EU Cyber Resilience Act
Get CRA-ready, without losing the overview.
The Cyber Resilience Act makes cybersecurity mandatory for every product with digital elements. The SwissGRC® Platform brings your CRA processes together in one place, so you stay ready to provide evidence at any time.
Timeline
Two 2026 deadlines that matter now
Many assume everything happens in 2027. Wrong. The first obligation takes effect in September 2026, and it applies to every manufacturer.
Notified bodies are designated
EU member states designate accredited conformity assessment bodies. No immediate action is needed for standard-category products that use self-declaration. Manufacturers of Class I and II products should make contact now to get ahead of capacity bottlenecks.
Reporting obligations for vulnerabilities and incidents
The central and most immediate obligation. Actively exploited vulnerabilities and severe security incidents must be reported to the national CSIRT authority and ENISA within strict deadlines:
- 24 hearly warning to CSIRT and ENISA
- 72 hmore detailed follow-up report
- 14 daysfinal report after update or workaround
- 30 daysfinal report for severe incidents
The full timeline at a glance
Classification
The four product categories
The CRA classifies products by risk. The category determines whether self-declaration is enough or a notified body has to assess.
Standard category
Ordinary business software, consumer electronics and standard IoT devices.
Class I: important products
Password managers, antivirus software, VPNs, firewalls, browsers.
Class II: critical products
Network management systems, industrial controls, smart meter gateways.
Critical core products
A very small group with the strictest requirements.
Unsure which category your products fall into? Take our free CRA gap analysis further down this page. Six questions give you an initial read on your readiness, anonymous and with no sign-up.
Requirements
The core technical obligations
The CRA requires cybersecurity to be built in and evidenced across the entire product lifecycle. Five obligations are central.
Security by design and default
Security from the start: secure default settings, no universal passwords, minimal attack surfaces, encrypted data.
Vulnerability management
Security updates for at least five years, plus a PSIRT process that handles vulnerabilities across the lifecycle.
Software Bill of Materials
A complete, current inventory of all software components per product, including third-party and open source.
Technical documentation and CE
From the end of 2027, affected products need an EU declaration of conformity and CE marking. Without them, no EU import.
Resilience and incident containment
Products must withstand attacks. Manufacturers must contain incidents quickly and inform users.
Whitepaper
Cyber Resilience Act: what Swiss manufacturers must do now
A hands-on guide from Swiss Infosec AG and Swiss GRC. All deadlines, the four product categories and a concrete roadmap up to September 2026.
Cyber Resilience Act: what Swiss manufacturers must do now
From the applicability analysis through the four product categories to a concrete roadmap up to September 2026.
- All deadlines and reporting obligations at a glance
- The four product categories and what they mean
- A prioritised roadmap for development teams
- Penalties and the EU representative mandate explained
Download for free
Please leave your details. The download appears immediately and is also sent to you by email. The whitepaper is written in German.
Thank you, your whitepaper is ready
The download starts via the button below. A copy of the link is also in your inbox. The whitepaper is in German.
Open whitepaper (PDF)Nothing opened? Click here directly.
Free gap analysis
How CRA-ready is your product security?
A self-assessment based on the ENISA maturity model for SMEs: 25 questions across five areas. You get a maturity level per area and overall right away, anonymous and with no sign-up.
Based on the ENISA SME Cyber Resilience Maturity Assessment Model. A self-assessment that does not replace a product-specific risk assessment, legal analysis or formal CRA conformity assessment.
For each question, pick the description closest to your current practice. There is no right or wrong, just an honest baseline.
Ergebnis
Request the detailed report and action checklist
Optional. We send a structured evaluation with your per-area maturity and a prioritised action checklist to your email. Your answers stay anonymous until you request the report.
Thank you. Your report is on its way and will arrive in your inbox shortly.
The gap analysis is a non-binding self-assessment based on the ENISA maturity model and does not replace a product-specific risk assessment, legal analysis or formal CRA conformity assessment.
The platform's role
Structure and evidence for your CRA compliance
The CRA requires not only a secure product but also robust processes and complete evidence. This is exactly where the SwissGRC® Platform comes in.
Applicability and scoping
Capture your portfolio, assign each product to a risk class, record the action needed. The analysis becomes a trackable action plan.
Risk management and ISMS
Assess and manage product risks in an integrated data model. Many CRA requirements map to ISO 27001 controls you already cover here.
Vulnerabilities and reporting
Map your PSIRT process and manage the tight reporting deadlines (24h, 72h, 14 days) with clear roles and a complete history.
SBOM at governance level
Link your SBOM to products and risks. When a component becomes vulnerable, you see at once which products are affected.
Technical documentation
Risk analyses, measures and conformity records in one place, versioned and retrievable at any time.
CRA, NIS2 and DORA combined
CRA, NIS2 and DORA in one platform. You produce evidence once, not three times.
Frequently asked questions
Understanding the CRA
The key questions on the Cyber Resilience Act, with a particular focus on Swiss manufacturers and the upcoming national legislation.
What is the Cyber Resilience Act (CRA)?
Does the CRA also apply to Swiss companies?
What deadlines apply in 2026 and 2027?
What are the reporting deadlines for vulnerabilities and incidents?
Which product category does my product fall into?
What are the penalties for non-compliance?
Is Switzerland introducing its own law?
How does the SwissGRC® Platform support CRA compliance?
11 September 2026 is coming. Prepare in a structured way.
See how you manage applicability, vulnerabilities, reporting processes and technical documentation with the SwissGRC® Platform. Or start with the whitepaper from Swiss Infosec AG and Swiss GRC.
DE