Free

EU CRA Health Check

Validate your product security strategy and confirm your readiness for the Cyber Resilience Act.

What

Requirements

EU CRA timeline: notification obligations from 11 September 2026, full conformity from 11 December 2027

Notification Obligation

11 September 2026

Vulnerability Notification

Notify ENISA without undue delay when an actively exploited vulnerability is identified.

Incident Reporting

Report severe security incidents that significantly impact product security.

24-Hour Notice

Submit an initial incident notification within 24 hours of awareness.

72-Hour Follow-up

Provide a detailed follow-up report including mitigation measures.

User Communication

Inform affected users and customers when action or mitigation is required.

Record Keeping

Maintain documented records of all incidents, vulnerabilities, and notifications.

Full conformity

11 December 2027

Declaration of Conformity

Formally declare that the product complies with all applicable CRA requirements before placing it on the market.

Technical Documentation

Maintain technical documentation that shows compliance throughout the product lifecycle.

Secure by Design

Build security into the product architecture from the earliest design stages.

Secure by Default

Ship products with secure default configurations that require minimal user action.

Vulnerability Management

Implement ongoing processes to identify, assess, remediate, and disclose vulnerabilities.

Pick a time

Schedule CRA strategy
health check

Our CRA specialists offer a free, one-hour health check of your EU CRA compliance strategy. There is no purchase requirement.

FAQ

1. Why is it free? What’s the catch?

There is no catch. SecureHabits team members also volunteer in nonprofit initiatives such as OWASP and ISO, and we want more teams to understand what the CRA expects before the deadlines arrive.

We do not expect a work assignment after the health check. If the report uncovers work where we can help, we can talk about it. Either way, you leave with a clearer plan.

2. Who is this health check for?

This health check is for manufacturers of products with digital elements or on-premises software who plan to sell their products on the European market.

If you already work with internal teams or external consultants on CRA compliance, we can review your current strategy and point out gaps before they become delivery problems.

3. Who should join the call?

The EU Cyber Resilience Act focuses on the security of the products you place on the European market. Its primary concern is the risk to your end users.

The ideal participants for this call are product owners, development managers, and members of application security teams.

4. What will we receive?

After the call, our team will send a report on the current state of your secure software development lifecycle. We’ll highlight gaps that may lead to unacceptable risk.

You’ll also receive a list of missing controls required for baseline CRA compliance, along with an effort estimate for the work needed to reach baseline compliance.

5. What can we expect after the health check?

After you receive the report and CRA readiness recommendations, we follow up only if you ask us to.

If you want help with the next steps, we can discuss the work at your pace.