Practical
A 90-day CRA readiness plan
You cannot boil the ocean in a quarter — but you can build real momentum. Here is a pragmatic plan for a small team.
The CRA can feel overwhelming if you look at the whole regulation at once. The trick is to sequence the work so each phase produces something useful and de-risks the next. This 90-day plan is aimed at small and mid-sized manufacturers who need to get moving without a dedicated compliance department. Treat the dates as a rhythm, not a legal deadline — the binding dates are in the regulation.
The goal of month one is clarity: know what you have and where you stand.
- Inventory your products. List every product with digital elements you place, or plan to place, on the EU market.
- Determine scope and risk class for each — Default, Important (Annex III) or Critical (Annex IV).
- Assign an owner. Name a person accountable for CRA across the company, even part-time.
- Run a gap assessment against the Annex I essential requirements for your top one or two products, and write down where you are weak.
Month two is about the ongoing machinery the CRA expects — the things that are painful to retrofit later.
- Generate an SBOM for your priority products and start scanning it against known-vulnerability data.
- Publish a CVD policy and a security contact — one policy for the whole company.
- Draft a vulnerability-handling workflow: how a report becomes a triaged issue, a fix, and an update.
- Build a reporting runbook for the 24h / 72h / final duties, including who approves a report and how fast.
Month three turns effort into demonstrable readiness.
- Fix the highest-priority Annex I gaps from your month-one assessment (default passwords, update mechanism, logging, data protection).
- Start the technical documentation — risk assessment, how each requirement is met, SBOM, support-period decision.
- Choose your conformity route per product (self-assessment vs notified body).
- Set a support period for each product and record it, with a plan to deliver updates across it.
What you will have after 90 days
- A clear picture of scope, risk class and gaps for your portfolio.
- The core processes — SBOM scanning, CVD, vulnerability handling, reporting runbook — actually running.
- Technical documentation under way and a chosen conformity route.
That is not "done" — full conformity is an ongoing commitment — but it is the hard 20% that unlocks the rest, and it puts you comfortably ahead of the timeline.
General information, not legal advice. Refer to Regulation (EU) 2024/2847 for binding requirements and dates.