CRA Compliance, End-to-End

The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for products with digital components. mgm security partners provides end-to-end support—from governance and secure development to incident reporting and audit-ready documentation.
Reporting requirements take effect on September 11, 2026, and the full requirements take effect on December 11, 2027.
Our Services
Five coordinated service modules covering the entire CRA lifecycle.
1 - CRA Scoping & Gap Analysis
Classify products, assign CRA obligations, and create a prioritized roadmap with deadlines.
- Classify the product portfolio by standard, important, and critical classes
- Compare the current status with Annexes I and II; quantify gaps
- Determine the conformity assessment path (self-assessment vs. testing laboratory)
- Prioritized Roadmap with Milestones Aligned with CRA Deadlines
2 - Governance & ISMS Integration
Integrate CRA obligations into ISMS, risk management, and supplier processes.
- Define Roles, Responsibilities, and Reporting Lines for CRA Matters
- Expand the existing ISO 27001 ISMS to include CRA controls rather than building a new one from scratch
- Supplier & Third-Party Vendor Evaluation, Including Contract Clauses
- Management Reporting and Internal Awareness Initiatives
3 - Secure Development & SBOM
Embed security throughout the SSDLC—with CRA-compliant SBOMs via mgm ATLAS and secure defaults.
The availability of the source code enables:
- More targeted review of suspected vulnerabilities
- Detection of potential gaps that cannot be reliably detected with a penetration test or only with great effort
- Overall, a greater coverage
Comprehensive Static Code Analysis (SAST) goes even further than a Greybox Penetration Test. We offer code analysis as a supplement to penetration testing or separately..
4 - Incident and Vulnerability Reporting
: Establish a PSIRT/CSIRT—with coordinated disclosure, patching, and updates throughout the lifecycle.
- Establish PSIRT/CSIRT processes, including escalation procedures and responsibilities
- Reporting Process to the ENISA Portal: 24-Hour Advance Notice, 72-Hour Report, Final Report
- Establish a Coordinated Vulnerability Disclosure Process for External Reporters
- Integration with existing SOC and incident response structures
5 - Assessment, Testing & Certification
Penetration tests, technical documentation, and proof of compliance for CE marking.
- Penetration tests and security analyses in accordance with Annex I requirements
- Preparing Technical Documentation and Declarations of Conformity to Meet Audit Standards
- Support with conformity assessment, including, if necessary, a notified body
- CE Marking and Submission to the Market Surveillance Process
Your Path to CRA Compliance
- Governance
Scoping, gap analysis, and integration of CRA obligations into your existing ISMS—the foundation for all subsequent steps.
's secure development approach—Security by Design, hardened SSDLC, and comprehensive SBOMs—ensures that new releases are compliant from the start.- Reporting & Incident Management
Starting September 11, 2026, every hour counts: PSIRT processes and reporting channels for the 24-hour and 72-hour deadlines will be in place in a timely manner. - Assessment & Documentation
Tests, technical documentation, and conformity assessment lead to the CE marking through December 11, 2027.
CRA Consulting: Quick Answers to Your Questions
When does the Cyber Resilience Act take effect for us?
The regulation has been in effect since December 10, 2024. Starting September 11, 2026, actively exploited vulnerabilities and serious security incidents must be reported; as of December 11, 2027, all requirements will be fully in effect—new products with digital elements may then only be placed on the market in the EU if they bear a CRA-compliant CE marking.
Are we even affected?
The CRA generally applies to all manufacturers, importers, and distributors of products with digital elements that are placed on the market in the EU—regardless of where their company is headquartered. In our CRA scoping analysis, we determine which products are affected, which risk class they fall into, and which exemptions might apply (e.g., for purely open-source projects without commercial exploitation).
What happens if we miss the deadlines?
The CRA provides for a three-tiered system of fines: up to €15 million or 2.5% of global annual revenue for violations of core safety requirements; up to €10 million or 2% for other obligations; and up to €5 million or 1% for providing false or incomplete information to authorities—in addition to the risk of being barred from selling products in the EU.
Do we need to replace our existing ISMS?
No. An existing ISO 27001 or comparable ISMS provides a solid foundation. We supplement it with CRA-specific controls—such as product risk classification, SBOM maintenance, and reporting processes—rather than establishing parallel structures.
How long does a typical CRA implementation take?
That depends on the product portfolio and the initial situation. Scoping and gap analysis typically provide a reliable roadmap within a few weeks; full implementation through to conformity assessment can take several months.
Why mgm security partners?
- 25+ years of experience
- Lean – We Simplify Your IT Security Journey
- 100% – Led by Senior Security Experts
- C-Level – Advisory Experience
We’re familiar with both the regulatory aspects and the technical implementation—drawing on over 25 years of experience working on projects for banks, insurance companies, industrial firms, and software vendors. Instead of duplicating processes on paper, we integrate CRA requirements right where your teams are already working: within your existing ISMS, in the development pipeline, and in your incident response setup.
DeepDive
What is the Cyber Resilience Act?
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU-wide regulation to establish mandatory cybersecurity requirements for “products with digital elements”—that is, virtually any hardware or software with a direct or indirect connection to a device or network.
Essentially, the CRA requires three things:
- Security “by design and by default” throughout the entire product lifecycle
- A structured approach to addressing vulnerabilities, including a Software Bill of Materials (SBOM)
- and mandatory reporting of actively exploited vulnerabilities and serious security incidents to ENISA and the relevant authorities.
The requirements are phased in—those who start now will avoid feeling rushed right before the deadlines.
Who is affected? Three risk categories
The CRA tiers its requirements based on the cybersecurity risk posed by a product. The classification determines whether a self-assessment is sufficient or whether an independent audit firm must be involved.
Standard
- About 90% of all affected products.
- Conformity is demonstrated through the manufacturer's self-assessment.
- Examples: traditional business software, consumer electronics, simple IoT devices
's Key Products (Annex III)
- Class I requires harmonized standards or a testing laboratory
- Class II requires an independent conformity assessment.
- Examples: Identity and access management, password managers, operating systems, smart home security technology, hypervisors, container runtimes
Critical Products
(Annex IV)
- Highest risk level – mandatory certification by a notified body under a European scheme.
- Examples: Smart cards and similar security-critical hardware components
