Cyber Resilience Act (CRA) Compliance Services

We help hardware and software manufacturers work out what the Cyber Resilience Act requires of their products and put it in place: scope and classification, risk assessment, vulnerability handling, Article 14 reporting, SBOM, technical documentation and preparation for the applicable conformity assessment route.

What the CRA asks of you

Regulation (EU) 2024/2847, the Cyber Resilience Act, sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on 10 December 2024 and applies in full from 11 December 2027. The reporting obligations in Article 14 apply earlier, from 11 September 2026.

We help manufacturers determine product scope and classification, select the applicable conformity assessment route, and prepare the required controls and documentation. We work with your engineering, product and compliance teams to assign responsibilities and implement the changes.

If you want the regulation itself, we publish it in full: read the Cyber Resilience Act full text and practitioner notes, article by article, with our notes on the provisions that are hardest to apply.

Scope and applicability

The CRA applies to products with digital elements (hardware and software) whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. We assess applicability before planning the compliance work.

Points that decide most scope questions in practice:

  • Components count. A software or hardware component placed on the market separately is a product in its own right.
  • Remote data processing. Article 3(2) defines this narrowly: data processing at a distance, where the software is designed and developed by the manufacturer or under its responsibility, and without which the product could not perform one of its functions. Where that test is met, the remote component is part of the product. Cloud and SaaS offerings are not in scope simply for being cloud services.
  • Exclusions. Products covered by certain sector-specific EU rules, including medical devices, motor vehicle type-approval, civil aviation and marine equipment, sit outside the CRA.
  • Free and open-source software is treated differently depending on whether it is supplied in the course of a commercial activity, and open-source stewards carry a distinct and lighter set of obligations.

Product classification

Classification determines your conformity assessment route, so it is usually the first thing we settle. The CRA sorts products by the core functionality of the categories it lists:

  • The default category: products with digital elements that do not fall within Annex III or Annex IV. Manufacturers may use the internal control procedure (Module A). Other conformity assessment routes remain available.
  • Important products with digital elements (Annex III), Class I: for example identity and privileged access management, browsers, password managers, and malware detection and removal software.
  • Important products with digital elements (Annex III), Class II: a smaller set at higher risk, where the available conformity assessment routes are narrower.
  • Critical products with digital elements (Annex IV): including hardware devices with security boxes, smart meter gateways, and devices for secure cryptoprocessing.

A product that performs functions beyond its core functionality still belongs to its category, and integrating a component that has the functionality of another category does not by itself move the product into that category. The technical descriptions of the categories are set out in a Commission implementing regulation, which support the classification assessment.

Conformity assessment and CE marking

CE marking indicates that the manufacturer declares the product conforms with the applicable EU requirements, having completed the conformity assessment procedure required for it. Depending on the product and the applicable route, that procedure may involve a notified body.

Conformity assessment support. Meroi Security prepares you for conformity assessment: we help you choose and justify the route, build the technical documentation and address compliance gaps. Meroi Security is not a notified body and does not perform the formal third-party conformity assessment. Where third-party assessment is required, we help prepare the product, documentation and evidence and support engagement with the appropriate notified body.

Harmonized standards

Applying a harmonized standard gives a presumption of conformity with the CRA requirements that standard covers, once its reference has been published in the Official Journal of the European Union for that purpose. The presumption reaches only the requirements the standard actually covers; anything outside it still has to be addressed by other means, and the manufacturer remains responsible for assessing all the risks of its product.

Standards such as IEC 62443 and ETSI EN 303 645 are often useful technical references and may already be part of how you build. They should not be treated as CRA harmonized standards, and applying them does not create a presumption of conformity, unless the relevant reference has been published for that purpose.

What non-compliance carries

Article 64 sets the maximum administrative fines. Member States establish the applicable penalty rules:

  • Failing the essential cybersecurity requirements in Annex I, or the manufacturer obligations in Articles 13 and 14: up to EUR 15 million or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher.
  • Failing most other obligations, including those on importers, distributors and notified bodies: up to EUR 10 million or 2%.
  • Supplying incorrect, incomplete or misleading information to a notified body or a market surveillance authority in reply to a request: up to EUR 5 million or 1%.

Market surveillance authorities can also require a product to be brought into conformity, withdrawn or recalled.

Our workstreams

Readiness and gap assessment

We assess your products, development processes and existing documentation against the applicable CRA requirements. You receive a prioritized list of gaps, with responsibilities and effort estimates.

You receive: a scope and classification determination per product, a gap register, and a sequenced remediation plan.

Cybersecurity risk assessment and Annex I

Annex I Part I applies according to your risk assessment: the manufacturer determines which product-property requirements are relevant, and Article 13(4) requires a clear justification wherever a requirement is treated as not applicable. Part II, the vulnerability handling requirements, applies throughout the support period regardless. The CRA does not mandate a particular risk assessment methodology, so we work with yours where you have one.

You receive: a documented risk assessment with the rationale for each conclusion, mapped to Annex I.

Vulnerability handling

The Part II obligations run for the whole support period: identifying and documenting vulnerabilities and components, remediating without delay, regular testing, disclosing fixed vulnerabilities, and operating a coordinated vulnerability disclosure policy. Where a reference standard helps, ISO/IEC 29147 covers vulnerability disclosure and ISO/IEC 30111 covers vulnerability handling.

You receive: a CVD policy, a documented vulnerability handling process, and a security advisory format.

Article 14 reporting

From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident affecting the product's security, notifies the CSIRT designated as coordinator and ENISA simultaneously, through the single reporting platform established under Article 16. The sequence is:

  • Early warning: without undue delay and in any event within 24 hours of becoming aware.
  • Notification: without undue delay and in any event within 72 hours.
  • Final report: the deadline differs by case. For an actively exploited vulnerability, no later than 14 days after a corrective or mitigating measure is available. For a severe incident, within one month of the 72-hour notification.

We help define reporting responsibilities, approval steps and the information needed for each notification.

You receive: a reporting runbook, named roles, support with registration and setup on the single reporting platform, and a dry run.

SBOM and software supply chain

Annex I Part II requires a software bill of materials covering at the very least the top-level dependencies, in a commonly used machine-readable format. We help select the format, define dependency coverage, integrate generation into your build and establish how the SBOM is used during vulnerability handling. These implementation choices support the requirement; the CRA does not prescribe the individual data fields.

You receive: SBOM generation integrated into your pipeline, a documented format decision, and a third-party component due diligence process.

Technical documentation

The technical documentation demonstrates that the product was designed, developed and produced to meet the essential requirements, and it has an external audience: market surveillance authorities can request it, and Article 13(13) requires it to be kept for ten years after the product is placed on the market or for the support period, whichever is longer.

You receive: technical documentation structured to Annex VII and support preparing the EU declaration of conformity.

Implementation support and training

We provide training for engineering, product and legal teams on their CRA responsibilities. Implementation support can include reporting exercises and assistance with preparing notifications.

Why work with us

  • Technical implementation. We help your engineers put security controls and compliance processes into operation.
  • Agreed responsibilities. Each engagement defines the work, deliverables and responsibilities of both teams.
  • We publish our reading of the regulation. Our article-by-article CRA reader shows how we interpret the text, with every practitioner note tied to the Commission or ENISA source it comes from.
  • Conformity assessment preparation. We help you prepare for the applicable route and coordinate with a notified body where required.

Talk to us

If you are working out whether the CRA applies to your product, which category it falls into, or what has to be in place by 11 December 2027, contact us to discuss your requirements and next steps. Initial assessments are free.

Email [email protected] or use the contact form.

Free initial assessment

Assess your CRA compliance today

Get Started