1. Home/
  2. Services/
  3. Regulatory Compliance Management/
  4. CRA Cyber Resilience Act/
  5. CRA Beratung

Subscribe to Newsletter

Stay up to date with the latest trends and developments

By subscribing, you agree to our privacy policy.

A
ADVISORI FTC GmbH

Transformation. Innovation. Security.

Office Address

Kaiserstraße 44

60329 Frankfurt am Main

Germany

View on map

Contact

info@advisori.de+49 69 913 113-01

Mon-Fri: 9:00 AM - 6:00 PM

Company

Services

Social Media

Follow us and stay up to date.

  • /
  • /

© 2024 ADVISORI FTC GmbH. All rights reserved.

Your browser does not support the video tag.
Implementing EU Cyber Resilience Act compliance

CRA Consulting — Cyber Resilience Act

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) imposes binding cybersecurity standards on all manufacturers, importers, and distributors of products with digital elements. From September 2026, reporting obligations apply for actively exploited vulnerabilities (24-hour deadline to ENISA); from December 2027, all products must be fully CRA-compliant — otherwise fines of up to €15 million or 2.5% of global annual turnover and loss of EU market access are at risk. ADVISORI ensures you are compliant in time.

  • ✓Early compliance with CRA requirements ahead of the 2026/2027 deadlines
  • ✓Secure-by-Design integration into your product development
  • ✓Development of a complete Software Bill of Materials (SBOM)
  • ✓Competitive advantage through demonstrable product security

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

info@advisori.de+49 69 913 113-01

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

What the Cyber Resilience Act means for your organisation

Why Choose ADVISORI?

  • Deep regulatory and industry expertise
  • Proven track record with leading organizations
  • Practical, implementation-focused approach
  • End-to-end support from assessment to implementation
⚠

Expert Consultation Available

Contact our specialists today for a personalized assessment of your requirements.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We guide you in a structured manner from the current-state analysis to demonstrable conformity — tailored to your product landscape and maturity level.

Our Approach:

Scoping & Product Classification: Identification of all products with digital elements in your portfolio and classification into CRA categories (Standard, Important Class I/II, Critical). Identification of the applicable conformity assessment procedures — self-assessment, assessment against harmonised standards, or third-party assessment by a notified body.

Gap Analysis & Maturity Assessment: Systematic comparison of your existing processes (development, vulnerability management, documentation, incident response) against the requirements of CRA Annexes I and II. Result: prioritised gap list with effort estimates and quick wins.

Compliance Roadmap: Development of a binding implementation plan with milestones for September 2026 (reporting obligations) and December 2027 (full conformity). Definition of work packages, responsibilities, and budget framework — aligned with your product development cycle.

Implementation: Execution of identified measures — SBOM toolchain in the CI/CD pipeline, Secure Development Lifecycle, Vulnerability Disclosure Policy, reporting processes to ENISA/CSIRT, secure default configurations. Parallel creation of technical documentation in accordance with Annex VII.

Internal Auditing & Conformity Assessment: Conducting an internal pre-audit against all CRA requirements, remediation of identified findings, and support throughout the formal conformity assessment — as a self-assessment for standard products, and in collaboration with notified bodies for Class II and critical products.

Ongoing Operations & Monitoring: Establishment of continuous vulnerability management throughout the entire support period (standard: 5 years), regular SBOM updates, monitoring of new harmonised standards and CRA implementing acts, training of new staff. This ensures your CRA compliance remains secured even after initial conformity.

"ADVISORI provided exceptional expertise and guidance throughout our project. Their deep understanding of regulatory requirements and practical approach helped us achieve our compliance goals efficiently."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

LinkedIn Profile

Our Services

We offer you tailored solutions for your digital transformation

CRA Gap Analysis & Product Classification

Systematic assessment of your product portfolio against all requirements of CRA Annexes I and II. We classify each product into the correct category (Standard, Important Class I/II, Critical), identify the applicable conformity assessment procedures, and deliver a prioritised measures roadmap with concrete work packages, responsibilities, and a timeline through to December 2027. Deliverable: gap report with product classification matrix and compliance roadmap.

