Initial review

CRA Snapshot: what the product covers, and what cannot yet be shown.

There is usually something already there: architecture notes, test results, review minutes, scattered across repositories and mailboxes. The Snapshot gathers them and separates the material that would hold up in front of a customer or a regulator from what is still only an assertion.

01 Fit

When this service fits

When you need a first, shared picture of a product with digital elements. It suits manufacturers, and also importers and distributors who first want to establish their role and starting point.

02 Scope

What we review

What the CRA is, and who it applies to

The Cyber Resilience Act is Regulation (EU) 2024/2847: EU cybersecurity requirements for products rather than for organisations. It applies directly, without a national implementing act, and binds the manufacturer, the importer and the distributor, each to a different extent.

A product with digital elements is, under art. 3(1), a software or hardware product together with its remote data processing solutions, including components placed on the market separately. The definition is deliberately broad: it covers an industrial controller and a library sold on its own alike.

Annex I splits the requirements in two: Part I concerns the properties of the product itself, and Part II concerns vulnerability handling across the whole support period, including drawing up an SBOM. Part II is the one that surprises people, because it does not end on launch day.

Dates: the obligation to report actively exploited vulnerabilities applies from 11 September 2026, and full application together with CE marking from 11 December 2027.

Source: Regulation (EU) 2024/2847, art. 3(1), art. 71, Annex I. Whether a given product is in scope, and in which class, requires an individual analysis; we are not a notified body.

What the review covers

  • Whether the product is a product with digital elements and what your role is: manufacturer, importer, distributor or authorised representative.
  • Possible exclusions and the classification: default product, important product or critical product.
  • Gaps against the requirements of Annex I: product properties and vulnerability handling.
  • Readiness to report actively exploited vulnerabilities and severe incidents (art. 14).
  • The software bill of materials (SBOM), the support period and the update process.
  • Technical documentation towards CE marking, as far as it is visible in the materials provided.

03 Result

What decision the result supports

The result is a structured decision: what is already supported, what cannot yet be demonstrated and where to begin.

04 Inputs

What to prepare

  • A short description of the product, its digital functions and architecture.
  • The available security documentation and customer requirements.
  • An SBOM and vulnerability and update procedures, if they already exist.

05 Terms

How scope and quotation are set

Scope and quotation depend on the number of products, the material available and the conversations required. We establish both after a short scoping call.

06 Limits

What falls outside the scope

This is not a conformity assessment, certification or a guarantee of compliance. The manufacturer is responsible for the declaration of conformity and CE marking; for some product classes the assessment is carried out by a notified body, which we are not. Standards such as IEC 62443 or ISO/IEC 27001 we treat as good practice and as mapping to requirements, not as an automatic guarantee of CRA compliance.

07 Process

Signal → review → evidence → decision

Signal

What raised the CRA question for your product?

Review

What is fact and what is a claim in the materials?

Evidence

What can already be demonstrated safely?

Decision

Where to begin and what to defer?

08 Questions

Questions before starting

  • Does this replace conformity assessment? No. It is a shared picture of readiness that the later work starts from.
  • How many products does it cover? We establish that after a short scoping call, depending on the material available.
  • What if we have no SBOM or procedures yet? That is common; establishing the starting point is exactly the point.

09 Contact

Discuss the CRA Snapshot scope

A few sentences about the product and situation are enough to begin; we will refine the scope of the first shared picture of readiness together.

Talk to us

Source: Regulation (EU) 2024/2847. Editorial review: CZ Cybersecurity sp. z o.o. Content reviewed: 21 July 2026.