Cyber Resilience ACT

Make sure your organization complies with CRA requirements.
We offer everything from comprehensive programs to ongoing consulting on an hourly basis. 
Purchase a preliminary analysis starting at 10,000 DKK
Illustration of how security is incorporated from the design phase onward and continuously updated to ensure compliance with the Cyber Resilience Act

The Cyber Resilience Act sets requirements for cybersecurity in products with digital elements, including software, hardware, and connected products on the European market. These requirements cover, among other things, secure development, technical documentation, vulnerability management, security updates, and maintenance throughout the product’s lifecycle.

For businesses, this means that cybersecurity must be integrated into product development, processes, and documentation. We help you gain a clear understanding of the requirements and translate them into concrete measures that strengthen product security, reduce risks, and support continued access to the European market.

Implementation of the Cyber Resilience Act: From Start to Finish

Step 1

Preliminary Analysis  

The preliminary analysis provides a clear overview of how the Cyber Resilience Act affects your products, processes, and responsibilities.

We assess the organization’s current status and identify any gaps in relation to legal requirements. The result is a concrete assessment of which measures should be prioritized to strengthen product safety, reduce risks, and work toward CRA compliance.

Example of a preliminary analysis for organizations subject to the Cyber Resilience Act

Step 2

Documentation   

To comply with the Cyber Resilience Act, the organization must be able to document how cybersecurity is managed throughout the product's lifecycle.

We help you get a clear overview of the necessary documentation, including requirements for secure development, SBOMs, risk assessments, vulnerability management, security updates, and role assignments. Our focus is on creating documentation that supports compliance and can be used directly in your product development and operations.

Example of documentation to support an organization's compliance with the Cyber Resilience Act

Step 3

Course of Events   

The compliance process ensures that you have the necessary processes, security measures, and relevant documentation in place to comply with the requirements of the Cyber Resilience Act.

We help you translate these requirements into specific workflows for product development, risk assessment, vulnerability management, security updates, and technical documentation. The goal is to provide you with a documented basis for compliance and to enable you to maintain these processes throughout the product’s lifecycle.

Illustration of how to incorporate security throughout the product's entire lifecycle in accordance with the Cyber Resilience Act

Step 4

Awareness training and workshops 

CRA compliance requires that relevant employees understand their responsibilities regarding cybersecurity during product development, operation, and maintenance.

We offer awareness training and workshops that provide management, product teams, developers, and other key personnel with a practical understanding of the requirements of the Cyber Resilience Act. The content is tailored to your organization and helps foster greater security awareness, clear workflows, and a stronger foundation for maintaining CRA compliance over time.

Illustration of awareness training for employees in organizations seeking ISO 27001 certification

Step 5

Full Compliance 

Once the necessary measures and relevant documentation are in place, the organization will have a verifiable basis for complying with the requirements of the Cyber Resilience Act and maintaining its security efforts throughout the product’s lifecycle.

Compliance with the CRA requires ongoing monitoring, updating, and documentation. We can therefore help you establish an annual cycle that ensures processes, safety measures, and technical documentation are reviewed and updated over time. This strengthens compliance, product quality, and confidence in your products on the European market.

Annual cycle illustrating efforts to ensure compliance with the Cyber Resilience Act in organizations

Get help with the Cyber Resilience Act

Are you unsure how the Cyber Resilience Act affects your products and processes?

We’ll help you get a clear picture of the requirements and develop a concrete CRA plan tailored to your organization, products, and responsibilities.

Example of documentation demonstrating an organization's compliance with the Cyber Resilience Act

Consulting

Practical and effective—on the organization’s terms

Duration and Scope

Customized to the company's products, software environment, and regulatory requirements

Contents

Mapping of Digital Products and Software Components

Risk Assessment and Safety Requirements for Products

IT Security Policies and Procedures

"Secure-by-design" and "secure-by-default" principles

Prepares documentation for the company

Software Supply Chain and Third-Party Dependencies

Awareness training and workshops

Internal and External Compliance Checks

Expected output

Enhanced Security in the Development Process

Improved Management of Vulnerabilities and Incidents

Increased trust among customers and business partners

IT Security Policies and Procedures

Start with a no-obligation consultation with one of our experts, or purchase a preliminary analysis starting at 10,000 DKK

The First Step Toward CRA Compliance

Send us an email to schedule a free 15-minute review of your Cyber Resilience Act requirements with one of our cybersecurity experts. 

