Preparing for the EU Cyber Resilience Act: where do you start?

EU Cyber Resilience Act compliance

Robin Kanjilal
Robin Kanjilal
Managing Director
5 min read
Preparing for the EU Cyber Resilience Act: where do you start?

Practical first steps for businesses placing digital products on the EU market.

Once a business has established that the EU Cyber Resilience Act (CRA) applies to it  , the next question is usually: where do we actually start?


What compliance actually involves

Becoming the "manufacturer" of a product under the CRA carries a specific set of responsibilities, whether the product was developed in-house or outsourced and placed on the market under your own brand:

  • Cybersecurity risk assessments
  • Secure-by-design and secure-by-default development
  • Vulnerability management processes
  • A Software Bill of Materials (SBOM)
  • Security updates throughout the support period, typically at least five years
  • Technical documentation
  • An EU Declaration of Conformity and CE marking

None of these are unfamiliar concepts individually. What's new is the expectation that they're demonstrable, documented and maintained throughout a product's life, rather than addressed once and filed away.

Who should own this internally?
CRA compliance rarely sits neatly with one department. Product and engineering teams need to build secure-by-design principles into development. IT typically owns vulnerability management and incident reporting. Compliance or legal usually handles documentation and conformity assessment, while procurement needs to understand supplier exposure.

Treating this as "an IT problem" is one of the more common mistakes businesses make. Without clear ownership across these areas, requirements can fall into the gaps between departments, and nobody notices until an audit or a customer asks the question directly.

The cost of getting it wrong
Non-compliance isn't just a legal risk. Products that don't meet CRA requirements can be barred from the EU market entirely, which for many UK businesses means losing access to one of their largest trading regions. Financial penalties apply too, but the more immediate risk for most organisations is commercial.

Customers are increasingly asking suppliers to prove compliance before signing contracts, the same way CE marking or ISO certifications are already used as a filter in procurement. A business that can't demonstrate CRA readiness may find itself excluded from tenders, or losing ground to competitors who can answer the question with confidence.

Your suppliers are part of the equation too
CRA exposure doesn't stop at your own product line. If a business relies on third-party components, outsourced development or white-labelled software, its compliance depends partly on decisions made by suppliers it doesn't directly control.

This is where the Software Bill of Materials becomes more than a documentation exercise. It's a working record of exactly what's inside a product, which makes it possible to identify when a supplier's component introduces a vulnerability, and to respond quickly when it does. Businesses that haven't mapped their supply chain in this way often find that's the first gap a proper assessment uncovers. 

A sensible starting point
Organisations that manufacture or distribute digital products into the EU should begin assessing their exposure now if they haven’t already.

In practice, that usually means:

  • Identifying which products qualify as products with digital elements
  • Validating product classifications against the legislation
  • Reviewing who carries manufacturer responsibilities across the business
  • Assessing existing software development and vulnerability management processes
  • Preparing incident reporting processes
  • Building a roadmap towards full compliance

None of these steps require a complete rebuild of existing processes. For many organisations, the groundwork, secure development practices, documentation, incident response, is already partly in place. The work is in identifying the gaps and closing them methodically, rather than all at once under pressure.

A quick readiness check
A few honest answers to these questions will show you roughly where your business stands:

  • Do you know which of your products count as products with digital elements under the CRA?
  • Could you name who holds manufacturer responsibility for each of them?
  • Do you have a documented vulnerability management process?
  • Could you produce technical documentation on request, today?
  • Do you know how you'd report a security incident within the 24-hour window?

If most of these are easy to answer, you're in a stronger position than you might think. If not, that's a reasonable place to start.


More than another compliance exercise
For many organisations, the EU Cyber Resilience Act represents more than another piece of compliance legislation. It reflects a shift in how regulators expect companies to build and oversee digital products.

Businesses that begin preparing now won't just reduce the risk of future compliance issues, they'll be better placed to demonstrate trust, resilience and cybersecurity maturity to customers, partners and regulators. And they'll be better positioned to keep expanding confidently into European and other regulated markets.

This is exactly where independent guidance tends to add the most value. It helps organisations understand what applies to them, identify the gaps and build a practical roadmap towards compliance.

Link to previous article

Keep exploring

Related insights

let's collaborate

Need IT That Reduces Risk and Stands Up to Regulation?

Let's strengthen reliability and optimise your IT for efficiency.