Home > CRA compliance support
The Cyber Resilience Act imposes cybersecurity requirements on products containing digital components that are made available on the European market.
Software, applications, components, connected devices and embedded systems must incorporate security from the design stage and throughout their support lifecycle.
The analysis must be carried out on a product-by-product basis, taking into account each product’s function, how it is marketed and the role played by your company.
Manufacturers and publishers bear the main responsibilities. Other operators in the value chain must also verify, document and cooperate.
Secure design, vulnerability management, documentation and compliance assessment.
Carrying out tasks assigned by a manufacturer based outside the European Union.
Verification of the compliance of products placed on the European market.
Checking of information, labelling and the conditions under which the product is made available.
A structured approach that combines regulatory compliance, cybersecurity and knowledge of product processes.
Self-assessment, third-party assessment or certification, depending on the product category and the applicable conditions.
Hardware and software products containing digital components, marketed in the European Union and connected directly or indirectly to a device or a network.
Yes. A publisher that develops software or commissions its development and markets it under its own name or brand may be regarded as a manufacturer.
A standalone SaaS solution does not automatically fall within the scope of the CRA. However, a remote processing solution that is essential to the operation of a product may fall within its scope.
No. The procedure depends on the product’s classification. Certain important or critical products require the involvement of a notified body or an applicable certification scheme.
Netsystem prepares the company, the product and the evidence. Where a third-party assessment is required, it must be carried out by an authorised body.
The PASSI certification is issued by the National Cybersecurity Agency (ANSSI).
It is aimed at trusted service providers who carry out organisational and physical security audits, as well as technical audits, either on their own behalf or on behalf of their clients.
This is a genuine mark of quality and expertise for organisations seeking a cybersecurity consultancy to carry out an audit of their organisation.
The CRA presents a fantastic opportunity for manufacturers and software publishers to make cybersecurity a genuine quality feature of their products. This regulation goes beyond a mere compliance requirement or the need to obtain CE marking: it requires security to be integrated throughout the product’s lifecycle, from design right through to the management of updates and vulnerabilities. At NETSYSTEM, we support our clients from the initial feasibility analysis and classification of their products right through to the preparation of the conformity assessment. Our approach combines regulatory expertise, cybersecurity and knowledge of development processes to translate the CRA’s requirements into concrete actions: Security by Design, risk analysis, SBOM, vulnerability management, technical documentation and the compilation of evidence. For us, the CRA represents an opportunity to build lasting trust in digital products. Our role is to help companies chart a pragmatic course, tailored to their products, their stage of development and their market challenges, from the initial assessment right through to preparing for compliance.
Vincent FERRARA, Head of Digital Trust practice
To find out more about our CRA audit and compliance support services, please do not hesitate to contact us. We are here to help you secure your digital journey and turn cybersecurity challenges into genuine opportunities for growth.