Manufacturers bear the heaviest responsibilities under the Cyber Resilience Act. We guide you step by step towards full compliance.
The CRA places the most extensive obligations on manufacturers of products with digital elements. From security-by-design and risk assessment to technical documentation, CE marking and long-term vulnerability management: the process requires legal knowledge, technical expertise and a structured approach. CRA-Portal helps you make this manageable.
Cybersecurity must be built into your product from the design stage, not added as an afterthought.
You must carry out a documented cybersecurity risk assessment for every product with digital elements.
Comprehensive technical documentation must be prepared and maintained throughout the product's lifetime.
A complete overview of all software components (including open source) must be maintained and available on request.
You are responsible for actively identifying and remediating vulnerabilities for at least 5 years after market access.
Actively exploited vulnerabilities and security incidents must be reported to ENISA within 24 hours.
Your product must carry a valid CE marking based on a correct conformity assessment.
You must draw up a Declaration of Conformity (DoC) and make it available to market surveillance authorities.
Security updates must be made available free of charge throughout the entire support period.
Schedule a no-obligation introductory meeting and find out how we can guide your organisation towards full compliance.