🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Sector-Specific Compliance

CRA Compliance Services

Part of our full compliance service catalog: CRA readiness assessment for software products, SBOM setup, and CE marking guidance.

1 service · Fixed price · 14-day warranty · Senior engineers only

Frequently Asked Questions

Does the CRA apply to SaaS?+
It depends. The CRA applies to SaaS where the service qualifies as a 'remote data processing solution' that is integral to a product with digital elements placed on the EU market — for example, a companion cloud backend for a connected device. A self-contained SaaS product with no dependent hardware or software component is more commonly regulated under NIS2 instead, not the CRA. Don't assume either way — this is one of the most frequently misjudged scope questions and worth confirming for your specific product.
What is a 'product with digital elements'?+
Any software or hardware product whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network — a broad definition covering most commercial software, connected hardware and IoT devices.
What must be reported from 11 September 2026?+
Actively exploited vulnerabilities and severe incidents affecting products with digital elements, under Article 14 — within 24 hours (early warning), 72 hours (full notification), and 14 days or 1 month (final report, depending on the trigger).
Who do I report to?+
Your national CSIRT (Computer Security Incident Response Team) and ENISA, via the single reporting platform ENISA is required to have operational by 11 September 2026.
Do I need an SBOM by September 2026?+
The CRA doesn't set a hard SBOM deadline tied to 11 September 2026, but Annex I, Part II, point 1 requires manufacturers to identify and document components and vulnerabilities in the product, including by drawing up a Software Bill of Materials — and you can't meet the 24-hour reporting obligation without knowing what components your product contains.
€89

Not Sure Where to Start?

Our IT Health Check finds every compliance gap in your infrastructure. 1 business day. You get a prioritized list of what to fix.

IT Health Check — €89