Product Security · P2

EU Cyber Resilience Act Readiness

The Cyber Resilience Act puts cybersecurity obligations on products with digital elements sold in the EU: secure-by-design requirements, vulnerability handling, an SBOM, and reporting of actively exploited vulnerabilities and severe incidents. Reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027; the work starts with knowing which of your products are in scope and in which class.

This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice, a regulatory determination, or a guarantee of compliance. Regulatory applicability depends on facts, jurisdiction, and legal interpretation that should be confirmed with qualified counsel.

Who it is for

The companies this problem finds first.

Manufacturers and importers of hardware and software products with digital elements sold in the EU

SaaS companies with a downloadable or on-device component

Open-source stewards and companies monetising open-source products

When it comes up

The moments that turn this from a someday into a now.

  • EU product sales or distributor requests
  • Reporting obligation date
  • Notified-body or conformity question
  • Customer asks for CRA position
What we assess

8 areas, one control library.

Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.

Digital product inventory and classification (default, important class I/II, critical)

Essential cybersecurity requirements (Annex I Part I)

Vulnerability handling requirements (Annex I Part II)

SBOM and support period

Conformity assessment route

Technical documentation and EU declaration of conformity

Reporting of actively exploited vulnerabilities and severe incidents

Market surveillance readiness

What you get

Deliverables you can hand to a buyer, a board or a regulator.

  • Digital product register with CRA classification position for counsel
  • Requirement-by-requirement readiness per product
  • Vulnerability-handling and reporting readiness
  • Technical documentation gap list
  • Roadmap to the 2026 and 2027 dates
Frameworks behind it

The sources every control cites.

Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.

  • EU Cyber Resilience Act (Regulation (EU) 2024/2847)
  • NIST Secure Software Development Framework (SSDF) v1.1, SP 800-218
  • ISO/IEC 27001
  • Network and Information Security Directive 2 (Directive (EU) 2022/2555)
Value by role

What each executive gets out of it.

CEO

Know which products carry CRA obligations before the reporting date.

CFO

Conformity work scoped per product class instead of assumed for the whole portfolio.

CTO / engineering

Secure-by-design and vulnerability-handling requirements mapped to what engineering already does.

General counsel

Classification reasoning documented for counsel and notified bodies.

CISO / security lead

Vulnerability reporting rehearsed against the 24-hour early-warning duty.

How it fits

Integrated capabilities, not a separate programme.

Engagement tiers

Product Security · Compliance. Tiers describe depth and cadence; there is no per-regulation price.

Usually bought by

Chief product officer, CTO / engineering, General counsel, CEO

Part of these packages

EU Expansion

FAQ

The objections, answered directly.

Pure remote services are largely outside scope, but downloadable clients, agents, on-device components and hardware are not. The product inventory decides it, product by product.

Start with the free check.

Cyber Resilience Act Quick Check: a short, scored indicator of where you stand and the evidence that would close each gap. A consultant follows up to scope the full readiness engagement.

Start the free Cyber Resilience Act Quick CheckSpeak with an advisor