By submitting your email address, you agree to our privacy policy and consent to being contacted by nesp.ONE.

View upcoming courses and webinars

Learn how your company can strengthen cybersecurity and achieve compliance with standards such as ISO 27001, NIS2, and CRA.

NIS2 for management 

Copenhagen / August 26, 26

ISO 27001: Certificate Course

Copenhagen / September 2–3, 2026

NIS 2 in Practice

Odense / September 10–11, 2026

ISO 27001: Certificate Course

Copenhagen / Oct. 7–8, 2025

Guides and articles on the Cyber Resilience Act

View all blog posts

CRA-rapportering

8 september, 2026

CRA-rapportering fra 11. september: Sådan forbereder producenter de første 72 timer

CRA-rapportering starter 11. september 2026. Se frister, Single Reporting Platform og fem oplysninger, producenter skal have klar.

Frequently Asked Questions About the Cyber Resilience Act

Do you still have questions that weren't answered? Schedule a free 15-minute consultation with a cybersecurity expert

Book a free consultation

The Cyber Resilience Act(CRA) is an EU regulation that establishes binding cybersecurity requirements for products with digital components, including software and hardware. The purpose is to ensure that products are designed, developed, and maintained with security built in throughout their entire lifecycle. (Read more about the CRA: europa.eu)

The regulation sets requirements for risk assessment, secure development practices, vulnerability management, and ongoing security updates. 

Nesp.ONE advises companies on understanding and implementing CRA requirements in practice. 

The CRA covers manufacturers of products with digital elements that are marketed in the EU. This applies to both software and hardware manufacturers. 

In addition, importers and distributors may be liable if they place products on the EU market. Companies that integrate third-party components into their own products may also be responsible for overall compliance. 

At Nesp.ONE, we help clarify the scope and responsibilities related to the CRA. 

The CRA took effect in December 2024, and most of its requirements will be fully applicable starting in December 2027. 

Companies should start preparations well in advance, as implementing secure development, documentation, and vulnerability management processes can be extensive. 

Nesp.ONE helps companies plan and organize their compliance efforts leading up to 2027. 

CRA means that security must be systematically integrated throughout the entire software development process—from design and development to operation and maintenance. 

This includes risk assessment, secure-by-design/default principles, documentation, and establishing vulnerability management. 

Nesp.ONE helps development organizations implement these requirements through Secure SDLC. 

Secure SDLC is not explicitly mentioned in the regulation, but in practice, a structured and documented secure development process is necessary to comply with the requirements. 

CRA sets requirements for both the product's safety characteristics and the manufacturer's internal processes, which necessitates systematic management. 

At Nesp.ONE, we help companies establish a Secure SDLC as the foundation for CRA compliance. 

Consulting on CRA requires both an understanding of regulatory requirements and technical expertise in software development, risk management, and security architecture. 

Companies often choose advisors with experience in product compliance and safe development. 

Nesp.ONE offers specialized consulting services in both regulatory interpretation and technical implementation. 

Foranalyse – Cyber Resilience Act

Formålet med en Cyber Resilience Act-foranalyse er at vurdere, hvordan virksomhedens produkter med digitale elementer og tilhørende udviklings- og vedligeholdelsesprocesser lever op til kravene i Cyber Resilience Act, også kaldet CRA.
Analysen identificerer forskellen mellem virksomhedens nuværende praksis og de relevante krav til cybersikkerhed, sårbarhedshåndtering, dokumentation og produktoverensstemmelse. Analysens omfang tilpasses virksomhedens rolle og de produkter, der markedsføres i EU, og tager udgangspunkt i følgende områder:

1. Afgrænsning af produkter og virksomhedens rolle

Der foretages en kortlægning af virksomhedens produkter med digitale elementer, herunder software, hardware, komponenter og eventuelle fjernbehandlingsløsninger.
Det vurderes, om produkterne er omfattet af CRA, og om virksomheden har rollen som fabrikant, importør eller distributør. Der foretages desuden en indledende vurdering af, om produkterne er omfattet af særlige produktkategorier eller undtagelser.

