Skip to content

CYBER RESILIENCE ACT

For manufacturers of products with digital elements. IEC 62443-4-1 proves how you build; the CRA governs what you must show the market. We map the two, name the gap, and hand you the evidence — before the clock runs out.

If your product has digital elements and carries a CE mark, the Cyber Resilience Act now applies to you. The obligations are not a policy PDF — they are demonstrated, evidenced, audited processes. IEC 62443-4-1 proves how you build; the CRA governs what you must show the market. Most teams discover the gap between the two too late.

The compliance clock is already running

Sept 2026

Reporting duties apply

24-hour early warning and 72-hour notification for actively exploited vulnerabilities and severe incidents — including products already on the market.

Dec 2027

The CRA applies in full

CE marking will require demonstrated cybersecurity: technical documentation, conformity assessment, and an EU declaration of conformity.

And your customers are asking earlier than the law does.

Where IEC 62443-4-1 stops, the CRA begins.

The standard audits your secure-development lifecycle — the process, the gates, the evidence. The CRA adds market-facing obligations the standard never covers: incident and vulnerability reporting, a coordinated-disclosure policy, a defensible support period, SBOM and third-party component duties, and the technical-documentation-to-CE conformity route. That seam between the standard and the regulation is where the audit finding lands — and no single framework governs both sides of it. Naming that gap, and closing it with evidence, is the work.

The standard audits how you build. The regulation audits what you place on the market. No single framework governs the seam between them — that seam is where the finding lands, and closing it with evidence is the work.

Every practice of IEC 62443-4-1

SM

Security Management

SR

Security Requirements

SD

Secure by Design

SI

Secure Implementation

SVV

Verification & Validation

DM

Defect Management

SUM

Secure Update Management

SG

Security Guidelines

Procedures, templates, and evidence registers behind every one.

Beyond the standard — the CRA obligations

Reporting playbook (Art. 14)

Who does what inside the 24-hour and 72-hour windows — for products already placed on the market, not just new ones.

PSIRT & coordinated disclosure

A public vulnerability-disclosure policy and the internal process that stands behind it.

Support-period policy

A defensible end-of-support definition and the security-update commitment that follows from it.

SBOM & third-party due diligence

Component inventory (CycloneDX/SPDX), known-vulnerability handling, and supplier obligations — the supply-chain surface the CRA makes yours.

Technical docs → EU declaration → CE

The conformity route mapped: technical documentation, conformity assessment, declaration of conformity, CE marking.

Engagements — how you buy

Entry point

CRA Gap Briefing

$2,500 – 3,500

90 minutes and a written memo: where your product stands against the Sept 2026 reporting duties and the Dec 2027 conformity deadline, and the three gaps that carry the most exposure.

Flagship · fixed scope

CRA Readiness Assessment

$18,000 – 35,000

Your product assessed across its full threat surface and mapped requirement-by-requirement to IEC 62443-4-1 and the CRA. Deliverable: the gap between standard and regulation named, a prioritised remediation plan, and the evidence you'll be asked for.

Productized documents

CRA Readiness Pack

from $12,000

The audit-ready document set — the SDLC standard, one procedure per 62443-4-1 practice, the CRA pack (reporting, PSIRT, support policy, SBOM, CE route), templates, and traceability registers — tailored to your products and roles. You adopt and run it instead of writing it. Weeks, not a year.

Ongoing

Advisory Retainer

$6,000 – 12,000 / mo

A standing capability through the compliance window: reporting-duty readiness, vulnerability-handling on call, and a rolling assessment as the harmonised standards land.

Who it's for

  • Machine builders and industrial-equipment manufacturers (CE-marked products with digital elements)
  • IoT, embedded, and connected-device makers
  • Software and firmware vendors placing products on the EU market
  • Component suppliers carrying SBOM and third-party obligations upstream
  • Manufacturers already building to IEC 62443-4-1 who have not mapped it to the CRA

Click one — we'll route you. None fit? Describe it below.

Start the inquiry

Five fields. We do the rest.

A person reads every inquiry and replies within one business day. Engagements are invoiced by CM & Co Consulting Group AB (Sweden).

See Strategic Advisory (FTSA)