and exclusions are confirmed before we quote.
After the review we can implement the agreed measures or coordinate your team or a suitable partner. Implementation is quoted separately.
Team training
We train developers and product teams on vulnerability handling, SBOMs, secure development and reporting, quoted separately. See also cybersecurity training.
Base scope and what you provide
- Reporting readiness: one manufacturer (one legal entity) and up to 3 products sharing one vulnerability process.
- Product assessment: one product or one product line with a shared codebase.
- You provide a description of the product, its architecture, dependencies and existing vulnerability processes. The timeline starts when we receive them.
- One presentation meeting and one round of corrections.
Boundaries
- We are not a notified body and do not issue conformity assessments or CE marking.
- Legal questions are commissioned separately from a lawyer. Technical product testing is agreed separately.
General information, not a legal opinion.