Manufacturer obligations

CRA compliance for manufacturers

Manufacturers bear the heaviest responsibilities under the Cyber Resilience Act. We guide you step by step towards full compliance.

Why is compliance so complex for manufacturers?

The CRA places the most extensive obligations on manufacturers of products with digital elements. From security-by-design and risk assessment to technical documentation, CE marking and long-term vulnerability management: the process requires legal knowledge, technical expertise and a structured approach. CRA-Portal helps you make this manageable.

Manufacturing

Your obligations as a manufacturer

01

Security-by-design

Cybersecurity must be built into your product from the design stage, not added as an afterthought.

02

Risk assessment

You must carry out a documented cybersecurity risk assessment for every product with digital elements.

03

Technical documentation

Comprehensive technical documentation must be prepared and maintained throughout the product's lifetime.

04

SBOM (Software Bill of Materials)

A complete overview of all software components (including open source) must be maintained and available on request.

05

Vulnerability management

You are responsible for actively identifying and remediating vulnerabilities for at least 5 years after market access.

06

Incident reporting

Actively exploited vulnerabilities and security incidents must be reported to ENISA within 24 hours.

07

CE marking

Your product must carry a valid CE marking based on a correct conformity assessment.

08

EU declaration of conformity

You must draw up a Declaration of Conformity (DoC) and make it available to market surveillance authorities.

09

Security updates

Security updates must be made available free of charge throughout the entire support period.

How we help manufacturers

Ready to tackle your CRA compliance?

Schedule a no-obligation introductory meeting and find out how we can guide your organisation towards full compliance.

CRA Assistent