Free whitepaper · Cyber Resilience Act
The CRA Readiness Gap
From regulatory awareness to operational readiness. A concise, practical guide to what the EU Cyber Resilience Act means for your connected products — and how to close the gap before the obligations apply.

What you will learn
Six things every CRA-affected team needs to know
Reporting obligations apply from 11 September 2026. The whitepaper turns the regulation into a clear, actionable picture for your organisation.
01
Is your product in scope?
Typical in-scope products with digital elements — and the common exclusions.
02
How is it classified?
Default, Important Class I and II, Critical — and what each level demands.
03
Key CRA dates
In force 10 Dec 2024, reporting from 11 Sep 2026, main obligations 11 Dec 2027.
04
Who owns compliance?
How product, engineering, security, legal and management share the responsibility.
05
From regulation to evidence
An eight-step path: scope, classify, assess, secure, document, monitor, update, report.
06
Readiness checklist
Eleven questions to self-assess where your organisation stands today.
Questions
About the whitepaper
- Who is the whitepaper for?
- Manufacturers, importers and distributors of connected products — product managers, engineering leads, security and compliance teams, and management preparing for the Cyber Resilience Act.
- Is the whitepaper free?
- Yes. Fill in your name, email and organisation and the PDF downloads immediately. We also email you a copy of the link.
- When do CRA obligations apply?
- The CRA entered into force on 10 December 2024. Reporting of actively exploited vulnerabilities and serious incidents applies from 11 September 2026, and the main obligations from 11 December 2027.