Practical

A 90-day CRA readiness plan

You cannot boil the ocean in a quarter — but you can build real momentum. Here is a pragmatic plan for a small team.

The CRA can feel overwhelming if you look at the whole regulation at once. The trick is to sequence the work so each phase produces something useful and de-risks the next. This 90-day plan is aimed at small and mid-sized manufacturers who need to get moving without a dedicated compliance department. Treat the dates as a rhythm, not a legal deadline — the binding dates are in the regulation.

Days 1–30 · Understand & scope

The goal of month one is clarity: know what you have and where you stand.

  • Inventory your products. List every product with digital elements you place, or plan to place, on the EU market.
  • Determine scope and risk class for each — Default, Important (Annex III) or Critical (Annex IV).
  • Assign an owner. Name a person accountable for CRA across the company, even part-time.
  • Run a gap assessment against the Annex I essential requirements for your top one or two products, and write down where you are weak.
Days 31–60 · Stand up the processes

Month two is about the ongoing machinery the CRA expects — the things that are painful to retrofit later.

  • Generate an SBOM for your priority products and start scanning it against known-vulnerability data.
  • Publish a CVD policy and a security contact — one policy for the whole company.
  • Draft a vulnerability-handling workflow: how a report becomes a triaged issue, a fix, and an update.
  • Build a reporting runbook for the 24h / 72h / final duties, including who approves a report and how fast.
Days 61–90 · Close gaps & assemble evidence

Month three turns effort into demonstrable readiness.

  • Fix the highest-priority Annex I gaps from your month-one assessment (default passwords, update mechanism, logging, data protection).
  • Start the technical documentation — risk assessment, how each requirement is met, SBOM, support-period decision.
  • Choose your conformity route per product (self-assessment vs notified body).
  • Set a support period for each product and record it, with a plan to deliver updates across it.

What you will have after 90 days

That is not "done" — full conformity is an ongoing commitment — but it is the hard 20% that unlocks the rest, and it puts you comfortably ahead of the timeline.

ComplyCRA is built around exactly this journey. It classifies your products, runs the Annex I self-assessment, generates and scans SBOMs, manages CVD and reporting, and rolls it all into a readiness score — so this 90-day plan becomes a guided checklist rather than a research project. Open ComplyCRA →

General information, not legal advice. Refer to Regulation (EU) 2024/2847 for binding requirements and dates.

← Setting up a CVD policy All CRA Insights →