At a glance
01Why it's the whole organization's job
CRA is not about fixing a single product; it requires security across the entire product lifecycle, from planning through post-market support (Annex I). Yet most companies' development processes are built around features and deadlines, so a 'cybersecurity' stage simply doesn't exist. That is why CRA readiness is not one department's task, but an organizational one — development, quality, procurement, legal, certification and service each carrying a share of the security responsibility.
02Across the product lifecycle — what you need
Each stage brings new security work. Here is the scope, at a glance.
※ The scope and depth of each item scale with the product classification (Default / Important / Critical).
03The hard part isn't 'what' — it's 'who'
Harder than knowing the list is "who owns this work" (R&R). Most of these new security tasks fall outside any team's core role, so the boundaries between departments blur.
This is where accountability gaps (blind spots) or overlaps appear — and when an incident actually hits, "who reports to the EU" is left empty. Whether organizational readiness succeeds comes down, in practice, to how you define this R&R.
04So — where does your organization stand today?
· No single right answer — what's missing and who should own it differ entirely by organization and product.
So the first step is not to aim for 'perfect readiness', but to accurately diagnose your organization's current capability and R&R gaps. That diagnosis and design go fastest and surest alongside regulatory and security experts.
Where does your organization stand, and what's missing?
From scope and classification to lifecycle security work and R&R design — ACE LABS works with you from readiness and gap assessment through building the system and supporting certification. (An independent pre-certification readiness/gap advisory, not a certification body.)
Sources
Basis for product requirements and obligations — Regulation (EU) 2024/2847 Articles 13·14·28·30·31·32 · Annex I/II/V/VII/VIII (EUR-Lex) · European Commission (EC)
This article is general information based on the public regulation Regulation (EU) 2024/2847 (Cyber Resilience Act) and public materials from the European Commission; it is not legal advice or a conformity determination. Scope, specific obligations and per-organization R&R require the original text and case-by-case review. ACE LABS (ACE LABS Inc.) is not a certification body, but an independent pre-certification readiness and gap-assessment advisory.