EU Cyber Resilience Act
The EU Cyber Resilience Act already applies to your product line. Reporting obligations are live.
A 10-day fixed-fee engagement that tells you exactly how CRA hits your products, what tier you're in, and what to do next, before you spend money on the wrong path.
10 business days · Fixed fee
Does the EU Cyber Resilience Act apply to your products? Four questions.
Does your product contain software or firmware, and can it connect to a device or a network, directly or indirectly?
If yes, it is a "product with digital elements" and the CRA applies. That covers nearly all ICT, networking, IoT, and embedded hardware, plus standalone software and the cloud services a product needs to function. Purely analog hardware with no code is out. So are products already covered by EU medical device, vehicle, aviation, and marine equipment rules.
Whose name is on the product when it reaches the EU?
If it is your brand, you are the manufacturer under the CRA and every obligation is yours, no matter where you are headquartered. An EU importer or distributor handling your product has its own duties, but the fines, the reporting clock, and the technical file all sit with you. If you build for an EU customer's brand as an ODM, your customer is the manufacturer and carries that liability, and they cannot meet it without you: expect contracts requiring a software bill of materials, security updates for the product's support period, vulnerability notification within hours, and documentation for their technical file. Either way, a Taiwan-based company shipping to the EU is in scope.
Is your product in the "important" or "critical" categories?
Most products are in the default tier and can self-assess. Important products listed in Annex III need more: Class I includes routers, modems, switches, operating systems, VPN products, password managers, security cameras, smart locks, baby monitors, alarm systems, and connected toys; Class II includes firewalls, intrusion detection and prevention systems, and hypervisors. Class I products can only self-assess if you build to an EU harmonised standard, and none have been published yet. Until they are, plan on a notified body for Class I. Class II always needs a notified body or an EU cybersecurity certification. Critical products in Annex IV, such as smart meter gateways, smartcards and secure elements, and tamper-protected cryptographic hardware, may face mandatory EU certification.
Are your products already on the EU market?
If yes, the CRA already applies to them. Since September 11, 2026, every manufacturer must report actively exploited vulnerabilities and severe incidents through ENISA's single reporting platform, with a 24-hour early warning, and that duty covers products placed on the market before the rules took effect. Full conformity and CE marking are required for products placed on the market from December 11, 2027. Products already on the market by then only need full conformity if they are substantially modified afterwards.
If you answered yes to 1 and 2 and aren't certain on 3 or 4, the Scope & Roadmap engagement is built for you.
Book a 30-minute scoping call →CRA Scope & Roadmap
A 10-business-day fixed-fee assessment for non-EU manufacturers placing products on the EU market.
- Written assessment of which SKUs are in CRA scope and which tier they fall into
- Conformity route analysis: which Annex VIII module applies and what that means for your product line
- Roadmap from your current reporting exposure to full conformity by December 11, 2027
- Identified roles and external dependencies: notified body, authorised representative, internal engineering, third-party support
- 60-minute roadmap call with your engineering and compliance leads
Ken Negard, CISSP
Founder, Profound Systems · ISO 27001 / SOC 2 Type 2 audits
Ken Negard is the founder of Profound Systems, a New York and Taiwan based systems and security practice. He is CISSP-certified and has carried organizations through ISO 27001 and SOC 2 Type 2 audits, the same evidence-and-process discipline CRA conformity demands.
His work sits where engineering meets regulation: mapping complex systems, scoping obligations, and sequencing the work so teams spend money in the right order. Engagements are direct. You work with Ken from scoping call to roadmap, and you finish with a plan your own team can run.
EU CRA Applicability Check (PDF)
Two-page reference covering the four-question applicability check, where the CRA stands today, and the Scope & Roadmap engagement. Useful as an internal forward.
One email. No list signup. PDF delivered immediately.
What this engagement is and isn't.
Profound Systems is a specialist practice, not a notified body or authorised representative. The Scope & Roadmap engagement produces an independent assessment and written plan; it does not constitute conformity certification or technical file authorship. For work requiring notified-body involvement or EU-based authorised representative services, we name the qualified providers and can coordinate handoff.