CRA is not a project but an ongoing obligation. Our packages combine a one-time setup with an annual subscription for incident reporting, monitoring, and legislative updates until after December 11, 2027.
Discover in 10 minutes which CRA obligations apply to your products and when you need to take action.
Ideal as a first step to clarify the scope.
Setup package for one product category. Get your technical file and SBOM in order for market access.
Setup for up to 5 product categories and an ongoing subscription for incident reporting, vulnerability disclosure, and legislative updates.
For organizations with large portfolios, multiple locations, or NIS2 interfaces. Complete unburdening with a dedicated compliance contact person.
Per importer relationship. Verification of manufacturer compliance, technical documentation, and CE marking before forwarding to the EU market.
Per distributor relationship. Checklist and logbook for the due diligence that distributors must exercise under CRA upon receipt and forwarding.
Per product category. Detailed mapping of your product against the essential cybersecurity requirements from CRA Annex I — including gap report and remediation advice.
All prices are excluding VAT. Annual subscription starts from the first compliant market admission. Notice period 3 months before renewal date. Customization and multi-year agreements on request.
Schedule a non-binding 20-minute conversation with a CRA specialist. We will advise you honestly about the scope and choose the right starting point together.