EU Cyber Resilience Act

The EU Cyber Resilience Act already applies to your product line. Reporting obligations are live.

A 10-day fixed-fee engagement that tells you exactly how CRA hits your products, what tier you're in, and what to do next, before you spend money on the wrong path.

10 business days  ·  Fixed fee

Where the CRA stands
September 11, 2026
Article 14 reporting obligations in effect, including for products already on the EU market.
December 11, 2027
Full conformity and CE marking required.
Self-check

Does the EU Cyber Resilience Act apply to your products? Four questions.

Does your product contain software or firmware, and can it connect to a device or a network, directly or indirectly?

If yes, it is a "product with digital elements" and the CRA applies. That covers nearly all ICT, networking, IoT, and embedded hardware, plus standalone software and the cloud services a product needs to function. Purely analog hardware with no code is out. So are products already covered by EU medical device, vehicle, aviation, and marine equipment rules.

Whose name is on the product when it reaches the EU?

If it is your brand, you are the manufacturer under the CRA and every obligation is yours, no matter where you are headquartered. An EU importer or distributor handling your product has its own duties, but the fines, the reporting clock, and the technical file all sit with you. If you build for an EU customer's brand as an ODM, your customer is the manufacturer and carries that liability, and they cannot meet it without you: expect contracts requiring a software bill of materials, security updates for the product's support period, vulnerability notification within hours, and documentation for their technical file. Either way, a Taiwan-based company shipping to the EU is in scope.

Is your product in the "important" or "critical" categories?

Most products are in the default tier and can self-assess. Important products listed in Annex III need more: Class I includes routers, modems, switches, operating systems, VPN products, password managers, security cameras, smart locks, baby monitors, alarm systems, and connected toys; Class II includes firewalls, intrusion detection and prevention systems, and hypervisors. Class I products can only self-assess if you build to an EU harmonised standard, and none have been published yet. Until they are, plan on a notified body for Class I. Class II always needs a notified body or an EU cybersecurity certification. Critical products in Annex IV, such as smart meter gateways, smartcards and secure elements, and tamper-protected cryptographic hardware, may face mandatory EU certification.

Are your products already on the EU market?

If yes, the CRA already applies to them. Since September 11, 2026, every manufacturer must report actively exploited vulnerabilities and severe incidents through ENISA's single reporting platform, with a 24-hour early warning, and that duty covers products placed on the market before the rules took effect. Full conformity and CE marking are required for products placed on the market from December 11, 2027. Products already on the market by then only need full conformity if they are substantially modified afterwards.

If you answered yes to 1 and 2 and aren't certain on 3 or 4, the Scope & Roadmap engagement is built for you.

Book a 30-minute scoping call →
The engagement
About

Ken Negard, CISSP

Founder, Profound Systems  ·  ISO 27001 / SOC 2 Type 2 audits

Ken Negard is the founder of Profound Systems, a New York and Taiwan based systems and security practice. He is CISSP-certified and has carried organizations through ISO 27001 and SOC 2 Type 2 audits, the same evidence-and-process discipline CRA conformity demands.

His work sits where engineering meets regulation: mapping complex systems, scoping obligations, and sequencing the work so teams spend money in the right order. Engagements are direct. You work with Ken from scoping call to roadmap, and you finish with a plan your own team can run.

One-pager

EU CRA Applicability Check (PDF)

Two-page reference covering the four-question applicability check, where the CRA stands today, and the Scope & Roadmap engagement. Useful as an internal forward.

One email. No list signup. PDF delivered immediately.

Note

What this engagement is and isn't.

Profound Systems is a specialist practice, not a notified body or authorised representative. The Scope & Roadmap engagement produces an independent assessment and written plan; it does not constitute conformity certification or technical file authorship. For work requiring notified-body involvement or EU-based authorised representative services, we name the qualified providers and can coordinate handoff.