CRA gap analysis
We classify your products (default, important class I/II, critical), map them against Annex I and deliver a prioritised roadmap.
EU Cyber Resilience Act
The Cyber Resilience Act sets mandatory cybersecurity requirements for every hardware and software product with digital elements sold in the EU. We help manufacturers close the gaps with consulting, testing and a secure development lifecycle that fits your teams.
In short
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to design them securely, handle vulnerabilities for the product’s support period and report actively exploited vulnerabilities. Reporting obligations apply from 11 September 2026; all other requirements apply from 11 December 2027. Zyberum provides CRA gap analyses, secure development lifecycle implementation, vulnerability handling processes and penetration testing.
Timeline
The CRA was published and entered into force. The transition period started.
Rules for notified bodies apply, so third-party assessments can be prepared.
Actively exploited vulnerabilities and severe incidents must be reported to ENISA and the CSIRT within 24 hours (early warning).
All essential requirements apply. Products without CE marking under the CRA can no longer be placed on the EU market.
Our services
We classify your products (default, important class I/II, critical), map them against Annex I and deliver a prioritised roadmap.
Security requirements, threat modelling, secure coding and code review integrated into your existing development process.
Independent security testing of devices, firmware, apps and cloud interfaces to find and fix vulnerabilities before market launch.
Coordinated vulnerability disclosure, PSIRT processes and 24h/72h reporting workflows for ENISA.
Software bill of materials, technical documentation and EU declaration of conformity prepared for audits.
Training for product owners and developers so CRA requirements become part of everyday engineering.
Why Zyberum
Our team combines extensive experience in product security with a deep understanding of EU regulation. We have implemented similar frameworks in automotive (UN R155, ISO/SAE 21434) and industry (IEC 62443), and we test products ourselves instead of only writing policies.
The result: compliance work that engineers accept, evidence that holds up in an assessment, and fewer vulnerabilities in the field.
FAQ
Almost all hardware and software products with digital elements that are placed on the EU market and can connect to a device or network: IoT devices, industrial controllers, routers, apps and desktop software. Some sectors with their own rules, such as medical devices, motor vehicles and aviation, are excluded.
Reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026. All other requirements, including CE marking under the CRA, apply from 11 December 2027.
Up to €15 million or 2.5% of worldwide annual turnover, whichever is higher, for violations of the essential requirements. Market surveillance authorities can also order non-compliant products to be withdrawn.
Most products can be self-assessed. Important products of class II and critical products need a notified body or a certification scheme, and class I products need one if harmonised standards are not fully applied.
Get started
One hour with a CRA expert: we classify your product and show you what is missing before December 2027.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy