Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

CRA Compliance, End-to-End

The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for products with digital components. mgm security partners provides end-to-end support—from governance and secure development to incident reporting and audit-ready documentation.

Reporting requirements take effect on September 11, 2026, and the full requirements take effect on December 11, 2027.

Our Services

Offer

Five coordinated service modules covering the entire CRA lifecycle.

  • Classify the product portfolio by standard, important, and critical classes
  • Compare the current status with Annexes I and II; quantify gaps
  • Determine the conformity assessment path (self-assessment vs. testing laboratory)
  • Prioritized Roadmap with Milestones Aligned with CRA Deadlines
  • Define Roles, Responsibilities, and Reporting Lines for CRA Matters
  • Expand the existing ISO 27001 ISMS to include CRA controls rather than building a new one from scratch
  • Supplier & Third-Party Vendor Evaluation, Including Contract Clauses
  • Management Reporting and Internal Awareness Initiatives

The availability of the source code enables:

  • More targeted review of suspected vulnerabilities
  • Detection of potential gaps that cannot be reliably detected with a penetration test or only with great effort
  • Overall, a greater coverage

Comprehensive Static Code Analysis (SAST) goes even further than a Greybox Penetration Test. We offer code analysis as a supplement to penetration testing or separately..

  • Establish PSIRT/CSIRT processes, including escalation procedures and responsibilities
  • Reporting Process to the ENISA Portal: 24-Hour Advance Notice, 72-Hour Report, Final Report
  • Establish a Coordinated Vulnerability Disclosure Process for External Reporters
  • Integration with existing SOC and incident response structures
  • Penetration tests and security analyses in accordance with Annex I requirements
  • Preparing Technical Documentation and Declarations of Conformity to Meet Audit Standards
  • Support with conformity assessment, including, if necessary, a notified body
  • CE Marking and Submission to the Market Surveillance Process

The challenge

  • Mandatory CRA Deadlines: Reporting Requirement Effective September 2026, Compliance by December 2027
  • Unclear Product Scope, Risk Classification, and Conformity Assessment
  • No process for reporting vulnerabilities and incidents within 24 hours
  • Security Is Not Embedded in Design, Development, and the Supply Chain
  • Missing SBOMs, documentation, and audit-ready evidence

Our Added Value

  • End-to-End: Governance, Development, Incident Reporting, and Documentation
  • Measures to fulfill CRA obligations integrated into your existing ISMS
  • Establishment of compliant reporting processes
  • Practical implementation by experts who understand the technology, not just the rules
  • Audit-ready evidence and compliance documentation

Your Path to CRA Compliance

  • Governance
    Scoping, gap analysis, and integration of CRA obligations into your existing ISMS—the foundation for all subsequent steps.

  • 's secure development approach—Security by Design, hardened SSDLC, and comprehensive SBOMs—ensures that new releases are compliant from the start.
  • Reporting & Incident Management
    Starting September 11, 2026, every hour counts: PSIRT processes and reporting channels for the 24-hour and 72-hour deadlines will be in place in a timely manner.
  • Assessment & Documentation
    Tests, technical documentation, and conformity assessment lead to the CE marking through December 11, 2027.

CRA Consulting: Quick Answers to Your Questions

The regulation has been in effect since December 10, 2024. Starting September 11, 2026, actively exploited vulnerabilities and serious security incidents must be reported; as of December 11, 2027, all requirements will be fully in effect—new products with digital elements may then only be placed on the market in the EU if they bear a CRA-compliant CE marking.

The CRA generally applies to all manufacturers, importers, and distributors of products with digital elements that are placed on the market in the EU—regardless of where their company is headquartered. In our CRA scoping analysis, we determine which products are affected, which risk class they fall into, and which exemptions might apply (e.g., for purely open-source projects without commercial exploitation).

The CRA provides for a three-tiered system of fines: up to €15 million or 2.5% of global annual revenue for violations of core safety requirements; up to €10 million or 2% for other obligations; and up to €5 million or 1% for providing false or incomplete information to authorities—in addition to the risk of being barred from selling products in the EU.

No. An existing ISO 27001 or comparable ISMS provides a solid foundation. We supplement it with CRA-specific controls—such as product risk classification, SBOM maintenance, and reporting processes—rather than establishing parallel structures.

That depends on the product portfolio and the initial situation. Scoping and gap analysis typically provide a reliable roadmap within a few weeks; full implementation through to conformity assessment can take several months.

Why mgm security partners?

  • 25+ years of experience
  • Lean – We Simplify Your IT Security Journey
  • 100% – Led by Senior Security Experts
  • C-Level – Advisory Experience

We’re familiar with both the regulatory aspects and the technical implementation—drawing on over 25 years of experience working on projects for banks, insurance companies, industrial firms, and software vendors. Instead of duplicating processes on paper, we integrate CRA requirements right where your teams are already working: within your existing ISMS, in the development pipeline, and in your incident response setup.

Maximiliane Mayer

Let's talk about your IT security challenges! Arrange your appointment!

DeepDive

What is the Cyber Resilience Act?

The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU-wide regulation to establish mandatory cybersecurity requirements for “products with digital elements”—that is, virtually any hardware or software with a direct or indirect connection to a device or network.

Essentially, the CRA requires three things:

  • Security “by design and by default” throughout the entire product lifecycle
  • A structured approach to addressing vulnerabilities, including a Software Bill of Materials (SBOM)
  • and mandatory reporting of actively exploited vulnerabilities and serious security incidents to ENISA and the relevant authorities.

The requirements are phased in—those who start now will avoid feeling rushed right before the deadlines.

December 10, 2024 – Entry into force of Regulation (EU) 2024/2847
September 11, 2026 – Reporting Requirements for Vulnerabilities and Incidents Take Effect
December 11, 2027 – Full Implementation – CE Marking Only with CRA Conformity
 
Fine for violating the core requirements: 2.5% of global annual revenue, up to €15 million

Who is affected? Three risk categories

The CRA tiers its requirements based on the cybersecurity risk posed by a product. The classification determines whether a self-assessment is sufficient or whether an independent audit firm must be involved.

Standard
 

  • About 90% of all affected products.
  • Conformity is demonstrated through the manufacturer's self-assessment.
  • Examples: traditional business software, consumer electronics, simple IoT devices


's Key Products (Annex III)

  • Class I requires harmonized standards or a testing laboratory
  • Class II requires an independent conformity assessment.
  • Examples: Identity and access management, password managers, operating systems, smart home security technology, hypervisors, container runtimes

Critical Products
(Annex IV)

  • Highest risk level – mandatory certification by a notified body under a European scheme.
  • Examples: Smart cards and similar security-critical hardware components