CRA Compliance, End-to-End

The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for products with digital components. mgm security partners provides end-to-end support—from governance and secure development to incident reporting and audit-ready documentation.
Reporting requirements take effect on September 11, 2026, and the full requirements take effect on December 11, 2027.
Our Services
Five coordinated service modules covering the entire CRA lifecycle.
1 - CRA Scoping & Gap Analysis
Classify products, assign CRA obligations, and create a prioritized roadmap with deadlines.
- Classify the product portfolio by standard, important, and critical classes
- Compare the current status with Annexes I and II; quantify gaps
- Determine the conformity assessment path (self-assessment vs. testing laboratory)
- Prioritized Roadmap with Milestones Aligned with CRA Deadlines
2 - Governance & ISMS Integration
Integrate CRA obligations into ISMS, risk management, and supplier processes.
Integrate CRA obligations into ISMS, risk management, and supplier processes.
- Define Roles, Responsibilities, and Reporting Lines for CRA Matters
- Expand the existing ISO 27001 ISMS to include CRA controls rather than building a new one from scratch
- Supplier & Third-Party Vendor Evaluation, Including Contract Clauses
- Management Reporting and Internal Awareness Initiatives
3 - Secure Development & SBOM
Embed security throughout the SSDLC—with CRA-compliant SBOMs via mgm ATLAS and secure defaults.
Ensure security through SSDLC—with CRA-compliant SBOMs via mgm ATLAS and secure defaults.
- Embed "Security by Design" and "Secure by Default" principles into the development process
- Automatically generate and maintain machine-readable SBOMs (CycloneDX/SPDX) with mgm ATLAS
- Continuously check dependencies and open-source components for vulnerabilities
- Establish secure update and patch mechanisms for the entire support period
4 - Incident and Vulnerability Reporting
: Establish a PSIRT/CSIRT—with coordinated disclosure, patching, and updates throughout the lifecycle.
- Establish PSIRT/CSIRT processes, including escalation procedures and responsibilities
- Reporting Process to the ENISA Portal: 24-Hour Advance Notice, 72-Hour Report, Final Report
- Establish a Coordinated Vulnerability Disclosure Process for External Reporters
- Integration with existing SOC and incident response structures
5 - Assessment, Testing & Certification
Penetration tests, technical documentation, and proof of compliance for CE marking.
- Penetration tests and security analyses in accordance with Annex I requirements
- Preparing Technical Documentation and Declarations of Conformity to Meet Audit Standards
- Support with conformity assessment, including, if necessary, a notified body
- CE Marking and Submission to the Market Surveillance Process
The challenge
- Mandatory CRA Deadlines: Reporting Requirement Effective September 2026, Compliance by December 2027
- Unclear Product Scope, Risk Classification, and Conformity Assessment
- No process for reporting vulnerabilities and incidents within 24 hours
- Security Is Not Embedded in Design, Development, and the Supply Chain
- Missing SBOMs, documentation, and audit-ready evidence
Our Added Value
- End-to-End: Governance, Development, Incident Reporting, and Documentation
- Measures to fulfill CRA obligations integrated into your existing ISMS
- Establishment of compliant reporting processes
- Practical implementation by experts who understand the technology, not just the rules
- Audit-ready evidence and compliance documentation
Your Path to CRA Compliance
- Governance
Scoping, gap analysis, and integration of CRA obligations into your existing ISMS—the foundation for all subsequent steps.
's secure development approach—Security by Design, hardened SSDLC, and comprehensive SBOMs—ensures that new releases are compliant from the start.- Reporting & Incident Management
Starting September 11, 2026, every hour counts: PSIRT processes and reporting channels for the 24-hour and 72-hour deadlines will be in place in a timely manner. - Assessment & Documentation
Tests, technical documentation, and conformity assessment lead to the CE marking through December 11, 2027.

CRA Consulting: Quick Answers to Your Questions
When does the Cyber Resilience Act take effect for us?
The regulation has been in effect since December 10, 2024. Starting September 11, 2026, actively exploited vulnerabilities and serious security incidents must be reported; as of December 11, 2027, all requirements will be fully in effect—new products with digital elements may then only be placed on the market in the EU if they bear a CRA-compliant CE marking.
Are we even affected?
The CRA generally applies to all manufacturers, importers, and distributors of products with digital elements that are placed on the market in the EU—regardless of where their company is headquartered. In our CRA scoping analysis, we determine which products are affected, which risk class they fall into, and which exemptions might apply (e.g., for purely open-source projects without commercial exploitation).
What happens if we miss the deadlines?
The CRA provides for a three-tiered system of fines: up to €15 million or 2.5% of global annual revenue for violations of core safety requirements; up to €10 million or 2% for other obligations; and up to €5 million or 1% for providing false or incomplete information to authorities—in addition to the risk of being barred from selling products in the EU.
Do we need to replace our existing ISMS?
No. An existing ISO 27001 or comparable ISMS provides a solid foundation. We supplement it with CRA-specific controls—such as product risk classification, SBOM maintenance, and reporting processes—rather than establishing parallel structures.
How long does a typical CRA implementation take?
That depends on the product portfolio and the initial situation. Scoping and gap analysis typically provide a reliable roadmap within a few weeks; full implementation through to conformity assessment can take several months.
DeepDive
What is the Cyber Resilience Act?
The Cyber Resilience Act (Regulation (EU) 2024/2847) is the first EU-wide regulation to establish mandatory cybersecurity requirements for “products with digital elements”—that is, virtually any hardware or software with a direct or indirect connection to a device or network.
Essentially, the CRA requires three things:
- Security “by design and by default” throughout the entire product lifecycle
- A structured approach to addressing vulnerabilities, including a Software Bill of Materials (SBOM)
- and mandatory reporting of actively exploited vulnerabilities and serious security incidents to ENISA and the relevant authorities.
The requirements are phased in—those who start now will avoid feeling rushed right before the deadlines.
Who is affected? Three risk categories
The CRA tiers its requirements based on the cybersecurity risk posed by a product. The classification determines whether a self-assessment is sufficient or whether an independent audit firm must be involved.
Standard
- About 90% of all affected products.
- Conformity is demonstrated through the manufacturer's self-assessment.
- Examples: traditional business software, consumer electronics, simple IoT devices
's Key Products (Annex III)
- Class I requires harmonized standards or a testing laboratory
- Class II requires an independent conformity assessment.
- Examples: Identity and access management, password managers, operating systems, smart home security technology, hypervisors, container runtimes
Critical Products
(Annex IV)
- Highest risk level – mandatory certification by a notified body under a European scheme.
- Examples: Smart cards and similar security-critical hardware components
