EU Cyber Resilience Act · Regulation (EU) 2024/2847

CRA compliance for companies that ship hardware, not code.

Send us your supplier's parts list. You get the technical file, the EU declaration of conformity, and a desk that drafts your 24-hour reports to ENISA for every connected product you sell in the EU.

The scope check takes about five minutes. No account needed.

Actively exploitedArt. 14(2)(a)
Drill: exploited flaw in the local API of LSP-2 smart plug
23:59:59
  1. 24 hEarly warning to CSIRT and ENISA14(2)(a)

Example drill. In your workspace the clock starts when you mark a finding as exploited.

Reporting applies since11 Sep 2026

Report exploited vulnerabilities within 24 hours, including for products already on the market.

Deadline11 Dec 2027

Connected products placed on the EU market from this date need a CRA technical file, declaration and CE marking.

Maximum fine€15M or 2.5%

Of worldwide annual turnover, whichever is higher, under Art. 64(2).

From parts list to signed file in four steps

Each step maps to a specific article or annex, and the workspace shows which one.

  1. 01 · Art. 2, 7, 8

    Scope check

    Three questions tell you whether the CRA applies, which category your product falls in, and whether you can self-assess.

  2. 02 · Annex I Part II (1)

    Components

    Upload the parts list from your chip or module supplier. We build the SBOM in CycloneDX and SPDX.

  3. 03 · Annex II, V, VII

    Technical file

    Fill the gaps the workspace points to. Download the technical file, the declaration and the user security information.

  4. 04 · Art. 14

    Watch and report

    We check every component against OSV and CISA's exploited list. If one is hit, the desk drafts each report stage.

What goes in your file

A market surveillance authority can ask for these for at least ten years, or the support period if longer.

Technical documentation

Product description, architecture, risk assessment against all 14 essential requirements, support period, standards, test reports.

Annex VII · Art. 31

EU declaration of conformity

Full declaration plus the simplified text to ship with the product.

Annex V · Annex VI

Security information for users

Contact point, support end date, secure setup, updates and data removal.

Annex II · Art. 13(18)

Vulnerability disclosure policy

A published policy and a security.txt file for your website.

Annex I Part II (5)(6)

Software bill of materials

Machine-readable, kept current as your firmware changes.

Annex I Part II (1)

Built for two kinds of seller

Both sell connected products in the EU. Neither has a security team.

Makers in the EU

Small hardware brands

You design smart home devices, sensors, wearables or e-bike electronics with 5 to 100 people. Your firmware comes from a chip vendor's SDK.

  • No code repository needed, a parts list is enough
  • File ready for your own sign-off in about 14 days
  • One price per product, no per-developer seats
Sellers outside the EU

Marketplace sellers

You sell connected products on Amazon EU or other marketplaces from China, the UK, the US or Turkey. You already pay a GPSR representative.

  • Documents in plain English, ready to hand to your EU representative
  • Reports prepared for the ENISA platform in the right order
  • Partner plan for representative firms that serve many sellers

Where Readymark fits

Typical options for a small maker's first connected product.

OptionYou needTypical costAfter the file
Consultancy projectWeeks of workshops€30,000 to €60,000 for a first product (estimate)Ends at delivery
Developer security toolsA code repository and an engineer to run them€25 to €1,000 per developer per monthFindings, no filing
Enterprise firmware platformsA sales processNot publishedManaged, per product per year
ReadymarkYour supplier's parts listFrom €79 per product per monthDaily watch and a 24-hour desk

One price per product

Prices exclude VAT. Cancel at the end of any month; the documents stay yours.

Starter

€79 per product / month
  • Scope check and category
  • SBOM in CycloneDX and SPDX
  • Technical file, declaration, user information
  • Disclosure policy and security.txt
  • Monthly vulnerability scan
Subscribe to Starter

Desk

€199 per product / month
  • Everything in Starter
  • Daily scan with CISA known-exploited alerts
  • Article 14 drafts within 4 hours of an alert
  • Human review of your technical file
  • Updates to the file for each firmware release
Subscribe to Desk

Partner

€490 per month
  • For EU representatives and seller agencies
  • Your brand on the workspace and documents
  • 10 client products included, €39 each after
  • Handover of files to your clients
Subscribe as a partner

Founding customers: the first 20 companies pay no €490 setup fee and get the first three months at half price. The discount applies at checkout automatically.

Talk to us first

Payment through Stripe. Invoices are issued by SIA "DDA Projects". Change the number of products or cancel from your billing page at any time.

Questions

Readymark prepares documents and reports. Your company signs them and stays responsible under the CRA.

Does the CRA apply to my product?

It applies to products with software or firmware that can connect to a device or network, directly or through an app. Medical devices, vehicles, aviation and marine equipment have their own rules and are excluded. The scope check in the workspace walks through Art. 2 and gives you the answer with the article it rests on.

My radio product already meets the RED cybersecurity rules. Is that enough?

No. The RED rules cover some security properties of radio equipment. They do not include the 24-hour reporting under Art. 14, a software bill of materials, a disclosure policy or a stated support period, and from 11 December 2027 the CRA is the rule for connected products. Your RED work still counts as evidence in the CRA file.

We are a small company. Do we still have to report?

Yes. Micro and small enterprises cannot be fined for missing the 24-hour early warning deadline (Art. 64(10)(a)), but the reporting duty itself applies to them.

Who submits the reports to ENISA?

Your company does, through the single reporting platform with an EU Login account. At launch the platform has no API, so no tool can submit for you. Readymark prepares each stage so the person on duty can paste and submit it in minutes.

Do you replace a notified body?

No. Most connected products are in the default category and can use self-assessment. Class I products can self-assess only if they apply a harmonised standard, common specification or certification scheme in full; until CRA standards are published, that usually means a notified body. Class II and critical products need a notified body or a certification. Readymark prepares the file you hand to them.

There are no harmonised CRA standards yet. How can the file be complete?

Annex VII lets you describe the solutions you adopted where no standard is applied. The workspace asks for that description for each requirement, and suggests established references such as ETSI EN 303 645 for consumer IoT.

How does the partner plan work?

Representative firms and seller agencies run one workspace for many client products under their own brand. Each client gets a complete file to keep. Terms are agreed per partner during the founding period.

Talk to us

Questions about scope, partner terms or a product line with many models. Replies within one working day.

The details are used only to answer you. See the privacy policy.

Find out where your product stands before your next shipment.

Check your product