EU Cyber Resilience Act · Regulation (EU) 2024/2847
Get your product CRA-compliant — without the €25,000 lab.
Vandorisk guides you through the Cyber Resilience Act in plain language — whether you build hardware, embedded firmware, or a standalone software product: the mandatory risk assessment, every essential requirement, your classification and conformity route — and generates the technical file, EU Declaration of Conformity and user information you need. In hours, not weeks. With the confidence that you did it right.
Built by an EU cybersecurity assessor·Deterministic checks, not AI guesses·You stay in control
01 — Applicability
Does the CRA apply to your product?
Three quick questions, 60 seconds. No signup.
1. Does your product include software or digital elements (firmware, an app, cloud connection)?
2. Is it made available on the EU market (sold, distributed, or imported into the EU)?
3. Is it a medical device, motor vehicle, or aviation product (covered by their own rules)?
02 — The first deadline
The first deadline isn’t 2027. It’s 11 September 2026.
From 11 September 2026, every manufacturer with a product with digital elements on the EU market must report actively exploited vulnerabilities and severe incidents: a 24-hour early warning, a 72-hour notification, and a final report within 14 days (one month for incidents) — filed to your CSIRT and ENISA. Failing the reporting obligations sits in the CRA’s highest penalty tier: fines up to €15 million or 2.5% of worldwide turnover, whichever is higher. You can’t file a 24-hour report with a process you don’t have. We help you build it before the clock starts.
VDP guidance
We help you stand up a vulnerability disclosure program that satisfies the CRA: a coordinated-disclosure policy, a single point of contact for vulnerability reports (Art. 13(17)), security.txt, and the internal routing that makes a researcher’s report actually reach someone who can act.
Review of your existing VDP
Already have a disclosure program? We review it clause-by-clause against the CRA’s vulnerability-handling requirements (Annex I Part II) and the Article 14 duties, and hand you a prioritized gap list — what holds up, what doesn’t, and what to fix first.
Reporting-obligation playbooks
Step-by-step playbooks for the 24h / 72h / 14-day vulnerability timeline and its incident equivalent: who does what, in which hour, with which template — so when a report is due, September 2026 is a drill your team has already run.
Ready before the deadline beats scrambling after it — join the waitlist or start your self-assessment →
03 — The method
How Vandorisk works
A guided self-assessment that mirrors how an assessor actually reviews a product — from “does this even apply to me?” to documents you can stand behind.
Classify with confidence
A guided Annex III/IV decision tree — the real 26 product categories in plain language — tells you whether you’re Default, Important or Critical, and exactly which conformity route that means. The “can I skip the lab?” answer, up front.
Risk assessment, guided
The mandatory Article 13 risk assessment as a structured, six-field flow: intended purpose, foreseeable misuse, operational environment, assets, lifetime, threats. It drives which requirements apply — with a documented justification for anything that doesn’t.
Every requirement in plain language
All Annex I product-security and vulnerability-handling requirements, each with what it means, how to satisfy it, and the exact legal reference. Upload your SBOM and Vandorisk screens it against known vulnerabilities — evidence, attached automatically.
Documents, not homework
A live readiness score with a prioritized gap list and hard compliance blockers — then one-click Word exports of your Annex VII technical file, EU Declaration of Conformity and Annex II user information. Autosaved, versioned against the requirement pack, audit-trailed.
04 — The economics
The maths your CFO will ask for
For the ~90% of products that can legally self-assess, the alternatives look like this:
| Test lab / notified body | Compliance consultant | Vandorisk | |
|---|---|---|---|
| Typical cost | €25,000+ per product | tens of thousands | from €1,500 / year |
| Typical time | weeks to months | weeks | hours |
| Who does the work | the lab — you wait | the consultant — you brief | you — guided, step by step |
| What you learn | little | some | how your own product complies |
| When rules change | pay again | pay again | your assessment updates with the pack |
Legally required to use a notified body (Class II / Critical)? Vandorisk doesn’t pretend otherwise — it prepares the evidence pack that makes that assessment faster.
