EU CRA Consulting

Cyber Resilience Act compliance guidance on the path to CE marking

Helping manufacturers of products with digital elements sold in the EU meet the Cyber Resilience Act (EU 2024/2847): product classification, gap analysis against the essential requirements, SBOM and vulnerability handling, incident reporting, and conformity assessment and technical documentation.

Compliance Advisory Advisory Service
For
Hardware and software manufacturers, importers, distributors selling into the EU
Deliverables
Classification, gap report, process documents, technical file package
Related Standards
Mapped against IEC 62443, the EN 18031 series and other existing standards

Key Dates

CRA compliance timeline

Consulting
  1. 2024-12-10

    Entry into Force

    Regulation (EU) 2024/2847 enters into force and the transition period begins.

  2. 2026-09-11 In effect

    Reporting Obligations Apply

    Actively exploited vulnerabilities and severe incidents must be reported on a 24-hour early warning, 72-hour notification and final report timeline.

  3. 2027-12-11

    Full Application

    All essential requirements and conformity assessment apply; non-compliant products cannot carry the CE marking into the EU market.

Scope of Work

What the Engagement Covers

01

Scope & Product Classification

Determine whether your product is a product with digital elements under the CRA, and whether it falls into the default, important (Class I / II) or critical category — which decides the conformity assessment procedure.

02

Essential Requirements Gap Analysis

Map your design, default configuration, update mechanism and support period against the product security and vulnerability handling requirements in Annex I, then prioritize remediation.

03

SBOM & Vulnerability Handling

Set up software bill of materials (SBOM) generation and maintenance, a coordinated vulnerability disclosure policy and a security update process that covers the full support period.

04

Reporting Obligations

Since 11 September 2026, actively exploited vulnerabilities and severe incidents must be reported on a 24-hour early warning, 72-hour notification and final report timeline. We help you build the internal triage and reporting process.

05

Conformity Assessment & Technical File

Plan the self-assessment or third-party route for your product category, and prepare the risk assessment, technical documentation and EU Declaration of Conformity needed for CE marking.

06

Alignment with IEC 62443

If you already run or plan an IEC 62443 program, we map the two sets of requirements so processes and evidence are shared rather than duplicated.

Engagement

Engagement Details

For Hardware and software manufacturers, importers, distributors selling into the EU
Deliverables Classification, gap report, process documents, technical file package
Related Standards Mapped against IEC 62443, the EN 18031 series and other existing standards
Regulation Regulation (EU) 2024/2847 (Cyber Resilience Act)
Reporting Applies from 11 September 2026
Full Application 11 December 2027

Use Cases

Use Cases

ICS and IoT vendors selling into the EU that need CE marking by the end of 2027
Manufacturers that must stand up vulnerability and incident reporting for the obligations applying since September 2026
R&D and compliance teams unsure which CRA category applies and which assessment route to take
Supply-chain vendors asked by European customers for SBOMs and security support commitments

Want to learn more aboutEU CRA Consulting?

Our consultants will scope the engagement with you and map out the compliance path that fits your products and schedule.