YOUR
Search

    Cyber Resilience Act

    Six Modules. A Clear Path to CRA Compliance.

    CRA Ready

    The Cyber Resilience Act imposes new cybersecurity requirements on businesses in relation to products with digital elements – ranging from product classification and conformity assessment to contracts and supply chains, reporting obligations, vulnerability management and ongoing product support.

    With CRA Ready, we guide you through these requirements in a structured way. Our advisory approach is modular and covers the entire product life cycle: from the initial assessment of your products to ongoing compliance once they have been placed on the market.

    You select the modules that best suit your business and products. In consultation with you, we will draw up a proposal setting out a scope of services tailored to your needs and the steps required. To give you as much cost certainty as possible, we will offer fixed fees for each step, where appropriate.

    CRA Ready translates regulatory requirements into clearly defined work packages, tangible results and deliverables tailored to your needs and ready to use.

    Six Modules. A Clear Path to CRA Compliance.

    Modul 1: Scope & Classification

    Which products fall under the CRA – and what requirements apply?

    Objective: To reach a sound decision as to whether and to what extent your products fall under the CRA, including the product class and the resulting conformity assessment route.

    Scope of services

    • Analysis of your product portfolio to identify "products with digital elements"
    • Classification into the three categories: "standard" products / important products (Classes I and II, Annex III) / critical products (Annex IV)
    • Assessment of your products in the light of Implementing Regulation (EU) 2025/2392 regarding the technical description of product categories
    • Clarification of your role (manufacturer, importer, distributor) and the respective lists of obligations
    • Identification of exemptions and overlaps with sector-specific legislation, e.g. for medical devices

    Output

    • Written "in-scope" note
    • Product/class matrix showing the assigned conformity assessment route
    Modul 2: Market Launch & Compliance

    Which conformity assessment route applies, and what documentation is required?

    Objective: A legally compliant market launch – from selecting the correct conformity assessment procedure, through product testing, to the complete set of conformity documentation upon placing the product on the market. 

    Scope of services

    • Selection of the appropriate conformity assessment procedure: Module A (internal control procedure) / Modules B+C (EU type examination procedure) / Module H (full quality assurance), Annex VIII CRA
    • Legal review of the technical documentation, the EU Declaration of Conformity and labelling requirements
    • For important / critical products: preparation for the involvement of notified bodies

    Output

    • Recommendations on the conformity assessment route
    • Documentation checklist
    • Review notes on the technical documentation and declaration of conformity
    Modul 3: Contracts & Supply Chain

    How should contracts and supply chains be structured to comply with CRA requirements?

    Objective: To ensure the legally compliant implementation of CRA requirements throughout the supply chain and in relation to suppliers of components and other product parts.

    Scope of services

    • Analysis of existing supplier and subcontractor contracts for CRA compliance (particularly for integrated components and open-source elements)
    • Incorporation of security, update and vulnerability management obligations into procurement and framework agreements
    • Ensuring compliance with information, reporting and cooperation obligations throughout the supply chain (including upstream reporting to component manufacturers and the sharing of security fixes)
    • Amendment of liability, indemnity and support period clauses
    • Provisions governing the handling of components whose support period ends before that of the enterprise's own product
    • Development of a reusable library of CRA clauses for future contract negotiations

    Output

    • CRA clause kit (modular contract modules, including user guidance)
    • Redline review of your key supplier contracts, including a CRA-specific risk analysis
    • Support with contract negotiations, where required
    Modul 4: Reporting Requirements & Incident Response

    How can reporting obligations and incident management processes be organised in a legally compliant manner?

    Objective: To establish robust processes for the timely assessment and reporting of actively exploited vulnerabilities and serious security incidents in accordance with the CRA.

    Scope of services

    • Establishment of a reporting process in line with CRA deadlines: 24-hour early warning, 72-hour report and subsequent final report
    • Mapping of the various deadlines and requirements for actively exploited vulnerabilities and serious security incidents
    • Development of a roles, escalation and decision-making matrix
    • Creation of reporting templates and an incident response runbook for CRA reporting obligations
    • Clarification of the distinction between events subject to mandatory reporting and those that may be reported voluntarily (Art. 15 CRA), as well as upstream reporting obligations (Art. 13 (6) CRA)
    • Legal support in the event of a specific emergency: assessment of the reporting obligation, assistance with drafting the report and support with communication with the authorities

    Output

    • Reporting runbook
    • On-demand incident support
    Modul 5: Lifecycle Compliance

    How does a product remain CRA-compliant even after it has been launched?

    Objective: To provide legally compliant support not only at the time of market launch, but throughout a product's entire support lifecycle – including vulnerability management, updates and a structured end-of-support process.

    Scope of services

    • Ongoing legal support, for example in relation to the provision of security updates and vulnerability management
    • Legal assessment of changes to the product that could affect CRA compliance status, particularly in the case of potential significant changes
    • Advice on product discontinuation – an orderly end-of-support process with appropriate user communication and compliance with CRA requirements regarding the support period
    • Regular compliance briefings on changes to legislation, new guidance documents from the Commission or ENISA, and relevant standards
    • Support with regulatory enquiries during day-to-day operations, particularly in dealings with market surveillance authorities

    Output

    • Ongoing legal assessments and recommendations for action
    Modul 6: Importer & Distributor Compliance

    What are the specific obligations of importers and distributors?

    Objective: Tailored advice for economic operators who do not manufacture products themselves but are required to fulfil their own obligations under the CRA.

    Scope of services

    • Clarification of role allocation: When is a business considered as a distributor, when as an importer – and when does it become a manufacturer under the CRA (e.g. in the case of a substantial change, own-brand products or white-label solutions)?
    • Analysis of the specific obligations of importers (where applicable): testing and inspection obligations prior to placing on the market, documentation and record-keeping obligations, as well as information and cooperation obligations in the event of vulnerabilities, safety risks and non-conformity
    • Analysis of the specific obligations of distributors: verification of the CE marking and other required information and documentation, as well as obligations in the event of suspected non-conformity or safety risks
    • Contractual safeguards against manufacturers and suppliers Advice on recourse claims and the allocation of liability within the supply chain

    Output

    • Role assessment note
    • List of obligations for distributors and importers
    • Contract amendments
    • Liability analysis

    Downloads