Blauer Hintergrund

Sustainable CRA Measures for Enhanced Product Security and Competitiveness

The CRA sets specific requirements for manufacturers, importers, and distributors of digital products. With carmasec, you understand your obligations, receive a reliable roadmap, and implement the requirements on schedule.

 

Our Services Get a consultation now

Checklisten-Icon
Key Facts

The CRA applies to hardware, software, and networked systems with digital elements. Initial reporting obligations for actively exploited vulnerabilities take effect from September 2026. From December 2027, only compliant products may be placed on the EU market. Violations may result in fines of up to 15 million euros or 2.5 percent of global annual revenue, as well as sales bans.

Puzzle-mit-Haken-Icon
Complex Requirements

The CRA requires Security by Design, comprehensive vulnerability management, regular security updates for at least five years, a complete SBOM, and a conformity assessment with CE marking. The requirements affect development, product management, and executive management equally.

Schutzschild mit Kreispfeilen-Icon
Known Challenges

Many organizations have previously focused on functional safety. Responsibilities for cybersecurity are often unclear. Legacy products can only be retrofitted with considerable effort. And the regulation itself is complex, while binding standards are still pending.

cra. done. right.

Your Partner for the Cyber Resilience Act

We bring experience from complex compliance projects. We analyze which of your products fall under the CRA and implement the requirements in a structured manner. Every measure is tailored to your context. The result: complete, auditable CRA compliance that secures the EU market.

Getting Started with CRA Compliance

Tailored to your specific needs.

Starter

Determining Impact

You’ll quickly know which of your products fall under the CRA and exactly what is required of you.

  • Impact analysis of your products
  • Classification into CRA product categories
  • Initial assessment of the need for action
  • Summary for management

start 1.500 €*

depending on the number of products

Schedule a strategy call

Professional

Clarity and Roadmap

You know you’re affected. We analyze the current situation, identify the gaps, and provide a prioritized roadmap with concrete next steps.

  • Everything from the Starter
  • Document Toolbox
  • Gap assessment against all CRA requirements
  • Prioritized action roadmap
  • Concrete next steps based on proven blueprints

start 9.000 €*

Schedule a strategy call

 

Managed

Full implementation

Ongoing support as a trusted advisor for your CRA compliance.

  • Defined monthly hour allocation
  • Regular scheduled meetings
  • Review of actions and documentation
  • Consultation on CRA
  • Support with action planning

start 3.500 €*

per month, depending on scope

Request a retainer

We’ll put together a customized package for you.

 

From Day One

With carmasec, you have an experienced partner for the entire Cyber Resilience implementation. From initial assessment to auditable compliance. You quickly understand which of your products are affected, what is specifically required, and which steps are next.

The Cyber Resilience Act fundamentally changes the way cybersecurity is approached in products. The implication is clear: No CRA compliance means no CE marking. And no CE marking means no market access in the EU.

Holger Kühlwetter, Senior Security Consultant

Contact Expert
Blauer Hintergrund
Whitepaper-Cover „Cyber Resilience Act kommt. Sind deine Produkte bereit?

CRA at a Glance

The Cyber Resilience Act requires manufacturers, importers, and distributors of digital products to demonstrate security throughout the entire product lifecycle. The requirements apply starting from the initial development phase and include security by design, vulnerability management, reporting obligations, SBOM documentation, security updates for at least five years, and a conformity assessment with CE marking.

You can find all the details on requirements, deadlines, and common implementation mistakes in our free white paper (in german).

Download

Illustration zum Cyber Resilience Act der EU mit CE-Kennzeichnung auf einem Computerchip

Only an analysis can reveal the true extent of the gap

Many companies believe their products already largely meet cyber resilience requirements. Gap analyses consistently paint a different picture, as the gap between perceived and actual compliance is often wider than expected.

 

Read the case study

Häkchen-Icon

We support organizations from initial assessment to auditable compliance. Every measure is aligned with the products and processes.

Häkchen-Icon

Our experience ranges from mid-sized manufacturers to internationally operating companies with complex product portfolios.

Häkchen-Icon

We combine governance, technical analysis, and operational implementation in one team to eliminate friction losses.

FAQ

Do you have questions about the Cyber Resilience Act? Here are our answers

Am I affected by the CRA?

The CRA applies to all products with digital elements that are manufactured, imported, or sold in the EU. This includes hardware with embedded software, software products, and networked systems. Exceptions include medical devices and vehicles, which are subject to their own regulations.

What does Security by Design mean?

Security is planned from the first development phase. This includes systematic risk analysis, threat models, and traceable documentation of all security-relevant decisions.

What does the CRA require for conformity assessment?

Products must undergo a conformity assessment before being placed on the EU market. CE marking is a prerequisite for market access.

How does the CRA differ from NIS-2?

NIS-2 regulates operators of essential and critical infrastructure. The CRA regulates products with digital elements and is directed at manufacturers, importers, and distributors. Both regulations may apply simultaneously.

How comprehensive is the CRA Starter Package and where does it end?

CRA Starter clarifies impact, risk classes, and initial action requirements. Structured implementation begins with CRA Professional.

What distinguishes your gap assessment from a traditional gap analysis?

We deliver prioritized measures that are immediately actionable. The assessment is based on your specific products and processes.

Which areas and roles are involved?

Development, product management, legal, and executive management.

How can the results be integrated into existing governance structures?

We align the measures with existing structures. Organizations that already operate an ISMS can build CRA requirements directly on it.

What is the added value compared to an internal analysis?

We bring experience from numerous CRA projects. You receive a reliable assessment that surpasses internally developed analyses in depth and practical relevance.

Who bears legal responsibility?

Manufacturers bear primary responsibility. Importers and distributors are liable if they fail to ensure compliant products. Executive management is personally responsible for compliance with reporting obligations.

What happens after CRA Starter or Professional?

You decide whether to manage implementation internally or entrust it to experienced hands with CRA Enterprise. We support both paths.

Whether start-up, mid-sized company, or corporation: We find the right solution

Trust is built through results

Contact

What can we do for you?

Fill out the form, submit it, done. We will get back to you within 24 hours, unless it’s a weekend or public holiday.

Portrait photo of Jan Sudmeyer, Managing Director at carmasec.
Jan Sudmeyer
Managing Director
+49 (0)201 426 385 905