CRA

CRA compliance, secure by design and by default

The CRA makes cybersecurity a condition of the EU market, held across the whole support period you declare, not only at launch. Secrato keeps the risk assessment, controls and evidence connected to the requirements they answer, so readiness holds as long as the product does.

GDPR BY DESIGN
HOSTED IN BELGIUM
EU DATA SOVEREIGNTY
ENTERPRISE-GRADE SECURITY
RISK MANAGEMENT MEASURES

Govern vulnerability handling continuously

Maintain vulnerability-handling procedures as owned, reviewable records rather than one-time documentation. Connect operational steps to the controls they implement and the risks they address.

IEC 62443 compliance evidence organisation
INCIDENT REPORTING

Keep reporting evidence ready

Connect evidence directly to the controls and records that support vulnerability and incident reporting. Keep information organised before reporting deadlines arise, reducing the need to reconstruct supporting records under time pressure.

GOVERNANCE & ACCOUNTABILITY

Connect product risk to readiness

Tie cybersecurity risks to the controls that treat them from design through maintenance. Give product and security teams visibility into risk posture, compliance status and findings from one connected environment.

Digital checklists for continuous environmental compliance monitoring
THE REST OF THE PLATFORM

More ways Secrato supports CRA

Beyond the core outcomes above, these capabilities support the wider CRA programme.

Compliance Engine

Manage requirements, controls, evidence, policies and status together, giving teams a current view of where implementation stands.

Procedure Management

Document and review the procedures that support CRA controls, policies and risks so implementation is backed by maintained operational detail.

Assessments

Structure assessment work around requirements and controls, with responses connected to the supporting evidence and records.

Audit Hub

Organise evidence, review control readiness and manage findings, with structured reviewer access where appropriate.

API and integrations

Connect internal and external systems through APIs and integrations to support evidence collection and reduce manual chasing.

Global Governance

Apply group-level governance decisions across workspaces while allowing approved local variations where required.

SUPPORTED FRAMEWORKS

One control. Multiple frameworks.

Many of the CRA’s process requirements overlap with cybersecurity controls already maintained for ISO 27001 or NIS2. The Unified Control Library lets teams reuse that shared control work across the relevant requirements, while product-specific cybersecurity requirements remain distinct engineering work.

Explore the other supported frameworks →

NIS 2

ISO 27001

CYFUN

GDPR

DORA

NIST CSF 2.0

PCI DSS

TISAX

ISO/IEC 42001

ANSSI

ISO 9001

ISO 14001

BSI

ISO 22301

IEC 62443

+ More and growing

FAQs for CRA compliance software

What is CRA?

The Cyber Resilience Act is the EU regulation setting cybersecurity requirements for products with digital elements, with obligations centred on manufacturers and continuing across the product support period. The CRA entered into force on 10 December 2024 and applies in full from 11 December 2027. Certain provisions apply earlier, including conformity-assessment-body rules from 11 June 2026 and Article 14 reporting obligations from 11 September 2026.

The Cyber Resilience Act applies to products with digital elements made available on the EU market where the intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. It establishes obligations for manufacturers and, depending on their role, authorised representatives, importers and distributors. It also contains limited, specific obligations for qualifying open-source software stewards; not every open-source project or maintainer falls within that definition.

Secrato supports the governance side of CRA readiness by keeping cybersecurity risks, controls, policies and evidence connected, giving product and security teams a clearer record of how the relevant requirements are being addressed.

Build the governance record behind CRA readiness

The CRA creates continuing cybersecurity responsibilities across the product lifecycle, not just a deadline to prepare for. See how Secrato can keep the risks, controls, policies and evidence behind that work connected as requirements take effect.

Secrato