Cyber Resilience Act (CRA) consulting: compliance for software and hardware manufacturers and suppliers
Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force in October 2024 and will be fully applicable in December 2027. It affects every manufacturer and distributor of products with digital elements sold in the EU: from desktop applications to IoT devices, routers and enterprise software. Fines reach €15 million or 2.5% of global annual turnover.
Does your company manufacture or distribute digital products in the EU?
If you develop software that includes client-side installable components, manufacture devices with network connectivity —IP cameras, routers, IoT devices, wearables, industrial systems—, distribute digital products made outside the EU within it, or your components are integrated into other manufacturers' products, the CRA affects you directly. The regulation applies across the whole chain: manufacturer, importer and distributor. Many companies wrongly assume it only applies to hardware manufacturers, but the CRA also covers software developers with networked components, desktop applications with remote connectivity and embedded systems. The deadline for full compliance is December 2027, but some obligations —such as reporting actively exploited incidents to ENISA— take effect in August 2026.
What our CRA consulting includes
- Applicability analysis: we determine whether your products fall within the scope of the CRA and in which category (Default, Class I, Class II or IACS)
- Technical gap analysis: we assess your secure development lifecycle (SDLC) against the requirements of Annex I of the CRA
- Vulnerability management gap analysis: disclosure, patching and ENISA notification processes
- Prioritized compliance plan: what to implement before August 2026 and what can wait until 2027
- Conformity assessment preparation: self-assessment for Default products, support with third-party audits for Class I and II
- Technical documentation: EU declaration of conformity, CE marking, security instructions for users
- Coordinated vulnerability disclosure (CVD) policy and ENISA notification process
CRA compliance process
- Product classification: We determine the category of each product (Default, Class I, Class II or IACS) based on its use, criticality and the criteria of Annex III of the CRA. The category defines the type of conformity assessment required.
- Technical gap analysis: We assess your development lifecycle against the essential cybersecurity requirements of Annex I: secure design, minimal attack surface, no default credentials, encryption, update management and event logging.
- Process gap analysis: We analyse your vulnerability management processes, responsible disclosure channels, security support periods and your ability to report actively exploited incidents to ENISA within the 24- and 72-hour windows.
- Compliance plan: We draw up an action plan with two horizons: urgent actions before August 2026 (ENISA reporting) and the full compliance plan for December 2027, with owners and effort estimates.
- Implementation and documentation: We support the implementation of technical controls in the SDLC and draft the mandatory documentation: EU declaration of conformity, security data sheet, user instructions and vulnerability history.
Deliverables
- Product classification report with justification based on the CRA and its Annexes
- Technical gap analysis against the essential requirements of Annex I (Parts I and II)
- Vulnerability management and ENISA notification process gap analysis
- Prioritized compliance plan with milestones for August 2026 and December 2027
- Draft EU declaration of conformity and technical security documentation
- Coordinated vulnerability disclosure (CVD) policy
Who does the CRA affect?
- Software manufacturers with installable components and network connectivity (SaaS with desktop agents, enterprise applications, firmware)
- Hardware manufacturers with connectivity: IoT devices, IP cameras, home and professional routers, wearables, connected medical devices
- Software component suppliers whose products are integrated into other manufacturers' products (libraries, SDKs, modules)
- EU importers and distributors of digital products manufactured outside the European Union
- Industrial automation companies and control system manufacturers (OT/ICS/SCADA) with networked components
Frequently asked questions about the CRA
When does the Cyber Resilience Act enter into force?
The CRA entered into force on 23 October 2024. Full application of the technical and conformity requirements is 11 December 2027. There are two critical intermediate deadlines: the requirements to report actively exploited incidents to ENISA apply from 11 August 2026, and notified bodies (for third-party assessment) must be designated from 11 September 2026.
Does the CRA apply to all software or only to connected hardware?
The CRA applies to all "products with digital elements": hardware and software with direct or indirect network connectivity. Excluded are open source software released without commercial purpose, pure SaaS services without client-side installable components, medical products regulated by the MDR, civil aviation products and defence equipment. If your SaaS includes a desktop agent or an installable plugin, that component does fall within the scope of the CRA.
What are the penalties for CRA non-compliance?
The CRA sets three levels of penalty: up to €15 million or 2.5% of global annual turnover for breaching the essential cybersecurity requirements; up to €10 million or 2% for breaching other obligations; and up to €5 million or 1% for providing incorrect information to the authorities.
What is the difference between Class I, Class II and Default products?
Default products are the majority and can use self-assessment. Class I includes higher-risk products (identity management systems, browsers, password managers, security software, home routers) and requires third-party assessment unless a harmonised standard is fully applied. Class II includes the most critical products (server operating systems, hypervisors, industrial firewalls, industrial control systems, PKI, TPMs) and mandatorily requires an audit by a notified body.
Does the CRA overlap with NIS2 or other regulations?
Yes. NIS2 regulates the cybersecurity of essential service operators, while the CRA regulates the security of digital products before they are placed on the market. If you are a software manufacturer and also operate an essential service, both apply to you. There are also overlaps with the MDR for connected medical devices (the MDR prevails) and with the EUCS scheme for critical cloud products.
How long does it take to comply with the CRA?
It depends on your starting point and product category. Companies with a secure SDLC already in place and mature vulnerability management processes can complete the process in 6-9 months. Organizations starting from scratch will need 12-24 months for full compliance before the 2027 deadline.