    SBOM Implementation & Vulnerability Management

    Development of a comprehensive Software Bill of Materials (SBOM) in machine-readable formats such as CycloneDX or SPDX. We integrate SBOM generation into your CI/CD pipeline, establish automated vulnerability matching against CVE databases, and implement the vulnerability handling process required by the CRA throughout the entire support period (typically 5 years). This means that in the next Log4Shell-type situation, you can identify which products are affected within minutes. Deliverable: SBOM toolchain, vulnerability management process, policy for free security updates.

      Secure-by-Design & Secure-by-Default Consulting

      Integration of cybersecurity from the concept phase of your product development — not as a retrospective add-on. We establish threat modelling (STRIDE/PASTA), define security requirements for your architecture, implement secure default configurations (no weak default passwords, automatic security updates, minimal attack surface), and embed security gates into your development process. Deliverable: Secure Development Lifecycle (SDL) framework, threat modelling documentation, security requirements catalogue.

        Reporting Obligations & Incident Response (from September 2026)

        From 11 September 2026, manufacturers must report actively exploited vulnerabilities to the competent CSIRT authority and ENISA within 24 hours — with a follow-up report within 72 hours and a final report within 14 days. We build your reporting process, define escalation paths, create report templates for the ENISA platform, and train your team through tabletop exercises. This ensures you are operationally ready by the deadline. Deliverable: incident response playbook, report templates, escalation matrix, training delivery.

          Conformity Assessment & CE Marking

          Preparation and support throughout the entire conformity assessment procedure — from self-assessment for standard products, to assessment against harmonised standards (EN 303 645, IEC 62443) for Class I products, through to collaboration with notified bodies for Class II and critical products. We prepare the technical documentation, the EU declaration of conformity, and support the CE marking process. Deliverable: technical documentation in accordance with Annex VII, EU declaration of conformity, CE marking approval.

            CRA Training & Management Briefings

            Tailored workshops for management, product management, development, and procurement. Content: CRA requirements in detail, product classification based on your specific product range, obligations by role (manufacturer, importer, distributor), penalty risks (up to €15 million / 2.5% of turnover), distinction from NIS2 and the EU AI Act, and concrete next steps. For SMEs, we offer compact formats that address the relief measures provided for small companies under the CRA. Deliverable: workshop delivery, management summary, individual action plan.

              Our Competencies in Regulatory Compliance Management

              Choose the area that fits your requirements

              BSI CRA

              BSI oversees CRA conformity of digital products as market surveillance authority in Germany. Vulnerability reporting obligations begin September 2026, and all manufacturers must be fully compliant by December 2027. We guide you through every BSI CRA requirement.

              CRA Act

              The Cyber Resilience Act mandates cybersecurity standards for all manufacturers of digital products in the EU. Vulnerability reporting from September 2026, full compliance by December 2027. ADVISORI supports your gap analysis, SBOM creation and conformity assessment.

              CRA Audit

              Systematic CRA audits verify compliance with all Cyber Resilience Act requirements. From gap analysis through conformity assessment under Module A, B, C or H to market surveillance preparation — with a clear roadmap for the deadlines starting June 2026.

              CRA BSI

              From 2027, BSI will enforce CRA conformity for all digital products in Germany as the designated market surveillance authority. Spot checks, document audits and penalties up to EUR 15 million await non-compliant manufacturers. We prepare you for BSI inspections.

              CRA Certification

              CRA certification ensures conformity of your digital products with the Cyber Resilience Act. From self-assessment to third-party conformity assessment.

              CRA Compliance

              Complete CRA compliance for digital product manufacturers. From security by design through vulnerability management to CE marking. Deadline: December 2027.

              CRA Cyber Resilience Act Conformity Assessment

              CRA conformity assessment demonstrates your product meets all cybersecurity requirements. Different modules by risk class through to CE marking.

              CRA Cyber Resilience Act Germany

              The EU Cyber Resilience Act explained for the German market. From September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours. By December 2027, all digital products must be CRA-compliant. Learn how BSI enforces CRA requirements in Germany.

              CRA Cyber Resilience Act Market Surveillance

              BSI oversees CRA conformity as national market surveillance authority. Learn about inspection procedures, corrective actions and potential sanctions.

