CRA · Organizational Readiness

CRA isn't one team's job — it's the whole organization's readiness

Preparing for the EU Cyber Resilience Act (CRA) does not end with the development team. Security has to be built into every stage of the product lifecycle — from planning to post-market support. Here is what that means, and why it is the whole organization's job.

Applies to makers of products with digital elements (PDE)Basis: Regulation (EU) 2024/2847Source: EUR-Lex · EC

At a glance

Core
Not one department ❌ → every lifecycle stage × the whole org
Common gap
Development has no 'security stage' (feature- and deadline-driven)
The real hard part
Who owns each new security task — accountability gaps & overlaps (R&R)
Starting point
Map your organization's current capability & gaps

01Why it's the whole organization's job

CRA is not about fixing a single product; it requires security across the entire product lifecycle, from planning through post-market support (Annex I). Yet most companies' development processes are built around features and deadlines, so a 'cybersecurity' stage simply doesn't exist. That is why CRA readiness is not one department's task, but an organizational one — development, quality, procurement, legal, certification and service each carrying a share of the security responsibility.

02Across the product lifecycle — what you need

Each stage brings new security work. Here is the scope, at a glance.

Planning · Governance
Security policy · product security classification · legal-risk review
Sourcing · Supply chain
Contractual security clauses · SBOM · supplier security capability (Art. 13(5))
Design · Development
Risk assessment (TARA) · secure architecture · vulnerability scanning
Verification · Documentation
Security verification gates · technical documentation (Annex VII)
Conformity · Launch
Conformity assessment · EU DoC · CE (Art. 28·30·32)
Post-market · Maintenance
24-hour incident reporting · vulnerability monitoring · support period (Art. 13·14)

※ The scope and depth of each item scale with the product classification (Default / Important / Critical).

03The hard part isn't 'what' — it's 'who'

Harder than knowing the list is "who owns this work" (R&R). Most of these new security tasks fall outside any team's core role, so the boundaries between departments blur.

Where it actually stalls
Vulnerability handling — discover → analyze → patch → deploy: which team owns each step?
24-hour incident reporting — technical drafting · legal-risk review · submission to authorities: who?
Security testing — development? QA? outsourced?

This is where accountability gaps (blind spots) or overlaps appear — and when an incident actually hits, "who reports to the EU" is left empty. Whether organizational readiness succeeds comes down, in practice, to how you define this R&R.

04So — where does your organization stand today?

Reality
· No in-house expertise — TARA · SBOM · vulnerability scanning are new areas; building internal capability can take one to two years.
· No single right answer — what's missing and who should own it differ entirely by organization and product.

So the first step is not to aim for 'perfect readiness', but to accurately diagnose your organization's current capability and R&R gaps. That diagnosis and design go fastest and surest alongside regulatory and security experts.

Where does your organization stand, and what's missing?

From scope and classification to lifecycle security work and R&R design — ACE LABS works with you from readiness and gap assessment through building the system and supporting certification. (An independent pre-certification readiness/gap advisory, not a certification body.)

Sources

Basis for product requirements and obligations — Regulation (EU) 2024/2847 Articles 13·14·28·30·31·32 · Annex I/II/V/VII/VIII (EUR-Lex) · European Commission (EC)

This article is general information based on the public regulation Regulation (EU) 2024/2847 (Cyber Resilience Act) and public materials from the European Commission; it is not legal advice or a conformity determination. Scope, specific obligations and per-organization R&R require the original text and case-by-case review. ACE LABS (ACE LABS Inc.) is not a certification body, but an independent pre-certification readiness and gap-assessment advisory.