Offer · Cybersecurity & Technical Security

CRA readiness for product companies

If you sell products with digital elements on the EU market, the Cyber Resilience Act applies to you. The reporting obligations have applied since 11 September 2026 and the product requirements apply from 11 December 2027. We take you from an unclear current state to a plan that holds both dates.

Cyber Resilience ActReporting from 11 September 2026Product requirements 11 December 2027SBOMA few days to a week

Who it is for and when

Suits companies that develop, manufacture or sell hardware or software on the EU market, and those that build third-party components into their products.

  • You sell software or connected products in the EU and do not know whether you are in scope, or in which class.
  • The reporting duty already applies and you have no routine for alerting ENISA and the national CSIRT in time.
  • You have no record of the components and dependencies in your products.
  • A customer or distributor has started asking you for CRA evidence.

What we do

  1. Scope and classification. We go through your product portfolio, determine which products are in scope and in which category, and what role you hold as manufacturer, importer or distributor.
  2. Reporting routine. We set the routine for actively exploited vulnerabilities and severe incidents: who raises the alert, how, and how you meet 24 hours, 72 hours and a final report within 14 days.
  3. Gap against the product requirements. We compare the current state with the requirements on secure development, vulnerability handling, updates and documentation, and list the gaps per product.
  4. Component record and vulnerability handling. We set up the work with SBOM, monitoring of vulnerabilities in third-party components and a process for releasing security updates.
  5. A plan to December 2027. You get a dated plan with owners, tied to your development and release cycles, plus the evidence the technical documentation requires.

You get

  • An assessment of which products are in scope and in which category
  • A reporting routine with the deadlines that have applied since 11 September 2026
  • A gap analysis against the CRA product requirements per product
  • An approach for SBOM and vulnerability handling in the supply chain
  • A dated plan through to 11 December 2027

Scope and price

From a few days for a company with one product to about a week for a broader portfolio. Many start with the reporting routine, since it already applies, and take the product requirements in stages.

The price varies from engagement to engagement and depends on the number of products, how development is organised and how much documentation already exists. You get a clear proposal after the first conversation.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set the work up. You get our assessment straight away, at no cost.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work alongside your organisation, report as we go and hand over so that you can manage the result yourselves.

Frequently asked questions

Are we in scope of the CRA?

The CRA applies to products with digital elements placed on the EU market, in practice most hardware and software products. Some categories carry stricter requirements. We go through your portfolio and determine role and class per product.

What has to be reported, and when?

Actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT: an early warning within 24 hours, a notification within 72 hours and a final report within 14 days of a corrective measure being available. This has applied since 11 September 2026.

What is an SBOM, and do we need one?

An SBOM is a record of the components in a product. The CRA requires the manufacturer to have control over components and vulnerabilities, and an SBOM is the practical way to get that control.

We already have ISO 27001, is that enough?

No, but it helps. ISO 27001 is about your own organisation, the CRA about your products. Much of the risk work and documentation can be reused.

Reviewed by Kristensson i Skåne AB. .

Sources: EUR-Lex: Regulation (EU) 2024/2847 (Cyber Resilience Act) · European Commission: CRA reporting obligations

Would you like to know what the CRA means for your products?

Contact us