              CRA Cyber Resilience Act Product Security Requirements

              The EU Cyber Resilience Act (CRA) Annex I defines 13 mandatory product security requirements for digital products. From security by design to SBOM documentation and vulnerability handling — these requirements become mandatory from December 2027 for all manufacturers. ADVISORI supports you in fully implementing the Annex I obligations.

              Frequently Asked Questions about CRA Consulting — Cyber Resilience Act

              Which products fall under the Cyber Resilience Act?

              The CRA covers all products with digital elements placed on the EU market — hardware with network functions (smartphones, laptops, IoT sensors, smartwatches, connected toys, smart home devices, firewalls, smart meter gateways) and pure software products (operating systems, accounting software, mobile apps, computer games). The decisive factor is a direct or indirect network connection. Excluded are products already regulated elsewhere, such as medical devices (Medical Device Regulation), type-approved vehicles (UN ECE R155), defence products, and non-commercial open-source software. The CRA is product-based, not sector-based — traditional industrial companies or automotive suppliers may also be affected if they manufacture connected products or software components.

              What product classes exist and what do they mean?

              The CRA distinguishes four categories: Standard products (the large majority) require a self-assessment by the manufacturer. Important products Class I (e.g. password managers, VPN software, network management systems, browsers, SIEM systems) can be assessed via self-assessment against harmonised standards or through third-party review. Important products Class II (e.g. firewalls, IDS/IPS, hypervisors, operating systems, industrial control systems) mandatorily require assessment by a notified conformity assessment body. Critical products (e.g. smart meter gateways, hardware security modules, smart cards) require EU certification. The classification directly determines the effort and cost of the conformity assessment.

              What deadlines apply under the CRA?

              The CRA entered into force on

              10 December

              2024 (

              20 days after publication in the EU Official Journal on

              20 November 2024). Implementation is phased: From

              11 June 2026, conformity assessment bodies must be notified. From

              11 September 2026, reporting obligations apply — manufacturers must report actively exploited vulnerabilities and significant security incidents to ENISA within

              24 hours. From

              11 December 2027, all products newly placed on the market must fully comply with all CRA requirements — including conformity assessment, technical documentation, SBOM, and CE marking. Products already on the market before this date are grandfathered — but only at the level of individual product units, not entire product lines.

              Success Stories

              Discover how we support companies in their digital transformation

              Digitalization in Steel Trading

              Klöckner & Co

              Digital Transformation in Steel Trading

              Case Study
              Digitalisierung im Stahlhandel - Klöckner & Co

              Results

              Over 2 billion euros in annual revenue through digital channels
              Goal to achieve 60% of revenue online by 2022
              Improved customer satisfaction through automated processes

              AI-Powered Manufacturing Optimization

              Siemens

              Smart Manufacturing Solutions for Maximum Value Creation

              Case Study
              Case study image for AI-Powered Manufacturing Optimization

              Results

              Significant increase in production performance
              Reduction of downtime and production costs
              Improved sustainability through more efficient resource utilization

              AI Automation in Production

              Festo

              Intelligent Networking for Future-Proof Production Systems

              Case Study
              FESTO AI Case Study

              Results

              Improved production speed and flexibility
              Reduced manufacturing costs through more efficient resource utilization
              Increased customer satisfaction through personalized products

              Generative AI in Manufacturing

              Bosch

              AI Process Optimization for Improved Production Efficiency

              Case Study
              BOSCH KI-Prozessoptimierung für bessere Produktionseffizienz

              Results

              Reduction of AI application implementation time to just a few weeks
              Improvement in product quality through early defect detection
              Increased manufacturing efficiency through reduced downtime

              Let's

              Work Together!

              Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

              Your strategic success starts here

              Our clients trust our expertise in digital transformation, compliance, and risk management

              Ready for the next step?

              Schedule a strategic consultation with our experts now

              30 Minutes • Non-binding • Immediately available

              For optimal preparation of your strategy session:

              Your strategic goals and challenges
              Desired business outcomes and ROI expectations
              Current compliance and risk situation
              Stakeholders and decision-makers in the project

              Prefer direct contact?

              Direct hotline for decision-makers

              Strategic inquiries via email

              Detailed Project Inquiry

              For complex inquiries or if you want to provide specific information in advance

              ADVISORI Logo
              BlogCase StudiesAbout Us
              info@advisori.de+49 69 913 113-01