EU Cyber Resilience Act
Cyber Resilience Act. From obligation to operational readiness.
The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for products with digital elements throughout their lifecycle.
- 1Hardware and softwareProducts with digital elements
- 2Architecture and engineeringWhere secure-by-design is built in
- 3ComponentsThird-party and open-source software
- 4Libraries and other dependenciesPart of the software supply chain
Responsibilities run through the whole product lifecycle
- Design
- Development
- Deployment
- Vulnerability handling
- Ongoing support
Who it affects
For organisations developing, manufacturing or supplying hardware and software into the EU market, cybersecurity is increasingly a product requirement, not simply an IT responsibility.
Cyvian helps organisations understand their CRA obligations, assess readiness and implement practical measures across product development, vulnerability management, supply chains and incident reporting.
Nine services in four areas
How Cyvian can help
Assess. Remediate. Evidence. Maintain. Choose an area to read the full description of each service in it.
Assess · 3 services
Understand what applies and where your product stands.
CRA Applicability & Readiness
Understand which products may fall within scope, organisational responsibilities and applicable requirements.
CRA Gap Assessment
Assess current product security practices and controls against relevant CRA requirements.
Product Cyber Risk Assessment
Identify cybersecurity risks associated with products and their intended use throughout the lifecycle.
Remediate · 2 services
Strengthen product security and understand software dependencies.
Secure-by-Design & Secure-by-Default
Integrate appropriate cybersecurity principles into product architecture, engineering and development processes.
Software Supply Chain
Understand cybersecurity risks associated with third-party software, open-source components, libraries and other dependencies.
Evidence · 2 services
Organise the evidence and prepare for conformity assessment.
Technical Documentation & Evidence
Develop and organise the cybersecurity evidence required to demonstrate how applicable CRA requirements have been addressed.
Conformity Readiness
Support preparation for the appropriate conformity assessment route, EU declaration of conformity and CE-marking requirements.
Maintain · 2 services
Support vulnerability management and reporting throughout the product lifecycle.
Vulnerability Management
Establish processes for identifying, assessing, remediating and documenting vulnerabilities throughout the product support period.
Incident & Vulnerability Reporting
Develop operational processes to identify, escalate and support mandatory CRA reporting requirements.
These areas group the services to help you find the right support. They are not a prescribed compliance route.
Assess. Remediate. Evidence. Maintain.
CRA isn't a one-off compliance exercise.
The Cyber Resilience Act introduces cybersecurity responsibilities throughout the lifecycle of a digital product, from design and development through deployment, vulnerability handling and ongoing support.
Cyvian brings together cybersecurity, governance and technology experience to help organisations build those requirements into the way products are developed and managed.
Talk to Cyvian about CRA readinessYour enquiry opens with this topic selected. You can change it before sending.
Continue exploring