EU Cyber Resilience Act Readiness
The Cyber Resilience Act puts cybersecurity obligations on products with digital elements sold in the EU: secure-by-design requirements, vulnerability handling, an SBOM, and reporting of actively exploited vulnerabilities and severe incidents. Reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027; the work starts with knowing which of your products are in scope and in which class.
This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice, a regulatory determination, or a guarantee of compliance. Regulatory applicability depends on facts, jurisdiction, and legal interpretation that should be confirmed with qualified counsel.
The companies this problem finds first.
Manufacturers and importers of hardware and software products with digital elements sold in the EU
SaaS companies with a downloadable or on-device component
Open-source stewards and companies monetising open-source products
The moments that turn this from a someday into a now.
- EU product sales or distributor requests
- Reporting obligation date
- Notified-body or conformity question
- Customer asks for CRA position
8 areas, one control library.
Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.
Digital product inventory and classification (default, important class I/II, critical)
Essential cybersecurity requirements (Annex I Part I)
Vulnerability handling requirements (Annex I Part II)
SBOM and support period
Conformity assessment route
Technical documentation and EU declaration of conformity
Reporting of actively exploited vulnerabilities and severe incidents
Market surveillance readiness
Deliverables you can hand to a buyer, a board or a regulator.
- Digital product register with CRA classification position for counsel
- Requirement-by-requirement readiness per product
- Vulnerability-handling and reporting readiness
- Technical documentation gap list
- Roadmap to the 2026 and 2027 dates
The sources every control cites.
Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.
- EU Cyber Resilience Act (Regulation (EU) 2024/2847)
- NIST Secure Software Development Framework (SSDF) v1.1, SP 800-218
- ISO/IEC 27001
- Network and Information Security Directive 2 (Directive (EU) 2022/2555)
What each executive gets out of it.
CEO
Know which products carry CRA obligations before the reporting date.
CFO
Conformity work scoped per product class instead of assumed for the whole portfolio.
CTO / engineering
Secure-by-design and vulnerability-handling requirements mapped to what engineering already does.
General counsel
Classification reasoning documented for counsel and notified bodies.
CISO / security lead
Vulnerability reporting rehearsed against the 24-hour early-warning duty.
Integrated capabilities, not a separate programme.
Engagement tiers
Product Security · Compliance. Tiers describe depth and cadence; there is no per-regulation price.
Usually bought by
Chief product officer, CTO / engineering, General counsel, CEO
Part of these packages
EU Expansion
The objections, answered directly.
Pure remote services are largely outside scope, but downloadable clients, agents, on-device components and hardware are not. The product inventory decides it, product by product.
Start with the free check.
Cyber Resilience Act Quick Check: a short, scored indicator of where you stand and the evidence that would close each gap. A consultant follows up to scope the full readiness engagement.