European compliance
Cyber Resilience Act: what to do if your product includes software or connectivity
If your product includes software or connects to something, the CRA affects you sooner than you think. We help you assess applicability and prepare compliance without last-minute redesigns.
- Applicable regulation
- EU CRA
- Product security
- By design
- Support & vulnerabilities
- Lifecycle
Definition
The Cyber Resilience Act (CRA) is the EU regulation on cybersecurity for products with software or connectivity. It covers the full lifecycle: secure design, vulnerability management, support and documentation for placing products on the European market.
Updated · Reglamento (UE) CRA · IEC 62443 · ENISA
What we solve
We help you see whether the CRA applies. What it requires (secure design, vulnerabilities, support). How to prepare evidence and processes.
View service: OT Cybersecurity →Who it is for
- Manufacturers of products with software or connectivity
- Suppliers of smart industrial components
- Product, quality and compliance teams
- Companies that import or place products on the EU market
What is included
- CRA applicability analysis for your product
- Cybersecurity requirements gap analysis
- Definition of vulnerability and support processes
- Security by design / by default recommendations
- Evidence and documentation preparation
Deliverables
- ▸CRA applicability report
- ▸Obligations and risks checklist
- ▸Compliance plan by product or family
- ▸Vulnerability governance recommendations
How we work
A clear process while you submit your enquiry via the form.
STEP 01
Scope
We confirm whether your product or component falls under the CRA and to what extent.
STEP 02
Gap analysis
We compare CRA requirements with your current design, processes and documentation.
STEP 03
Compliance plan
We prioritise technical, product and after-sales support actions.
STEP 04
Evidence
We define what to document and how to demonstrate conformity sustainably.
Frequently asked questions
Does the CRA apply to industrial machinery?
It may apply when the product incorporates relevant digital elements. We assess case by case the boundary between machinery, component and digital product.
How does it relate to NIS2 or 62443?
NIS2 focuses more on entities and governance; 62443 on OT environments; the CRA on products with digital elements. They often overlap and should be aligned.
Is there still time to prepare?
Yes, but product cycles are long. Acting now avoids costly redesigns and market access blocks later.
You may also be interested in
Machine safety
RD 1215 Compliance
We assess your machinery against RD 1215/1997, prioritise the measures and close the technical file—so you face the next inspection without last-minute improvisation.
European conformity
Machinery Regulation
If you manufacture or modify machinery for the EU, Regulation 2023/1230 changes your obligations. We help you see what applies to your case and prepare the technical file in time.
OT cybersecurity
ISA / IEC 62443
Your OT plant is more exposed than you think. With IEC/ISA 62443 we turn that exposure into a clear phased plan, prioritised by risk—without stopping production.