The essentials

The CRA targets products with digital elements placed on the European market. A company that develops solely for its own internal use does not necessarily occupy the same role as a manufacturer, an importer or a distributor.

1. Qualify the product and the economic role

The scope must identify software, hardware, associated remote processing, components distributed separately, the target market and the actors in the chain. Exclusions and special cases are documented product by product.

2. Build risk into product decisions

The risk analysis drives architecture, default configuration, authentication, data protection, attack-surface reduction and the criteria for placing on the market. It evolves with the threats and with changes to the product.

3. Control components and the support period

The component inventory, vulnerabilities, patches, open source dependencies, update channels and the support period must be consistent with the commitments given to users.

4. Prepare the reporting before the incident

Detection, qualification, decisions and the gathering of the necessary information must make it possible to meet the applicable deadlines without improvising the chain of responsibility at the moment of an exploited vulnerability.

5. Build the file as delivery progresses

Technical documentation, user information, conformity assessment, changes and evidence must be produced together with the product. Reconstructing the history after the fact increases both risk and cost.

Assess your CRA readiness Qualify a product