Hamburg Digital Check
Antrag über das eAntragsportal der IFB
www.ifbhh.deFrom 11.09.2026, manufacturers report actively exploited vulnerabilities to ENISA and the CSIRT within 24 hours. We check your exposure, arm your reporting chain, and prepare the funding application. You file it; the granting body decides.
Orientation, not evidence. Not legal advice. Pure SaaS is generally outside the CRA, and we tell you that first, not last.
Reporting duty live: 24 h early warning, 72 h notification, via the central ENISA platform. That takes an EU Login and a practiced process.
Full application: the complete Annex I duty catalog, technical documentation and CE marking included.
Subsidy on preparation through state and EU programs, up to €7,500 in Hamburg and €15,000 in NRW. Fundable, not guaranteed: the grant belongs to the granting body.
The CRA addresses whoever places products with digital elements on the EU market. We sort that out in the first step, not the last.
Devices with firmware, machines with controls, installable software, apps, IoT, connectors. Selling under your own name or substantially modifying a product also makes you the manufacturer. Importers and distributors carry verification duties.
Pure cloud services are generally outside the CRA. The exception is remote processing without which your product cannot fulfil its function. If you are pure SaaS, skip this page and look at C5 and NIS2. We say it that directly.
No CRA duties of their own, but from now on the right questions for suppliers: SBOM, support period, reporting process. If you are in NIS2 scope you need those answers for your supply chain anyway.
For the default category, manufacturers assess themselves. Important products of classes I and II and critical products need the notified body or certification, and that act belongs to them, not to us. Our field is everything before it: exposure, gaps, reporting chain, documentation, funding path.
Exposure, role and product category: default, important class I or II, critical. Plus the funding match: which program fits your location, size and project. Free in the Path Check.
Expert check with the SRP-Ready package: 24/72 reporting chain defined, roles named, EU Login set up, dry run documented. Then the readiness scan against the 13 product duties of Annex I: SBOM, update process, vulnerability disclosure, support period, technical documentation.
We prepare the funding application: service description, fundable line items, submission checklist. You file, the body decides. After the grant we close the gaps; for class I/II and critical products we escort you to the competent body.
Experts lead the review, highly specialized AI tooling accelerates it, we ready you for reporting duty and oversight. No tool alone achieves readiness, and a CRA certificate for the default category does not exist.
The points most product teams get stuck on in the first pass.
The CRA obligates whoever places products with digital elements on the EU market. Operators and users carry no CRA duties of their own. Selling under your own name or substantially modifying a product moves you into the manufacturer role.
Pure cloud services are generally not covered. Covered is remote processing that is an integral part of a product, without which it cannot fulfil its function. That line is product-specific and belongs in an expert assessment, not in an assumption.
From 11.09.2026: early warning within 24 hours for actively exploited vulnerabilities and severe incidents, notification within 72 hours, final report after the fix is available or within one month. Reporting runs through the central ENISA platform, which requires an EU Login account and a practiced process.
Annex I requires, among other things, security by design, secure defaults, vulnerability handling across the support period, a software bill of materials (SBOM), coordinated vulnerability disclosure and technical documentation. For the default category the manufacturer assesses itself; important products of classes I and II and critical products need the notified body or certification.
There is no CRA-specific funding money, but state and EU programs subsidize exactly the work the CRA demands: diagnosis, consulting, implementation. We deliver the fundable service and prepare your application, and we say openly that we do so also because we are then the named provider in it. You file, the body grants.
There is no CRA certificate for the default category; nobody can sell you 'CRA-zertifiziert' today. A check result is orientation, not evidence. And nobody but the granting body can promise you a grant.
We keep the programs as maintained data, every figure with source and verification date. Fundable means the service fits the program. Funded means the body has granted. In between sits your application, and we prepare it.
Antrag über das eAntragsportal der IFB
www.ifbhh.deRegistrierung zur Verlosung, einmal je zwei Jahre
www.nrwbank.deRunde 1 geschlossen am 29.03.2026, weitere Runde angekündigt, Termin offen
www.secure4sme.euExpert check with SRP-Ready package, €2,490. For a Hamburg SME, up to €1,245 of that can be subsidized via the Hamburg Digital Check. Fundable, not guaranteed: the IFB decides.
Not classic funding consultancy: we accompany only programs that finance our own service, and we disclose exactly that. You file the application. Without a grant the regular price applies, with no disadvantage.
Free, instant. Buys you clarity: in scope or not, which category is likely, which funding pot fits.
Buys you reporting capability: the chain defined and rehearsed before the real case tests it. In Hamburg fundable at 50 %.
Buys you the duty catalog: scan against Annex I, prioritized action plan, gaps closed up to the handover.
Buys you steadiness: vulnerability cycle, SBOM maintenance, deadline radar up to full application on 11.12.2027 and beyond.
The Path Check tests exposure and role and shows which duties and programs fit your house. No account, no sales call.
A check result is orientation, not evidence, and replaces neither conformity assessment nor a funding decision.