The EU Cyber Resilience Act (Regulation (EU) 2024/2847) makes cybersecurity a condition of market access for products with digital elements. Manufacturers must design and build these products to be secure by default, maintain them with security updates throughout their expected lifetime, and support them with a 24-hour vulnerability and incident reporting process. SQA Consultant helps manufacturers work out which requirements apply to their product, build the evidence needed to prove conformity, and prepare for the applicable conformity assessment route.
Key Compliance Deadlines
- 11 June 2026 – Conformity assessment bodies begin notifying under CRA rules.
- 11 September 2026 – Mandatory 24-hour vulnerability and severe incident reporting to ENISA begins, including for products already on the market.
- 30 October 2026 – The majority of harmonised standards are expected to be published.
- 11 December 2027 – Full CRA compliance applies, covering technical documentation, conformity assessment and CE marking.
Conformity Assessment Routes
Every product with digital elements must meet the same essential cybersecurity requirements set out in Annex I. A product's classification does not change what it must achieve – only how conformity must be demonstrated.
- Default and Annex III Class I products – Self-Assessment (Annex VIII, Module A): Default products can use self-assessment regardless of the technical specification applied. Annex III Class I products keep the self-assessment route only where harmonised standards, common specifications, or a European cybersecurity certification scheme cover all applicable essential requirements and are applied in full. The manufacturer prepares the Annex VII technical documentation, issues the EU declaration of conformity, and affixes the CE marking on its own responsibility. Most harmonised standards are still pending publication, so we confirm whether this route is actually open for a given product before relying on it.
- Class II products – Third-Party Conformity Assessment (Annex VIII, Module B+C or Module H): Class II products always require assessment by an accredited notified body, even where harmonised standards are applied. Under Module B+C, the notified body examines the technical documentation and product type before the manufacturer declares conformity to the assessed type. Under Module H, the notified body audits the manufacturer's full development and vulnerability-handling processes. Where a notified body is involved, its identification number accompanies the CE marking, so assessment lead time should be built into the release roadmap.
Our CRA Compliance Services
- CRA Classification & Gap Assessment – determine whether each product is default, Annex III Class I, or Class II, and produce a prioritized gap analysis against the Annex I essential requirements.
- Module A Self-Assessment Support – build the Annex VII technical file, risk analysis and EU declaration of conformity for default and eligible Class I products.
- Class II Notified Body Readiness – prepare documentation, processes and evidence for Module B+C or Module H assessment, and support the manufacturer through notified body review.
- SBOM & Vulnerability Management – machine-readable software bill of materials generation and continuous vulnerability tracking across components and open-source dependencies.
- Vulnerability & Incident Reporting – a PSIRT workflow that detects, classifies and reports actively exploited vulnerabilities within the 24-hour, 72-hour and 14-day windows required by Article 14.
- Secure-by-Design Security Testing – penetration testing, static and dynamic analysis and secure development review, evidencing Annex I, Part I requirements.
CRA Obligations Mapped to Our Services
| CRA Obligation | What It Requires | SQA Consultant Service |
|---|---|---|
| SBOM, Annex I, Part II | Machine-readable SBOM covering at least top-level dependencies | SBOM & vulnerability assessment |
| Vulnerability reporting, Article 14 | Report actively exploited vulnerabilities to ENISA within 24 hours | PSIRT reporting workflow |
| Essential requirements, Annex I, Part I | Secure-by-design and secure development practices | Security & penetration testing |
| Conformity, Article 32 and Annex VIII | Module A self-assessment, or Module B+C and Module H via notified body | Conformity & agency approval |
| Technical documentation, Annex VII | Product description, risk analysis and mitigation evidence | Requirements engineering |
How We Engage
- Classify – scope the product portfolio, determine each product's category, and map gaps against Annex I.
- Build – stand up SBOM, vulnerability management and reporting workflows.
- Test – validate secure-by-design controls through independent testing.
- Declare – complete Module A self-assessment, or prepare for notified body review.
Since 11 September 2026, the CRA requires manufacturers to report actively exploited vulnerabilities to ENISA within 24 hours – even for products already on the market. A manufacturer cannot report on components it has not identified, so if an SBOM or incident response process is untested, exposure begins now, not in 2027. We inventory components, build a 24-hour reporting workflow, and then prepare full CRA compliance ahead of December 2027.