Your 6-Step Path to
CRA Compliance
A complete implementation roadmap for the EU Cyber Resilience Act. From initial assessment to ongoing monitoring, this guide covers everything you need to achieve compliance by December 2027.
Why This Guide Works
This roadmap has been designed based on the actual CRA regulation text and industry best practices. Each step builds on the previous one, ensuring nothing is missed.
Regulation-Based
Every step directly maps to specific CRA articles and requirements
Time-Efficient
Realistic timelines that fit into your development cycles
Tool-Supported
Free tools and templates to accelerate implementation
Before You Start
This guide assumes your product falls under CRA scope (has digital elements and is sold in the EU). If you're unsure, use our Product Checker first. Each step includes difficulty levels and time estimates to help you plan resources accordingly.
EU-Aligned Standards Framework
The CRA sets essential cybersecurity requirements in Annex I but does not mandate specific standards. These voluntary frameworks can help demonstrate conformity, but no harmonised standards have been formally cited in the Official Journal yet — the standardisation request is ongoing with first deliverables expected Q3 2026. Until then, using these standards is good practice but does not give a legal presumption of conformity.
ENISA Guidelines
EU-driven cybersecurity best practices aligned with CRA objectives
- Threat modeling methodologies
- Incident response frameworks
- SBOM best practices
IEC 62443-4-1 & 4-2
Industrial-grade secure product development and lifecycle security
- Secure development lifecycle (SDL)
- Technical security requirements
- Component security validation
ISO/IEC 27001 Suite
Comprehensive security management with CRA-specific extensions
- 27034: Application security
- 29147: Vulnerability disclosure
- 30111: Vulnerability handling
- 27036: Supply chain security
Leverage Your Existing Certifications
If you already have ISO/IEC 27001 certification or follow IEC 62443 standards, you have a strong foundation for meeting CRA essential requirements. These frameworks are not legally mandated by the CRA, but they align with Annex I requirements and can reduce your compliance effort. View our Standards Guide to see how international standards map to CRA obligations.
Implementation Timeline Overview
Plan your CRA compliance journey with realistic milestones
Figure Out What You Need to Do
2-4 weeks
BeginnerBuild Security Into Your Product
4-8 weeks
IntermediateSet Up Your Security Processes
4-6 weeks
IntermediateCreate the Required Paperwork
3-5 weeks
BeginnerTest That Everything Works
3-6 weeks
AdvancedKeep It Secure Forever
Ongoing
IntermediateConformity Assessment Procedures by Product Category
The CRA requires different conformity assessment procedures based on your product's risk category. Identify your category and follow the correct assessment route.
Default Products
Most products with digital elements
Self-assessment: manufacturer verifies compliance and maintains technical documentation. No third-party involvement required.
Important Class I (Annex III, Part I)
Products with higher security implications
Self-assessment allowed IF harmonised standards covering all requirements are applied. Otherwise, EU-type examination (Module B) plus production control (Module C) by notified body.
Important Class II (Annex III, Part II)
Products in critical sectors
Mandatory third-party: EU-type examination (Module B) plus production control (Module C), OR full quality assurance (Module H) by notified body.
Critical Products (Annex IV)
Products that could cause serious harm
Mandatory third-party: Same as Important Class II, or where required by implementing acts, European cybersecurity certification scheme per Regulation (EU) 2019/881.
Not sure which category applies?
Use our Product Checker Tool to determine your product's risk category, or review the Annex III and Annex IV product lists.
Your Step-by-Step Implementation Guide
Follow these 6 steps in order to achieve full CRA compliance. Each step builds on the previous one, creating a comprehensive security and compliance program.
1. Figure Out What You Need to Do
Check which of your products need to follow CRA rules and how strict they need to be
Key Actions
- List all your products that have software or connect to internet
- Check the product category: default, important (Class I or II), or critical
- See what security features you already have
- Make a list of what's missing
Available Tools
Real Examples
2. Build Security Into Your Product
Make your products secure from the beginning, not as an afterthought
Key Actions
- Implement secure development practices (Annex I Part I requirements)
- Conduct threat modelling and risk assessment
- Ensure products ship without known exploitable vulnerabilities
- Document security requirements and design decisions
Available Tools
Real Examples
3. Set Up Your Security Processes
Create systems to handle security problems when they happen
Key Actions
- Establish a vulnerability disclosure policy (Annex I Part II)
- Set up vulnerability handling procedures (ISO 29147/30111 can help)
- Create incident response and ENISA reporting capability
- Build secure update distribution systems
Available Tools
Real Examples
4. Create the Required Paperwork
Write the official documents that prove your product follows CRA rules
Key Actions
- Write technical docs showing how your product is secure
- Create the official EU declaration paper
- Write easy-to-read security guides for users
- List all the software components in your product
Available Tools
Real Examples
5. Test That Everything Works
Prove your product actually meets all the security requirements
Key Actions
- Run security tests on your product
- Check that you've followed all the rules
- Get an outside expert to verify (if required)
- Have someone try to hack your product (safely)
Available Tools
Real Examples
6. Keep It Secure Forever
Monitor and maintain your product's security for years after you sell it
Key Actions
- Watch for new security threats that affect your product
- Fix security problems quickly when they're found
- Keep your customers updated about security
- Plan how long you'll support each product version
Available Tools
Real Examples
Quick Reference Guide
Key information you'll need throughout your implementation
Critical Deadlines
Core Requirements
Supporting Tools & Resources
Free tools to accelerate your CRA compliance implementation
CRA Gap Analysis
Assess your compliance with CRA Annex I requirements
Product Checker
Check if your products are covered by CRA
Secure Development Checklist
CRA requirements checklist (with optional IEC 62443 mapping)
CRA Documentation Templates
Templates for CRA technical documentation (ISO 27001 compatible)
Risk Calculator
Determine your product category (default/important/critical)
CRA Timeline
View key deadlines and implementation milestones
Ready to Start Your CRA Compliance Journey?
Don't wait until 2027. Start with a gap analysis to understand exactly where you stand and what needs to be done.