CRA Audit and Compliance

Ensure your products comply with the Cyber Resilience Act

CYBER RESILIENCE ACT

Cybersecurity is becoming a product requirement

The Cyber Resilience Act imposes cybersecurity requirements on products containing digital components that are made available on the European market.

Software, applications, components, connected devices and embedded systems must incorporate security from the design stage and throughout their support lifecycle.

The analysis must be carried out on a product-by-product basis, taking into account each product’s function, how it is marketed and the role played by your company.

DATES TO NOTE
  • Since 11 September 2026
    • Notification of actively exploited vulnerabilities and serious incidents.
  • 11.12.2027
    • Implementation of the key requirements of the Regulation.
COMPANIES AFFECTED

Four stakeholders, distinct obligations

Manufacturers and publishers bear the main responsibilities. Other operators in the value chain must also verify, document and cooperate.

01

Manufacturers
and publishers

Secure design, vulnerability management, documentation and compliance assessment.

02

Agents

Carrying out tasks assigned by a manufacturer based outside the European Union.

03

Importers

Verification of the compliance of products placed on the European market.

04

Distributors

Checking of information, labelling and the conditions under which the product is made available.

NETSYSTEM SUPPORT

From assessment to preparing for compliance

A structured approach that combines regulatory compliance, cybersecurity and knowledge of product processes.

01

Frame

Scope, the organisation’s role, product classification, applicable requirements and compliance strategy.
02

Ensure compliance

Security by Design, secure development, vulnerabilities, updates, support and reporting.
03

Gathering evidence

Risk analysis, technical documentation, SBOM, procedures and supporting evidence.
04

Preparing for the assessment

Safety testing, compliance documentation and assistance with third-party arrangements where necessary.
Scope of the assignment

An overview of regulatory, cyber and product matters

Your deliverables

  • Applicability note and product mapping
  • Classification analysis and applicable requirements
  • Gap analysis and maturity level
  • Technical Testing Plan
  • List of evidence to be provided
  • Prioritised action plan and CRA roadmap
  • Preparatory dossier for conformity assessment
Compliance assessment

The classification determines the route

Self-assessment, third-party assessment or certification, depending on the product category and the applicable conditions.

01
Important · classe I
Self-assessment subject to certain conditions or involving a third party.
02
Important · classe II
Third-party intervention.
03
Critical
Certification or enhanced assessment.
04
Others products
Self-assessment may be possible in certain cases.
CYBER RESILIENCE ACT

Understanding
the CRA

Which products are covered by the CRA?

Hardware and software products containing digital components, marketed in the European Union and connected directly or indirectly to a device or a network.

Are software publishers affected?

Yes. A publisher that develops software or commissions its development and markets it under its own name or brand may be regarded as a manufacturer.

Are SaaS solutions affected?

A standalone SaaS solution does not automatically fall within the scope of the CRA. However, a remote processing solution that is essential to the operation of a product may fall within its scope.

Is self-assessment always possible?

No. The procedure depends on the product’s classification. Certain important or critical products require the involvement of a notified body or an applicable certification scheme.

Does Netsystem issue a CRA certificate?

Netsystem prepares the company, the product and the evidence. Where a third-party assessment is required, it must be carried out by an authorised body.

Netsystem is PASSI-certified

The PASSI certification is issued by the National Cybersecurity Agency (ANSSI).

It is aimed at trusted service providers who carry out organisational and physical security audits, as well as technical audits, either on their own behalf or on behalf of their clients.

This is a genuine mark of quality and expertise for organisations seeking a cybersecurity consultancy to carry out an audit of their organisation.

Why choose Netsystem?

The CRA presents a fantastic opportunity for manufacturers and software publishers to make cybersecurity a genuine quality feature of their products. This regulation goes beyond a mere compliance requirement or the need to obtain CE marking: it requires security to be integrated throughout the product’s lifecycle, from design right through to the management of updates and vulnerabilities. At NETSYSTEM, we support our clients from the initial feasibility analysis and classification of their products right through to the preparation of the conformity assessment. Our approach combines regulatory expertise, cybersecurity and knowledge of development processes to translate the CRA’s requirements into concrete actions: Security by Design, risk analysis, SBOM, vulnerability management, technical documentation and the compilation of evidence. For us, the CRA represents an opportunity to build lasting trust in digital products. Our role is to help companies chart a pragmatic course, tailored to their products, their stage of development and their market challenges, from the initial assessment right through to preparing for compliance.

Let’s discuss your products and draw up your CRA roadmap.

To find out more about our CRA audit and compliance support services, please do not hesitate to contact us. We are here to help you secure your digital journey and turn cybersecurity challenges into genuine opportunities for growth.