05 — The value
Why teams choose Vandorisk
Because the alternative isn’t really “do it yourself” — it’s buy the standards, decipher them, document everything by hand, and rebuild it every time the product changes. We removed each of those walls.
No standards shelf required
Understanding your obligations normally starts with buying standards at hundreds of euros apiece — thousands for a full set — written in regulatory language few product teams can parse. Vandorisk translates every applicable requirement into plain language, with how-to-satisfy guidance and the exact legal reference, so you don’t have to.
Assessor DNA
Vandorisk is built by an EU cybersecurity assessor who has evaluated real products against the standards behind this regulation — the same lens a lab would apply, encoded into software.
Deterministic, not generative
No black-box AI verdicts. Every check is a deterministic rule that traces to an article of Regulation (EU) 2024/2847 — the same inputs always produce the same result, and you can show a market-surveillance authority why.
Experienced professionals on call
Stuck on a compliance question or a technical one? Professional help from experienced compliance practitioners is part of the offering — a person who has done real evaluations, not a chatbot.
06 — Pricing
Simple, affordable pricing
A fraction of a lab — with the confidence of doing it right.
Free
For finding out where you stand.
- CRA applicability check
- Annex III/IV classification & conformity route
- Plain-language guidance library
Professional
For shipping a defensible self-assessment.
- Full guided self-assessment, risk assessment first
- SBOM upload & known-vulnerability screening
- Product-specific test plan & results report (coming Q4 2026)
- Readiness score, gap list & compliance blockers
- Technical file, EU DoC & Annex II as Word documents
- Evidence maintained for 10 years or the support period
Enterprise
For portfolios and regulated environments.
- Multiple products, teams & roles
- On-prem / private cloud deployment
- Priority support & onboarding
- Extra regulation packs (AI Act, RED)
07 — Questions
Questions every team asks
Is this legal advice? Can I rely on it?
No — Vandorisk is guided self-assessment and documentation software, not legal advice, and the manufacturer remains responsible for the Declaration of Conformity. What it gives you is the same thing a good assessor would: the applicable requirements, in order, with evidence captured and documents generated — so the declaration you sign is defensible and traceable.
My product might be Important Class I or II. Can I still self-assess?
Class I products may self-assess when harmonised standards are applied — but none have been cited in the Official Journal yet, which in practice pushes Class I toward a notified body for now. Class II and Critical products always involve a third party. Vandorisk tells you which class you’re in, is honest about the route, and prepares the evidence pack either way.
Does this apply to software products, or only physical devices?
Both. The CRA covers any “product with digital elements” — defined in the regulation as software orhardware, placed on the market as a product (Art. 3(1)). A standalone app, an operating system, a VPN client, a password manager, firmware — all squarely in scope, same rules, same routes, no hardware required. The one real carve-out is pure cloud/SaaS offered purely as an online service with no downloadable or installable product: that’s generally outside the CRA’s scope, unless it’s the “remote data processing” backend a covered product depends on to work (then it’s in scope through that product). Vandorisk’s classifier and requirement pack already reflect this — several Annex III categories are pure software (operating systems, browsers, password managers, VPNs, anti-malware, SIEM, PKI software), not just connected devices.
Do I have to buy the standards to comply?
No — and this is where most of the months (and thousands of euros) usually go. The standards behind CE-marking cybersecurity cost hundreds of euros apiece and are written for assessors, not product teams. Vandorisk’s requirement packs — built by an experienced compliance evaluator — translate every applicable requirement into plain language with how-to-satisfy guidance and the exact legal reference. For the CRA specifically, no harmonised standards have been cited in the Official Journal yet, so assessment runs against Annex I directly — which is exactly what Vandorisk guides you through.
When do I actually need to act?
Vulnerability and incident reporting duties start in September 2026; the full regulation — technical file, Declaration of Conformity, CE marking — applies from 11 December 2027 to every product placed on the EU market. A first self-assessment typically surfaces gaps (a missing CVD policy, an undocumented support period) that take months to close. Teams that start in 2026 are the ones not paying rush rates in 2027.
08 — Early access
Be first in line
Join the waitlist for early access and CRA guidance as we build. No spam.