// CRA readiness
Cyber Resilience Act (CRA) & Product Security Readiness
We work with you to establish the classification of your products with digital elements under EU Regulation 2024/2847 (CRA), review compliance with essential cybersecurity requirements, and prepare your technical documentation, SBOM, and vulnerability handling workflows. The advisory and technical audit service is delivered by SKOPION Intelligence; the specialized evaluation and evidence tool we work with is CRASteps.
Tool and service
CRASteps is the tool we use to structure risk categories under Annexes III and IV, verify Annex I essential requirements, record software components and SBOMs, and uncover conformity gaps prior to CE marking. The technical assessment, threat modeling, and remediation roadmap are the SKOPION Intelligence service. A tool replaces neither manufacturer conformity assessment nor the assessment of a Notified Body.
CRAStepsHow it runs
- 01Product classification: Scoping and categorisation (Default, Important Class I/II, Critical products with digital elements).
- 02Requirements review: Evaluation against Annex I Part I essential cybersecurity requirements (secure by design, integrity, confidentiality).
- 03SBOM & vulnerability handling: Supply chain analysis, Software Bill of Materials (SBOM) review, and 24h vulnerability notification readiness under Annex I Part II.
- 04Gap analysis & documentation: Review of technical documentation under Annex VII and selection of the conformity assessment module.
- 05Executive briefing: Delivery of an actionable remediation and hardening roadmap ahead of statutory enforcement dates.
What you receive
- A documented and reasoned product classification under Regulation (EU) 2024/2847.
- A structured gap analysis comparing requirements, design decisions, and available evidence.
- A specific vulnerability handling and SBOM governance assessment with identified risk priorities.
- A step-by-step action roadmap for technical documentation and CE marking.
- A technical assessment report in English, German, or Polish.
What this is not
- Not a certification issued by a Notified Body for Class II or critical products.
- Not formal legal counsel; the EU Declaration of Conformity remains the statutory responsibility of the manufacturer.
- Not an automated surface scan without product architectural verification.
- Does not transfer manufacturer, importer, or distributor statutory liability.
Discuss CRA readiness
The starting point is a scoped conversation about your product portfolio and engineering lifecycle — no self-service sign-up. Contact us through the form using the topic “CRA Readiness (Cyber Resilience Act)”.
Request a conversationSKOPION Intelligence · tool: CRASteps · not a notified body