Skip to content
CRA Navigator

Regulation (EU) 2024/2847

Every connected product you sell in the EU now needs a security case.

CRA Navigator helps manufacturers of products with digital elements work out exactly what the Cyber Resilience Act requires, close the gaps against IEC 62443-4-1, and assemble the evidence a notified body will ask for.

2027
Full CRA application · 11 December
2026
Vulnerability reporting starts · 11 September
8
IEC 62443-4-1 practices audited for certification
15M
Maximum penalty in EUR, or 2.5% of global turnover
Macro view of an industrial embedded controller circuit board

Compliance clock

Days until reporting obligations apply · 11 Sep 2026
Days until full application · 11 Dec 2027

How we work

Two tracks that reinforce each other

The CRA sets the legal obligation. IEC 62443-4-1 gives you the process discipline and the audit trail to demonstrate it. Most manufacturers need both, sequenced properly.

Track A · Regulation

Cyber Resilience Act conformity

Determine your product class, meet the Annex I essential requirements, and build the technical documentation that supports CE marking and the EU declaration of conformity.

  • 01Scope and classification against Annex III and Annex IV
  • 02Annex I Part I product security requirements
  • 03Annex I Part II vulnerability handling processes
  • 04SBOM generation, depth, and maintenance
  • 05Coordinated vulnerability disclosure policy
  • 0624-hour and 72-hour reporting workflow to ENISA and CSIRTs
  • 07Support period definition and security update delivery
  • 08Conformity assessment route and notified body engagement
Read the CRA breakdown

Track B · Standard

IEC 62443-4-1 certification preparation

Build a secure development lifecycle that stands up to third-party audit, using the standard that harmonised European requirements lean on most heavily for process evidence.

  • 01Maturity level target setting and audit scoping
  • 02Security management and development environment controls
  • 03Threat modelling and secure design reviews
  • 04Secure coding standards and implementation review
  • 05Verification, validation, and penetration testing regimes
  • 06Security issue management and update delivery processes
  • 07Evidence packs, records, and traceability
  • 08Audit dry-run and certification body liaison
Read the certification guide

Engagement model

From questionnaire to declaration of conformity

  1. 01

    Assess

    You complete the relevant questionnaire. Answers are scored against regulatory text and standard clauses, producing a gap list with severity and effort estimates.

  2. 02

    Scope

    We confirm your product classification, the applicable conformity assessment route, and whether a notified body is mandatory for your class.

  3. 03

    Remediate

    A sequenced plan closes process gaps first, since evidence takes time to accumulate. Technical product gaps follow, tied to your release calendar.

  4. 04

    Evidence

    Threat models, test records, SBOMs, disclosure policy, and update procedures are assembled into the technical documentation an auditor will request.

  5. 05

    Certify

    We run an audit dry-run against IEC 62443-4-1, close findings, and support you through the certification body engagement and declaration of conformity.

Assessment 01

CRA Readiness Assessment

A structured self-assessment against the essential cybersecurity requirements in Annex I of Regulation (EU) 2024/2847, plus the vulnerability handling and reporting obligations that apply from September 2026.

Length
12–18 minutes
Questions
48 questions
Built for
Product security officers, compliance leads, engineering managers

Prefer to check scope first? Run the four-minute classification check.

Questionnaire not connected

CRA Readiness Assessment is ready for its Tally form

This section will render the live questionnaire as soon as a Tally form ID is supplied. The embed, loading behaviour, and dynamic height handling are already wired up.

  1. 01Build the questionnaire at tally.so using the question outline listed on this page.
  2. 02Copy the ID from the share link — for tally.so/r/wA1b2C the ID is wA1b2C.
  3. 03Paste it into lib/site.ts under TALLY_FORMS The form goes live immediately.

Not sure which track applies to your product?

Send us the product category and target markets. We will tell you the likely CRA class and whether IEC 62443-4-1 certification is worth pursuing in your case.

Get in touch