Implementation Guide - 3 Years to Prepare

Your 6-Step Path to
CRA Compliance

A complete implementation roadmap for the EU Cyber Resilience Act. From initial assessment to ongoing monitoring, this guide covers everything you need to achieve compliance by December 2027.

3-6 months total implementation
Step-by-step instructions
Tools and templates included

Why This Guide Works

This roadmap has been designed based on the actual CRA regulation text and industry best practices. Each step builds on the previous one, ensuring nothing is missed.

Regulation-Based

Every step directly maps to specific CRA articles and requirements

Time-Efficient

Realistic timelines that fit into your development cycles

Tool-Supported

Free tools and templates to accelerate implementation

Before You Start

This guide assumes your product falls under CRA scope (has digital elements and is sold in the EU). If you're unsure, use our Product Checker first. Each step includes difficulty levels and time estimates to help you plan resources accordingly.

EU-Aligned Standards Framework

The CRA sets essential cybersecurity requirements in Annex I but does not mandate specific standards. These voluntary frameworks can help demonstrate conformity, but no harmonised standards have been formally cited in the Official Journal yet — the standardisation request is ongoing with first deliverables expected Q3 2026. Until then, using these standards is good practice but does not give a legal presumption of conformity.

ENISA Guidelines

EU-driven cybersecurity best practices aligned with CRA objectives

  • Threat modeling methodologies
  • Incident response frameworks
  • SBOM best practices

IEC 62443-4-1 & 4-2

Industrial-grade secure product development and lifecycle security

  • Secure development lifecycle (SDL)
  • Technical security requirements
  • Component security validation

ISO/IEC 27001 Suite

Comprehensive security management with CRA-specific extensions

  • 27034: Application security
  • 29147: Vulnerability disclosure
  • 30111: Vulnerability handling
  • 27036: Supply chain security

Leverage Your Existing Certifications

If you already have ISO/IEC 27001 certification or follow IEC 62443 standards, you have a strong foundation for meeting CRA essential requirements. These frameworks are not legally mandated by the CRA, but they align with Annex I requirements and can reduce your compliance effort. View our Standards Guide to see how international standards map to CRA obligations.

Implementation Timeline Overview

Plan your CRA compliance journey with realistic milestones

1

Figure Out What You Need to Do

2-4 weeks

Beginner
2

Build Security Into Your Product

4-8 weeks

Intermediate
3

Set Up Your Security Processes

4-6 weeks

Intermediate
4

Create the Required Paperwork

3-5 weeks

Beginner
5

Test That Everything Works

3-6 weeks

Advanced
6

Keep It Secure Forever

Ongoing

Intermediate
Total Timeline: 3-6 Months
Depending on your current security maturity

Conformity Assessment Procedures by Product Category

The CRA requires different conformity assessment procedures based on your product's risk category. Identify your category and follow the correct assessment route.

Default Products

Most products with digital elements

Module A (Internal Control)

Self-assessment: manufacturer verifies compliance and maintains technical documentation. No third-party involvement required.

Reference: Annex VIII, Part I

Important Class I (Annex III, Part I)

Products with higher security implications

Module A or Module B+C

Self-assessment allowed IF harmonised standards covering all requirements are applied. Otherwise, EU-type examination (Module B) plus production control (Module C) by notified body.

Reference: Annex VIII, Part II

Important Class II (Annex III, Part II)

Products in critical sectors

Module B+C or Module H

Mandatory third-party: EU-type examination (Module B) plus production control (Module C), OR full quality assurance (Module H) by notified body.

Reference: Annex VIII, Part III

Critical Products (Annex IV)

Products that could cause serious harm

Module B+C, Module H, or EU Cybersecurity Certification

Mandatory third-party: Same as Important Class II, or where required by implementing acts, European cybersecurity certification scheme per Regulation (EU) 2019/881.

Reference: Annex VIII, Part IV

Not sure which category applies?

Use our Product Checker Tool to determine your product's risk category, or review the Annex III and Annex IV product lists.

Your Step-by-Step Implementation Guide

Follow these 6 steps in order to achieve full CRA compliance. Each step builds on the previous one, creating a comprehensive security and compliance program.

Step 1 Beginner

1. Figure Out What You Need to Do

Check which of your products need to follow CRA rules and how strict they need to be

Key Actions

  • List all your products that have software or connect to internet
  • Check the product category: default, important (Class I or II), or critical
  • See what security features you already have
  • Make a list of what's missing

Real Examples

Smart thermostat = default category Industrial sensor = important products (Annex III) Power grid controller = critical products (Annex IV)
Timeline: 2-4 weeks
Step 2 Intermediate

2. Build Security Into Your Product

Make your products secure from the beginning, not as an afterthought

Key Actions

  • Implement secure development practices (Annex I Part I requirements)
  • Conduct threat modelling and risk assessment
  • Ensure products ship without known exploitable vulnerabilities
  • Document security requirements and design decisions

Available Tools

CRA Gap Analysis Secure Development Checklist IEC 62443 Mapping (optional)

Real Examples

Use strong passwords Encrypt data Limit who can access what
Timeline: 4-8 weeks
Step 3 Intermediate

3. Set Up Your Security Processes

Create systems to handle security problems when they happen

Key Actions

  • Establish a vulnerability disclosure policy (Annex I Part II)
  • Set up vulnerability handling procedures (ISO 29147/30111 can help)
  • Create incident response and ENISA reporting capability
  • Build secure update distribution systems

Available Tools

Vulnerability Disclosure Template Incident Response Guide SBOM Generator

Real Examples

Bug bounty program Automatic security updates Emergency response team
Timeline: 4-6 weeks
Step 4 Beginner

4. Create the Required Paperwork

Write the official documents that prove your product follows CRA rules

Key Actions

  • Write technical docs showing how your product is secure
  • Create the official EU declaration paper
  • Write easy-to-read security guides for users
  • List all the software components in your product

Real Examples

CE marking certificate User manual security section Software ingredient list
Timeline: 3-5 weeks
Step 5 Advanced

5. Test That Everything Works

Prove your product actually meets all the security requirements

Key Actions

  • Run security tests on your product
  • Check that you've followed all the rules
  • Get an outside expert to verify (if required)
  • Have someone try to hack your product (safely)

Real Examples

Penetration testing Third-party audit Vulnerability scanning
Timeline: 3-6 weeks
Step 6 Intermediate

6. Keep It Secure Forever

Monitor and maintain your product's security for years after you sell it

Key Actions

  • Watch for new security threats that affect your product
  • Fix security problems quickly when they're found
  • Keep your customers updated about security
  • Plan how long you'll support each product version

Real Examples

Monthly security patches Vulnerability database monitoring 5-year support policy
Timeline: Ongoing

Quick Reference Guide

Key information you'll need throughout your implementation

Critical Deadlines

December 10, 2024
CRA enters into force
September 11, 2026
Reporting obligations apply
December 11, 2027
Full CRA requirements apply

Core Requirements

Security by design and default
Vulnerability disclosure process
Security updates for product lifetime
Technical documentation
CE marking and declaration
Incident response capability

Ready to Start Your CRA Compliance Journey?

Don't wait until 2027. Start with a gap analysis to understand exactly where you stand and what needs to be done.

Article Article 11 ·
View on EUR-Lex

🤝 Still Feeling Overwhelmed by CRA?

The Cyber Resilience Act has a lot of moving parts. Our free tools work great for most people, but if you're dealing with something really complex or have a tight deadline, we can help you figure it out faster.