Writing · 27 August 2026

EU Cyber Resilience Act Preparation

Planning and preparation for implementers of the EU Cyber Resilience Act

What EU CRA means for businesses

In an environment of narrow and voluntary product security frameworks and regulations, the EU Cyber Resilience Act presents a step change for businesses deploying connected products into the European Union.

Compliance becomes a gatekeeper for access to the market, and the only exclusions are for product categories that are already heavily regulated.

This presents unique challenges for many businesses which, until now, have faced no mandatory minimum product security standards. The shift in obligations means businesses will be grappling with complex security topics in areas where they lack prior experience and in-house expertise.

While large organisations make up the substantial majority of revenue for impacted products, this doesn’t tell the full story. Because of the wide net EU CRA casts, and the minimal carve outs, it is estimated that 99% of all impacted businesses are small and medium sized.

The organisations that succeed will be those that adopt a structured approach to the regulation through genuine improvement of their product security and resilience. Technical excellence alone will not be enough. Operational preparedness is a central pillar of the requirements, and client procurement pressures will necessitate meaningful evidence gathering activity.

How businesses approach alignment to the Cyber Resilience Act will determine not only initial success in adhering to it, but how effectively they can meet its demands into the future.


Principal actions for successful compliance

Understand how much of your product catalogue is affected

The regulations capture a broad horizontal segment of products, but this doesn’t necessarily mean that an entire business’s product catalogue will fall under the regulations.

Product inventory already placed on the market before 11 December 2027 and some special categories of products (e.g., aviation, medical) are exempt.

It’s also important to understand that the scope of EU CRA may in some cases be broader and capture more than an organisation anticipates. For example, if an organisation imports or distributes someone else’s white-labelled products under its own name, then it inherits the full set of obligations for those products.

The pre-11 December 2027 carve out only applies to individual units, not a product type. And any substantial modification to those units after the date brings them into scope.

Seek leadership buy-in

An EU Cyber Resilience Act compliance project requires clear planning and resourcing. The regulations require review of, and potential changes to, many areas of a business, from product design to software development, legal counsel, and customer service.

Gaining leadership buy-in from decision makers is vital for effective execution of organisation readiness. Without this support, coordinating a compliance programme becomes inefficient and fragmented. Necessary resource goes unallocated, timescales are stretched and compliance is put at risk.

Identify internal stakeholders

Understanding and assigning internal responsibilities for teams and individuals when planning a compliance programme is key to operational success. It must be clear who within a business owns the strategic implementation, and who is accountable for each tranche of compliance.

Consider how centralised compliance execution should be. The 24-hour notification window for vulnerability exploitation and severe incidents mandated by EU CRA necessitates rapid internal communication and coordination. Even with sufficient planning, the reporting timescales require clarity from everyone on the role that they play. A RACI matrix can be a useful framework for achieving such clarity.

Understand where compliance is already met

Much of the regulation formalises best practices in secure product design, development, and operations. As a result, businesses that have well established development and security programmes will already be implementing many of the requirements.

An organisation must understand its current compliance position before embarking on any roll out of new practices or documentation. By assessing each area of the requirements against existing business practice, more efficient and coordinated implementation plans can be presented to leadership sponsors.

Triage and plan remediation

If European Standards organisations haven’t published formal implementation guidance when a business comes to plan EU CRA compliance, advice from the European Commission is clear: do not wait.

There is no single correct path to compliance, and essential requirements are listed clearly in the regulation’s annexes. Businesses that have completed an assessment of their current product security posture should begin planning their remediation programme, and look to analogous established security frameworks to guide their implementations.


Turn EU CRA into a business asset

The regulation should not be framed merely as a box ticking exercise. The requirements are rigorous, but also lean enough to allow compliance activities to become transformative for a business’s product security.

Organisations will come out of the process with capabilities that genuinely strengthen operational confidence in incident response, while solidifying product competitiveness during the sales process, and improving client relationships in the face of ever more thorough cyber scrutiny.


Gauge your readiness

Ask the right questions from the start to set up for success.

  • Do you have a complete catalogue of the products going into the EU market, and do you have enough information to hand to classify them?
  • Could you produce a machine-readable software bill of materials for your products on the market without starting a project for it?
  • If you became aware of an actively exploited vulnerability in your product Friday afternoon, who would be filing the notification before the end of Saturday?
  • Do you have a named owner for delivering EU CRA, with a defined budget?
  • Do your products have a published end of support date and has providing security updates until then been costed?
  • If asked tomorrow, could you assemble the required technical product documentation from what your engineering team already produces?

Where to start

Build your compliance programme so that evidence of your product security comes from what the business already does.

Bedrock Cyber supports organisations in planning for and delivering EU CRA compliance with processes that generate proof without additional burden.

Start a conversation


Looking to go deeper? Find examples of compliance readiness activities and a pathway outline in Bedrock Cyber’s EU CRA Factsheet.

Where to start

What are you being asked to prove?