2. Produktklassifikation og overensstemmelsesvurdering hændelser

An assessment is conducted of the company’s processes for handling cybersecurity incidents. The analysis includes, among other things, the company’s ability to identify, record, analyze, handle, and report security incidents, as well as ensure that lessons learned from incidents are used for continuous improvement.

3. Cybersikkerhedsrisikovurdering

Der vurderes, om virksomheden gennemfører og dokumenterer cybersikkerhedsrisikovurderinger for de omfattede produkter.
Analysen omfatter blandt andet produktets funktion, forventede anvendelse, angrebsflade, databehandling, eksterne grænseflader, afhængigheder og mulige konsekvenser for brugere og andre systemer. 

4. Security by design og security by default

Der foretages en vurdering af, om cybersikkerhed indgår systematisk i produktets design, udvikling og standardkonfiguration.
Dette omfatter blandt andet sikker arkitektur, begrænsning af angrebsfladen, sikre standardindstillinger, adgangskontrol, autentificering, beskyttelse af data, logning og modstandsdygtighed over for kendte angrebsformer.

5. Sikker udviklingsproces

Der vurderes, om virksomheden har etableret en struktureret og dokumenteret proces for sikker produktudvikling.
Analysen omfatter blandt andet sikkerhedskrav, trusselsmodellering, kodegennemgang, ændringsstyring, test, styring af udviklingsmiljøer og godkendelse af sikkerhedsrelevante ændringer før frigivelse.

6. Softwarekomponenter og forsyningskæde

Der foretages en vurdering af virksomhedens styring af tredjepartskomponenter, open source-software og øvrige afhængigheder i produktet.
Analysen omfatter blandt andet overblik over komponenter, kontrol med kendte sårbarheder, leverandørkrav, versionsstyring og etablering og vedligeholdelse af en software bill of materials (SBOM), hvor dette er relevant.

7. Sårbarhedshåndtering

Der vurderes, om virksomheden har etableret processer for at identificere, modtage, analysere, prioritere og afhjælpe sårbarheder gennem produktets supportperiode.

8. Sikkerhedsopdateringer og supportperiode

Der foretages en vurdering af virksomhedens processer for udvikling, distribution og installation af sikkerhedsopdateringer.
Analysen omfatter blandt andet fastlæggelse og dokumentation af produktets supportperiode, rettidig håndtering af sårbarheder, sikker distribution af opdateringer og tydelig information til brugerne om tilgængelige opdateringer og ophør af support.

9. Håndtering og rapportering af hændelser og sårbarheder

Der vurderes, om virksomheden har etableret processer, roller og kommunikationsveje til håndtering og rapportering af aktivt udnyttede sårbarheder og alvorlige sikkerhedshændelser.
Analysen omfatter blandt andet intern eskalation, indsamling af nødvendige oplysninger, overholdelse af rapporteringsfrister og koordinering mellem produktudvikling, ledelse, juridiske funktioner og relevante myndigheder.

10. Teknisk dokumentation og brugerinformation

Der foretages en vurdering af, om virksomheden kan udarbejde og vedligeholde den dokumentation, der er nødvendig for at demonstrere produktets overensstemmelse med CRA.
Dette omfatter blandt andet produktbeskrivelse, cybersikkerhedsrisikovurdering, design- og udviklingsinformation, testresultater, håndtering af sårbarheder, supportperiode og instruktioner til sikker installation, anvendelse og vedligeholdelse.

Cyber Resilience Act foranalyserapport

På baggrund af foranalysen modtager virksomheden en rapport med en vurdering af de omfattede produkter og virksomhedens nuværende modenhed inden for sikker produktudvikling, sårbarhedshåndtering og dokumentation.
Rapporten identificerer mangler i forhold til relevante CRA-krav og indeholder en prioriteret handlingsplan. Den giver virksomheden et klart grundlag for at styrke produktsikkerheden, etablere de nødvendige processer og arbejde målrettet frem mod overensstemmelsesvurdering og CE-mærkning.
Preliminary analysis starting at 10,000 DKK. Contact us