Determine your product’s category (Default, Class I, Class II) and define the relevant threat and risk profile (TARA).
Review your current development practices against CRA requirements and receive a prioritized remediation plan. Get expert support in preparing technical documentation for CRA submission.
Validate product resilience through security testing, including penetration testing, fuzzing, and vulnerability analysis. Strengthen product security with targeted hardening strategies.
Gain clarity on security certification requirements for your product. Align CRA activities with other standards like SESIP, IEC 62443, and RED to streamline certification efforts and reduce duplication.
We help you meet EU Cyber Resilience Act requirements with minimal disruption.
Address security gaps early to reduce future threats and avoid development delays.
Get expert support to efficiently compile technical files and meet CRA reporting requirements.
Integrate CRA with other certifications under one streamlined roadmap to save time and resources. Leverage Keysight’s global security expertise and recognized accreditations.
Learn what the EU Cyber Resilience Act means for products with digital elements, the key timelines, and how organizations can prepare. This webinar covers the essentials, practical steps, and case studies to help you understand CRA requirements.
Products with Digital Elements (PDEs), including software, firmware, cloud systems, and SDKs.
Yes, if they’re likely to be used in a connected context. For example, USB sticks are not connected out of the box but contain firmware and are meant to be connected. Similarly, smart TVs contain embedded firmware and network capability.
Yes. Standalone software is explicitly covered, even if it’s not pre-installed on hardware.
Yes, if still being sold or updated after 11 Dec 2027.
The CRA impacts a broad range of stakeholders involved in the design, development, and distribution of products with digital elements: manufacturers, authorized representatives, importers, distributors, software developers, and startups.
Risk assessments, implementing secure-by-design, vulnerability handling, conformity assessments, technical documentation, and updates.
TARA results, SBOM, update strategy, conformity details, and vulnerability procedures.
Varies by risk category: self-assessment for low risk, Notified Body for higher risk.
Partially—they help, but don’t automatically fulfill all CRA obligations.
A Notified Body, an independent third-party organization designated by an EU Member State, provides an independent evaluation for Important II and Critical products. Notified Bodies must be accredited and listed in the NANDO (New Approach Notified and Designated Organizations) database.
Manufacturers of lower-risk products (Default or Important Class I) usually don’t need a Notified Body unless they opt for third-party assessment.
You risk fines, product bans, reputational harm, and can’t apply the CE mark. Fines and enforcement actions may vary depending on the severity of the breach.
Compliance is required for CE marking of digital products in the EU.
Yes—they must appoint an authorized representative established in the EU and fully meet CRA requirements before market placement.
Start by classifying your product (Default, Important, or Critical), as this defines whether you need a self-assessment or a Notified Body. Conduct a gap analysis to check your current security and compliance against CRA requirements, including secure design, risk management, and documentation. Then, build a roadmap with clear responsibilities and timelines. Use readiness tools like SBOM generators, risk templates, SDL checklists, and training resources. Keysight supports you every step of the way, from product scoping to CE marking, helping you stay compliant without slowing innovation or time-to-market.
Our experts regularly share practical insights in our blog. Explore the latest developments on the Cyber Resilience Act.
What are you looking for?