Skip to content
REF · CRA · REG (EU) 2024/2847

24 hours is not long. We make you report-ready.

From 11.09.2026, manufacturers report actively exploited vulnerabilities to ENISA and the CSIRT within 24 hours. We check your exposure, arm your reporting chain, and prepare the funding application. You file it; the granting body decides.

Orientation, not evidence. Not legal advice. Pure SaaS is generally outside the CRA, and we tell you that first, not last.

TIMELINE

Two deadlines, one window.

11.09.2026

Reporting duty live: 24 h early warning, 72 h notification, via the central ENISA platform. That takes an EU Login and a practiced process.

11.12.2027

Full application: the complete Annex I duty catalog, technical documentation and CE marking included.

up to 50 %

Subsidy on preparation through state and EU programs, up to €7,500 in Hamburg and €15,000 in NRW. Fundable, not guaranteed: the grant belongs to the granting body.

WHO IS IN SCOPE

The honest question first: does the CRA even apply to you?

The CRA addresses whoever places products with digital elements on the EU market. We sort that out in the first step, not the last.

Manufacturers: yes

Devices with firmware, machines with controls, installable software, apps, IoT, connectors. Selling under your own name or substantially modifying a product also makes you the manufacturer. Importers and distributors carry verification duties.

Pure SaaS: generally no

Pure cloud services are generally outside the CRA. The exception is remote processing without which your product cannot fulfil its function. If you are pure SaaS, skip this page and look at C5 and NIS2. We say it that directly.

Buyers and operators: indirectly

No CRA duties of their own, but from now on the right questions for suppliers: SBOM, support period, reporting process. If you are in NIS2 scope you need those answers for your supply chain anyway.

METHOD

Experts lead the review. AI accelerates it. We ready you for oversight.

For the default category, manufacturers assess themselves. Important products of classes I and II and critical products need the notified body or certification, and that act belongs to them, not to us. Our field is everything before it: exposure, gaps, reporting chain, documentation, funding path.

  1. STEP · 01
    Classify

    Exposure, role and product category: default, important class I or II, critical. Plus the funding match: which program fits your location, size and project. Free in the Path Check.

  2. STEP · 02
    Arm

    Expert check with the SRP-Ready package: 24/72 reporting chain defined, roles named, EU Login set up, dry run documented. Then the readiness scan against the 13 product duties of Annex I: SBOM, update process, vulnerability disclosure, support period, technical documentation.

  3. STEP · 03
    Fund and hand over

    We prepare the funding application: service description, fundable line items, submission checklist. You file, the body decides. After the grant we close the gaps; for class I/II and critical products we escort you to the competent body.

Experts lead the review, highly specialized AI tooling accelerates it, we ready you for reporting duty and oversight. No tool alone achieves readiness, and a CRA certificate for the default category does not exist.

THE SHORT GUIDE

What the CRA actually asks of you.

The points most product teams get stuck on in the first pass.

Addressees: manufacturers, importers, distributors

The CRA obligates whoever places products with digital elements on the EU market. Operators and users carry no CRA duties of their own. Selling under your own name or substantially modifying a product moves you into the manufacturer role.

The SaaS line: remote processing decides

Pure cloud services are generally not covered. Covered is remote processing that is an integral part of a product, without which it cannot fulfil its function. That line is product-specific and belongs in an expert assessment, not in an assumption.

Reporting duties: the 24-hour chain

From 11.09.2026: early warning within 24 hours for actively exploited vulnerabilities and severe incidents, notification within 72 hours, final report after the fix is available or within one month. Reporting runs through the central ENISA platform, which requires an EU Login account and a practiced process.

Product duties from December 2027

Annex I requires, among other things, security by design, secure defaults, vulnerability handling across the support period, a software bill of materials (SBOM), coordinated vulnerability disclosure and technical documentation. For the default category the manufacturer assesses itself; important products of classes I and II and critical products need the notified body or certification.

The funding path: who pays for preparation

There is no CRA-specific funding money, but state and EU programs subsidize exactly the work the CRA demands: diagnosis, consulting, implementation. We deliver the fundable service and prepare your application, and we say openly that we do so also because we are then the named provider in it. You file, the body grants.

No certificate, watch the claims

There is no CRA certificate for the default category; nobody can sell you 'CRA-zertifiziert' today. A check result is orientation, not evidence. And nobody but the granting body can promise you a grant.

THE FUNDING PATH

Three pots, one principle: preparation does not have to come fully out of your pocket.

We keep the programs as maintained data, every figure with source and verification date. Fundable means the service fits the program. Funded means the body has granted. In between sits your application, and we prepare it.

HHVerified 22.08.2026

Hamburg Digital Check

IFB Hamburg
50 %Subsidy
up to €7,500

Antrag über das eAntragsportal der IFB

www.ifbhh.de
NWVerified 02.09.2026

MID Digitale Sicherheit

NRW.BANK / Land NRW
50 %Subsidy
up to €15,000 (min. €4,000)

Registrierung zur Verlosung, einmal je zwei Jahre

www.nrwbank.de
EUVerified 02.09.2026

SECURE / Secure4SME

EU Digital Europe Programme
50 %Subsidy
up to €30,000

Runde 1 geschlossen am 29.03.2026, weitere Runde angekündigt, Termin offen

www.secure4sme.eu
SAMPLE CALCULATION

Expert check with SRP-Ready package, €2,490. For a Hamburg SME, up to €1,245 of that can be subsidized via the Hamburg Digital Check. Fundable, not guaranteed: the IFB decides.

Not classic funding consultancy: we accompany only programs that finance our own service, and we disclose exactly that. You file the application. Without a grant the regular price applies, with no disadvantage.

From check to steady: four steps.

  1. 01
    Path Check

    Free, instant. Buys you clarity: in scope or not, which category is likely, which funding pot fits.

  2. 02
    Expert check + SRP-Ready

    Buys you reporting capability: the chain defined and rehearsed before the real case tests it. In Hamburg fundable at 50 %.

  3. 03
    Readiness sprint + remediation

    Buys you the duty catalog: scan against Annex I, prioritized action plan, gaps closed up to the handover.

  4. 04
    Care

    Buys you steadiness: vulnerability cycle, SBOM maintenance, deadline radar up to full application on 11.12.2027 and beyond.

READY?

Three minutes to your classification.

The Path Check tests exposure and role and shows which duties and programs fit your house. No account, no sales call.

A check result is orientation, not evidence, and replaces neither conformity assessment nor a funding decision.

Pure SaaS? Then C5 is your building site →