About the CRA
The Cyber Resilience Act aims to improve the cybersecurity of products with digital elements. For SMEs, this can create new responsibilities around secure development, documentation, vulnerability handling, and customer communication. CRA-COMP explains these requirements in accessible language and helps SMEs take practical first steps.
What is the CRA?
A European regulation that sets cybersecurity requirements for products with digital elements throughout their lifecycle.
Why was it created?
To make products with digital elements more secure by reducing vulnerabilities, improving transparency, and ensuring cybersecurity is considered throughout the product lifecycle.
Who is affected?
Manufacturers, importers, distributors and other economic operators of digital products.
What does the CRA mean for SMEs?
For SMEs, the CRA means understanding whether your products are affected, what role your organization plays, and what security responsibilities must be managed over time.
Product Scope
Identify whether your product is affected by the CRA.
Organization Role
Understand whether you act as a manufacturer, importer, distributor, or integrator.
Security Measures
Assess risks and apply appropriate technical and organizational measures.
Vulnerability Handling
Prepare processes to identify, manage, and communicate vulnerabilities.
Documentation
Keep clear records of compliance decisions, security controls, and product information.
Customer Communication
Provide users with clear information about updates, support periods, and security responsibilities.
The CRA-COMP Project
CRA-COMP supports SMEs with simple guidance, practical tools, awareness materials, and templates to achieve CRA compliance.
Our Objectives
- Understand what the CRA is
- Identify whether you are affected
- Understand your responsibilities
- Apply practical cybersecurity measures
- Prepare useful documentation
- Communicate clearly with customers
- Strengthen cyber resilience
- Connect with European support
Key CRA Questions for SMEs
These questions help SMEs understand their possible CRA responsibilities.
What is the CRA?
The Cyber Resilience Act is a European regulation for the cybersecurity of products with digital elements.
Am I affected?
You may be affected if you develop, manufacture, import, distribute, integrate, or sell digital products.
How strongly am I affected?
This depends on your role, product type, product criticality, supply-chain position, and customer context.
What do I need to do?
Start by identifying risks, documenting security decisions, preparing customer information, and setting up vulnerability handling.
How do I communicate this to customers?
Explain security features, updates, responsibilities, support periods, and residual risks in clear language.