Cyber Resilience Act Readiness for Software and Device Makers
Product classification, Annex I gap analysis, SBOM, technical file and the 24-hour reporting playbook, delivered by people who test software for a living. Then a named PSIRT seat so the reporting duty has an owner. New to the law? Start with our plain-language guide to the CRA regulation.
Gap assessment EUR 8,900. Readiness from EUR 26,000. PSIRT seat EUR 2,300 per month. Fixed.

Why Manufacturers Are Starting Now
The reporting clock starts before the rest of the law
From 11 September 2026 every manufacturer must report an actively exploited vulnerability to ENISA within 24 hours, with a 72-hour notification and a 14-day final report. That obligation arrives fifteen months before the essential requirements, and it hits companies that have not started any conformity work.
Nobody can tell you which class your product is in
Default products self-assess. Important class I products self-assess only if harmonised standards exist, and none are cited yet. Class II needs a notified body, and as of June 2026 none has been designated. You need a route for both outcomes, decided now.
Security debt becomes strict liability
The revised Product Liability Directive applies to products placed on the market from 9 December 2026. Software is a product, a missing security update is a defect, and CRA non-conformity is prima facie evidence of one. The SBOM and the update policy stop being paperwork and become the defence.


What the CRA Requires of a Product
Annex I sets the security properties the product must have and the vulnerability handling process the manufacturer must run. Annex II sets what users must be told. Annex VII sets the technical documentation. Together they are a security programme for the product, not a certificate, and they apply for as long as the product is supported.



The 24-Hour Clock Starts on 11 September 2026
Article 14 requires an early warning to the ENISA Single Reporting Platform within 24 hours of becoming aware of an actively exploited vulnerability, a fuller notification within 72 hours, and a final report within 14 days. Severe incidents follow the same shape with a one-month final report. The platform routes the report to the CSIRT of the country where you have your main establishment.
Twenty-four hours is not enough time to decide who decides. The playbook we deliver names the person who classifies, the person who files, the evidence they need and the wording of each report, and we drill it with your engineers against a real vulnerability from your own backlog.
If you do not want to staff that seat, we hold it: the single point of contact under Article 13(17), the ENISA account and the on-call decision, on a fixed monthly fee.
Who the CRA Binds

Compared With the Usual Offer
| Atlant Security | Typical offer | |
|---|---|---|
| Honesty about classes | We tell you when a notified body is unavoidable and plan for it | A checklist that assumes self-assessment for everything |
| Evidence | Findings from the code, pipeline and a penetration test | A policy pack with the word CRA inserted |
| Reporting | The 24-hour clock drilled before September 2026, decision rights agreed | A template in a folder |
| After the project | A named single point of contact and PSIRT seat on a monthly fee | Consultant gone, reporting duty unowned |
| Pricing | Published, fixed, per product family | Quoted after the free consultation |
How CRA Readiness Works
Scope and classify
Every product with digital elements listed, placed into default, important class I or II, or critical, with the conformity route and the notified-body question answered for each.
Gap analysis
Annex I requirements and Annex II information duties assessed against the product and the development process, with evidence from the code, the build pipeline and a security test, not from a questionnaire.
Remediation and documentation
SBOM generation in the build, secure update mechanism, coordinated disclosure policy, support period statement, risk assessment and the technical file assembled in the Annex VII structure.
Reporting readiness and hand-off
ENISA platform account, the 24-hour playbook drilled with your engineers, then either your own PSIRT runs it or we hold the single point of contact seat for you.

Pricing
Fixed prices per product family, scoped in writing before we start. Notified body fees, where a class II product needs one, are charged by the body and are separate.
Gap Assessment and Reporting Playbook
Three weeks. Answers the classification question and makes you ready for 11 September 2026.
- Product inventory and written classification
- Annex I and II gap report, graded
- Article 14 reporting playbook and decision rights
- ENISA Single Reporting Platform onboarding
- One reporting drill with your engineers
Full CRA Readiness
One product family, from scoping to the technical file and declaration of conformity.
- Everything in the gap assessment
- Security test of the product and its update mechanism
- SBOM generated in the build pipeline
- Coordinated disclosure policy and support statement
- Annex VII technical file and declaration of conformity
- Notified body preparation where required
PSIRT and Single Point of Contact Seat
The reporting duty, owned. 12-month term, quarterly exit.
- Named single point of contact under Article 13(17)
- Vulnerability triage and the 24-hour classification decision
- ENISA reports drafted and filed
- Disclosure handling with researchers and customers
- Quarterly vulnerability handling report to management
Know Your Class Before the Clock Starts
A free classification call tells you which of your products are in scope, which class they fall into and what 11 September 2026 means for you. Thirty minutes, no slides.
Book the Classification Call