Cyber Resilience Act
CRA — from component register to compliance in 3 months.
The Cyber Resilience Act applies to virtually every product with digital elements that you place on the EU market. With PRISM ISO you build your component register, set up the vulnerability management process and establish the reporting path for actively exploited vulnerabilities — systematically instead of scattered across spreadsheets. 200+ organisations already manage their evidence in PRISM.
Why now
- • Reporting obligation for actively exploited vulnerabilities from 11 September 2026 — the process must be in place
- • Customer or supply chain asking for SBOM or CRA declaration of conformity?
- • New product with digital elements in planning or close to market launch?
Regulation (EU) 2024/2847 has been in force since 10 December 2024. Reporting deadlines — 24-hour early warning, 72-hour notification for actively exploited vulnerabilities — apply from 11 September 2026; full security requirements from 11 December 2027. Manufacturers, importers and distributors of products with digital elements are affected.
What PRISM brings to the CRA
- Component/SBOM register: all software and hardware components of your product structured and captured
- Gap analysis against CRA security requirements (Annex I) — current status in under 2 hours
- Vulnerability management process with owners, deadlines and evidence
- Reporting process for actively exploited vulnerabilities — 24-hour early warning and 72-hour notification as documented workflow
- Multi-framework crosswalk: fulfill CRA controls and ISO 27001 or NIS 2 in one pass
- Auditor directly bookable (PRISM Certified)
Vulnerability & Compliance Tracking
CRA compliance structured — from gap analysis to evidence.
The Cyber Resilience Act requires vulnerability tracking, SBOM, incident reporting and secure update processes. PRISM ISO maps these requirements as executable measures — with audit-proof documentation for market surveillance authorities and notified bodies.
Who is this for?
Yes, if
- You develop or distribute software or hardware with digital elements
- Product owner, CISO or CTO — without a dedicated product security department
- Customer request for SBOM or CRA conformity as trigger
- Goal: component register and reporting process established within a few months
Not suitable
- Large enterprises with their own product security team and GRC stack (Archer, ServiceNow)
- Pure consulting relationship without software use
Many CRA-obliged companies are also required under ISO 27001 or NIS 2 — with the integrated crosswalk you fulfil multiple standards without double effort.
Frequently Asked Questions about the Cyber Resilience Act (CRA)
- What is the Cyber Resilience Act?
- The EU Cyber Resilience Act (CRA) is a regulation that establishes horizontal cybersecurity requirements for products with digital elements — from networked devices to software products. It applies fully from October 2027 and affects manufacturers, importers and distributors who place products on the EU market.
- Am I affected by the CRA?
- If you place hardware or software with a network connection or data interface on the EU market, you are very likely affected. Exceptions include open-source software without commercial use and certain special sectors (medical devices, aviation). Critical Class I and Class II products are subject to stricter requirements.
- What do I need to demonstrate specifically?
- The CRA requires: secure product development (Secure-by-Design), vulnerability tracking and remediation throughout the entire product lifecycle, SBOM (Software Bill of Materials), reporting of actively exploited vulnerabilities within 24 hours to ENISA, updateability and support obligations (at least 5 years). PRISM ISO maps these requirements as executable controls.
- When does the CRA come into force?
- The CRA entered into force in December 2024. Transition periods: vulnerability reporting from December 2026, full application from October 2027. Starting the gap analysis now provides sufficient time for a structured implementation.
- How does PRISM ISO help with the CRA?
- PRISM ISO structures the CRA requirements as executable controls — gap analysis, action plan, evidence documentation and internal audit. The multi-framework crosswalk automatically transfers controls that you already fulfil for ISO 27001 or NIS 2 to the CRA.
Software alone — or with consultant and auditor?
Three tiers, one goal: your Cyber Resilience Act (CRA) evidence. From the licence to a fixed-price package including an auditor.
So geht PRISM vor
Von der Lücke bis zum laufenden Betrieb.
Vier Phasen, eine Plattform — kein Wechsel zwischen Tools, keine Lücken zwischen Phasen.
Wo stehen Sie heute?
PRISM bewertet Ihre bestehenden Dokumente, Prozesse und Kontrollen gegen alle Anforderungen der CRA. Jede Lücke kommt mit Begründung und direktem Link zur Maßnahme — kein manuelles Zusammensuchen.
Was unsere Kunden sagen
„Der Security Health Check war sehr effizient und zielführend und half uns, Transparenz zu schaffen."
Johannes Beier
IT-Leiter · B2B Medical
Security Health CheckTrusted by
CRA compliance in 3 months.
In the initial call we clarify concretely which CRA requirements apply to your product.