Your situation

CRA consulting for your products and development processes

You develop or distribute products with digital elements and want to implement the requirements of the Cyber Resilience Act. Together with your product teams, we clarify which requirements are relevant, where your existing processes stand and which measures and evidence are missing.

For small and medium-sized enterprises: the CRA starter package with kick-off, training, CRA toolbox, implementation phase and readiness check.

Free of charge and without obligation.

  • CRA article published in iX
  • Co-author of the IEC 62443-4-2 evaluation scheme
  • TR-03185 procedure at DUX Healthcare
A man holding a large black hourglass in front of the sand table
Cyber Resilience Act: the deadlines are running, the course has to be set now.

Your situation

You develop or distribute products with digital elements and need to implement the Cyber Resilience Act?

The Cyber Resilience Act (CRA) sets binding minimum standards for the cybersecurity of products with digital elements for the first time – from smart home thermostats and network components to machines and industrial plants. Since 11 September 2026, the reporting obligations for actively exploited vulnerabilities and severe incidents have applied. From 11 December 2027, manufacturers must demonstrate that their products are developed securely, updated regularly and protected against vulnerabilities. Infringements can lead to fines of up to EUR 15 million or 2.5 per cent of worldwide annual turnover; responsibility lies with the management.

Product teams then face concrete questions: Which CRA product category does our product fall into? Which essential requirements do we already meet? How do we set up vulnerability handling and a PSIRT? Which security tests and evidence do we need for conformity assessment and CE marking – and do stricter procedures apply to important or critical products?

This is where we come in: with security know-how from product development and the experience of a product evaluation facility that has been testing since 1992. Since 19 February 2025 it has been accredited by DAkkS (German national accreditation body) to DIN EN ISO/IEC 17025:2018 for product testing in the EUCC scheme (D-PL-21736-01-00). For OT products, we clarify which requirements your work under IEC 62443 already covers. Small and medium-sized enterprises get a compact start with our CRA starter package. According to the BSI, the IT Security Label of the BSI already allows manufacturers of connected consumer devices to prepare for the technical CRA requirements. We classify which further evaluations and evidence your product needs in our consulting for product manufacturers.

Services & results

From the CRA workshop to the readiness check

You know which CRA product categories your products fall into and what is still missing for conformity: from the workshop and gap analysis to risk assessment, vulnerability handling with a PSIRT and security tests by a testing laboratory accredited by DAkkS to ISO/IEC 17025. For small and medium-sized enterprises, the CRA starter package bundles these steps up to the readiness check.

Workshop, gap analysis and implementation consulting answer different questions: Which requirements apply, where are the gaps, which processes are missing? For small and medium-sized enterprises, the CRA starter package bundles these steps into a clearly structured start – from kick-off and training to the CRA toolbox and the readiness check.

Kick-off and CRA workshop

In the kick-off we get to know your products and goals. In the CRA workshop your product teams get an overview of the CRA obligations and learn how to integrate the requirements into their daily work. We answer company-specific questions and special cases directly.

Classification of your products

Your products are assigned to the appropriate CRA product categories. You know which requirements are relevant – and which are not.

CRA gap analysis

We compare the status of your products and development processes with the legal requirements and show which measures and evidence are still missing. For a larger portfolio, we first prioritise the products by criticality.

For OT products, we check which requirements are already met through IEC 62443 and where action is still needed.

Your CRA action items

A gap analysis showing the identified need for implementation and evidence.

CRA implementation with toolbox and consulting

You receive our CRA toolbox with templates and aids for risk assessment, documentation and evidence. In the implementation phase you work independently or with our support. We provide targeted support in setting up the core processes:

  • Risk assessment
  • Vulnerability handling and PSIRT (Product Security Incident Response Team)
  • Building internal security testing capabilities
  • Documentation for conformity assessment and CE marking

Your CRA toolbox

Templates and aids that let your team continue working independently after the project ends.

Security tests according to CRA requirements

The CRA requires manufacturers to systematically test all security requirements, analyse the attack surface and maintain and update a software bill of materials (SBOM). As a testing laboratory accredited by DAkkS to ISO/IEC 17025, we carry out security tests and product pentests – as part of your CRA compliance or as stand-alone security evidence.

Readiness check

Finally, we review your implementation status. This lets you identify open points early and avoid rework shortly before the 2027 deadline.

