The Cyber Resilience Act imposes new cybersecurity requirements on businesses in relation to products with digital elements – ranging from product classification and conformity assessment to contracts and supply chains, reporting obligations, vulnerability management and ongoing product support.
With CRA Ready, we guide you through these requirements in a structured way. Our advisory approach is modular and covers the entire product life cycle: from the initial assessment of your products to ongoing compliance once they have been placed on the market.
You select the modules that best suit your business and products. In consultation with you, we will draw up a proposal setting out a scope of services tailored to your needs and the steps required. To give you as much cost certainty as possible, we will offer fixed fees for each step, where appropriate.
CRA Ready translates regulatory requirements into clearly defined work packages, tangible results and deliverables tailored to your needs and ready to use.
Which products fall under the CRA – and what requirements apply?
Objective: To reach a sound decision as to whether and to what extent your products fall under the CRA, including the product class and the resulting conformity assessment route.
Scope of services
Output
Which conformity assessment route applies, and what documentation is required?
Objective: A legally compliant market launch – from selecting the correct conformity assessment procedure, through product testing, to the complete set of conformity documentation upon placing the product on the market.
Scope of services
Output
How should contracts and supply chains be structured to comply with CRA requirements?
Objective: To ensure the legally compliant implementation of CRA requirements throughout the supply chain and in relation to suppliers of components and other product parts.
Scope of services
Output
How can reporting obligations and incident management processes be organised in a legally compliant manner?
Objective: To establish robust processes for the timely assessment and reporting of actively exploited vulnerabilities and serious security incidents in accordance with the CRA.
Scope of services
Output
How does a product remain CRA-compliant even after it has been launched?
Objective: To provide legally compliant support not only at the time of market launch, but throughout a product's entire support lifecycle – including vulnerability management, updates and a structured end-of-support process.
Scope of services
Output
What are the specific obligations of importers and distributors?
Objective: Tailored advice for economic operators who do not manufacture products themselves but are required to fulfil their own obligations under the CRA.
Scope of services
Output