What we do / Products

Cyber Resilience Act

What is the Cyber Resilience Act

CRA is a landmark EU regulation to improve the cybersecurity for “products with digital elements”, including IoT devices. Its primary goal is to ensure that all digital products meet essential cybersecurity requirements throughout their lifecycle, protecting consumers and businesses from cyber threats. Starting in 2027, products that don’t comply will face heavy fines and restricted market access, meaning CRA compliance is not just a legal requirement – it’s a competitive advantage.

Contact

A fully tailored approach to CRA compliance

At QRTECH we provide a tailored approach from initial audits and gap analysis to secure implementation. Our service ensures long-term compliance management throughout the product lifecycle with continuous updates, vulnerability patching, and proactive documentation.

An efficient process to CRA compliance for existing IoT products

Critically, existing products on the market also need to comply with CRA vulnerability management requirements and updates. Thanks to our long experience and expertise within the IoT space for both hardware, software and cloud solutions we stand ready to assist all our existing and potential customers with their compliance needs. Here’s an overview of our CRA compliance process:

ISO 27001 – a testament to our commitment to security

Our ISO 27001:2022 certification sets us apart as a trusted partner, ensuring that our processes, systems, and services meet the highest global standards for information security. The certification is:

  • a guarantee that we handle your data and projects with the utmost care and security.
  • a perfectly complement to the Cyber Resilience Act’s (CRA) requirements, ensuring a seamless path to compliance.

1. Initial CRA assessment
Conducting a comprehensive security assessment of the product’s current architecture and components and identify potential vulnerabilities or compliance gaps.

2. CRA implementation, remediation & security updates
Implementing required updates and modifications to meet CRA standards, including firmware patches, enhanced access controls, and secure configuration management.

3. Documentation & reporting
Assisting and guiding with all necessary CRA documentation, including risk assessments, SBOM and conformity declarations for regulatory compliance.

4. Ongoing vulnerability patching
Continuous proactive patching and updates to maintain compliance.

5. Annual CRA audits and compliance checks
Regular security audits and assessments to ensure that products continue to meet evolving CRA standards.

6. Providing 3rd line of support
Dedicated support for incident management response and reporting to comply with CRA requirements.

Why partner with us on CRA compliance?

Our proven expertise in IoT and security, ensures a seamless and effective journey to compliance for both existing and new products. We offer an efficient, cost-effective pathway tailored to meet CRA requirements, minimizing disruptions and maximizing value. Also, our commitment extends beyond initial compliance, as we support long-term product integrity and security through comprehensive AM/SLA agreements, fostering a reliable partnership dedicated to sustaining your CRA compliance over time.

Download our CRA checklist

Is your product ready? Does it protect data integrity and confidentiality? Are your communications encrypted to meet industry standards? Do you have robust systems for vulnerability management and updates?

Our CRA compliance checklist is designed to help you assess your product’s
readiness, address potential gaps, and start on the path to full CRA compliance.

CRA-Checklist

Your path to CRA compliance starts here

That transition period to full CRA compliance has started. Ready to secure your product line and protect your customers? And avoid those hefty fines? Connect with us today to start your CRA compliance journey.

Contact

Contact

Anders Lembing

Anders Lembing

Business Area Manager / Embedded systems