Our expertise

We advise on the CRA from the perspective of a product evaluation facility. The secuvera evaluation facility was recognised by the BSI in 1992 and works according to ISO/IEC 17025. How products are evaluated thus feeds directly into the gap analysis and implementation consulting.

We contribute to standardisation: we drove the TeleTrusT evaluation scheme for IEC 62443-4-2 forward as coordinator and play a leading role in the standard part IEC 62443-6-2 (evaluation methodology). The head of our evaluation facility, Sebastian Fritsch, chairs the working groups DIN NA 043-01-27-03 “Evaluation criteria for IT security” and DKE AK 931.1.4 “Evaluation Methods”. We supported Red Lion Europe up to certification according to IEC 62443-4-1.

We publish our assessment of the CRA: in April 2026 in iX with the article “Cyber Resilience Act: Markteingriff für mehr Sicherheit?” and the interview “CRA: Jetzt mit der Umsetzung starten” with managing director Tobias Glemser, and in 2025 with the iX article “Der Cyber Resilience Act und der Stand der Technik” by Sophia Pötsch and Sebastian Fritsch (all in German).

Getting started

Working with your product portfolio and development status

Looking at product status and development processes together

Describe your product, the intended operating conditions and the status of your security documentation. Existing threat analyses, evidence from IEC 62443 projects and processes for handling vulnerabilities show what a CRA gap analysis can build on. From this, we define the scope of products and processes to be examined.

Discuss your CRA implementation
Hands writing notes next to a compass and navigation instruments on a map
Product portfolio systematically checked against CRA obligations.

The CRA starter package for small and medium-sized enterprises

A simplified start to CRA implementation for small and medium-sized enterprises. Sessions usually take place by video conference. With the CRA toolbox, your team continues working independently after the project ends.

  1. Kick-off

    About one hour with a team of two: we plan the process and dates, get to know your products and clarify special cases. We then evaluate your documents regarding the relevance of the CRA.

  2. Training and product classification

    The CRA obligations in practice: product categories, technical requirements and documentation. You then present your products, and together we assign them to a CRA product category. We also clarify which module can be used for the conformity assessment.

  3. CRA toolbox

    Handover of the templates and aids, each explained with examples in short workshops. Your team can then start implementation.

  4. Risk assessment workshop

    The risk assessment is the central element of the CRA. We start it together in a dedicated workshop; you then continue it independently.

  5. Implementation phase

    Within an agreed period, you implement the requirements independently. On request, we discuss open questions in regular check-ups; this support is optional and charged according to effort.

  6. CRA readiness check

    You present your results. We review them for completeness and plausibility with regard to the relevant CRA requirements and hand over the identified gaps in documented form. The check is part of the package.

Distinguishing consulting from conformity assessment

The scope of the engagement is defined for your products and their development status. Consulting and gap analysis do not replace the required conformity assessment procedure. An existing IEC 62443 certification is not a blanket proof of CRA conformity.

Questions about CRA implementation in the product team

What does a CRA gap analysis at secuvera look at?

It compares the status of your products and development processes with the relevant requirements. Existing security functions and evidence are taken into account. The result shows the measures and evidence still missing, which your product team can continue working on.

Can we use our IEC 62443 work for the CRA?

For OT products, we check which requirements are already covered by your IEC 62443 work. Remaining gaps are addressed separately. An IEC 62443 certification is not a blanket proof of full CRA conformity.

Is the CRA workshop already an assessment of our product?

The workshop conveys the requirements and addresses your product teams' questions. A systematic assessment of existing measures and evidence takes place in a separately commissioned gap analysis. The two steps have different results.

Do we receive a confirmation of conformity through CRA consulting?

Consulting supports your implementation and your evidence. It does not replace the conformity assessment procedure required for the product. Evaluations and further procedural steps are determined based on the product and its evidence requirements.

Which products fall under the CRA?

The CRA applies to products with digital elements – in the consumer sector, for example, smart home thermostats or smartwatches, in the B2B sector network components, machines or entire industrial plants. Important products such as operating systems, firewalls or password managers are subject to stricter assessment procedures with external involvement, and critical products to certification.

Articles on this topic (in German)

All 34 articles on the topic (in German)

Older articles reflect the legal situation at the time of publication. The sections above summarise the current situation.

How can we support you with the CRA?