Initial review

CRA Snapshot: what the product covers, and what cannot yet be shown.

We organise the available materials, declarations and gaps, so the team knows which decisions need attention first.

01 Fit

When this service fits

When you need a first, shared picture of a product with digital elements, rather than a full conformity assessment. It suits manufacturers, and also importers and distributors who first want to establish their role and starting point.

02 Scope

What we review

  • Whether the product is a product with digital elements and what your role is: manufacturer, importer, distributor or authorised representative.
  • Possible exclusions and the classification: default product, important product or critical product.
  • Gaps against the requirements of Annex I: product properties and vulnerability handling.
  • Readiness to report actively exploited vulnerabilities and severe incidents (art. 14).
  • The software bill of materials (SBOM), the support period and the update process.
  • Technical documentation towards CE marking, as far as it is visible in the materials provided.

03 Result

What decision the result supports

The result is a structured decision: what is already supported, what cannot yet be demonstrated and where to begin.

04 Inputs

What to prepare

  • A short description of the product, its digital functions and architecture.
  • The available security documentation and customer requirements.
  • An SBOM and vulnerability and update procedures, if they already exist.

05 Terms

How scope and quotation are set

Scope and quotation depend on the number of products, the material available and the conversations required. We establish both after a short scoping call.

06 Limits

What this service does not replace

This is not a conformity assessment, certification or a guarantee of compliance. The manufacturer is responsible for the declaration of conformity and CE marking; for some product classes the assessment is carried out by a notified body, which we are not. Standards such as IEC 62443 or ISO/IEC 27001 we treat as good practice and as mapping to requirements, not as an automatic guarantee of CRA compliance.

07 Process

Signal → review → evidence → decision

Signal

What raised the CRA question for your product?

Review

What is fact and what is a claim in the materials?

Evidence

What can already be demonstrated safely?

Decision

Where to begin and what to defer?

08 Questions

Questions before starting

  • Does this replace conformity assessment? No. It is a shared picture of readiness that the later work starts from.
  • How many products does it cover? We establish that after a short scoping call, depending on the material available.
  • What if we have no SBOM or procedures yet? That is common; establishing the starting point is exactly the point.

09 Contact

Discuss the CRA Snapshot scope

A few sentences about the product and situation are enough to begin; we will refine the scope of the first shared picture of readiness together.

Discuss your product

Source: Regulation (EU) 2024/2847. Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.