CRA Implementation: What SMEs Need to Know Now
The Cyber Resilience Act (CRA) has been in effect since December 2024. Yet for many small and medium-sized enterprises, it remains a mystery. That is about to change: The first reporting requirements take effect in September 2026, and the German implementing legislation, which is intended to regulate the act’s implementation, is facing criticism. Associations such as TeleTrusT criticize that the planned support for SMEs falls far short of what is needed. According to FTAPI, SMEs should not wait for government assistance but should take action now to build CRA readiness.
Implementing the CRA Is a Top Priority
The CRA requires all manufacturers, importers, and distributors of products with digital components—such as software, hardware, and IoT devices—to implement comprehensive cybersecurity measures. Unlike regulations such as NIS-2, there are no size-based exemptions here. Whether a large corporation or a micro-enterprise, anyone selling digital products in the EU must comply with the requirements. Implementation is not just the responsibility of the IT department, but a top priority—with management personally liable in the event of a serious incident. At the same time, the current draft bill for the CRA Implementation Act shows that the government has budgeted 1.28 million euros annually for support. By comparison, the NIS 2 Act allocated four times that amount for training in the federal administration alone.
The Five Most Important Steps Toward CRA Compliance
The funding gap makes it clear: SMEs must take implementation into their own hands. Five steps that matter now:
- Determine Scope of Application
Any product that can connect directly or indirectly to a device or network—including not only IoT devices but also standalone software products—falls under the CRA, regardless of whether it is actually connected. This does not apply to SaaS solutions and open-source components.
- Establish reporting processes
The first mandatory requirement takes effect in just a few months: Starting September 11, 2026, actively exploited vulnerabilities and serious security incidents must be reported. The timeline is tight:
- Initial report within 24 hours
- Follow-up report within 72 hours
- Final report no later than 14 days after a remediation measure becomes available
Anyone who does not yet have internal processes for vulnerability management and incident response must establish them now—not as an IT project, but as an operational priority.
- Embed Security by Design
The CRA requires that security be an integral part of product development from the very beginning. The most significant vulnerabilities arise when architectural decisions (authentication, data flow control, multi-tenancy) are made without an explicit focus on security. SMEs just getting started don’t need to aim for perfection, but they do need a verifiable, documented process.
- Inventory the supply chain and open-source dependencies
Many products today consist of a combination of in-house development, open-source libraries, cloud services, and third-party components. The CRA addresses precisely these risks: manufacturers are also responsible for embedded third-party components. A Software Bill of Materials (SBOM)—a structured overview of all software components used—is the key tool for establishing transparency and remaining capable of taking action in an emergency.
- Take Advantage of Funding Opportunities
Through the SECURE program (https://www.secure4sme.eu/about-secure), the EU is providing a total of 16.5 million euros in direct financial support for SMEs that manufacture, develop, or distribute products with digital components. Eligible activities include risk analyses, penetration tests, and security assessments. Eligible applicants are companies with fewer than 250 employees and annual revenue of up to 50 million euros. The first call for proposals has already closed, and a second round has been announced.
Regulation as a Competitive Advantage
These requirements also present a strategic opportunity. Companies that are CRA-compliant will become the preferred partners in supply chains where clients will be required to insist on verifiable security standards in the future. Conversely, those who cannot meet these standards risk losing business.
“The new regulations are forcing companies to think strategically about cybersecurity,” says Ari Albertini, CEO of FTAPI. “This is the moment that will determine who will still be perceived as a reliable technology partner in the coming years. SMEs that act now are gaining a head start that others will never be able to catch up with.”
The CRA marks the end of an era in which cybersecurity was a matter for specialists. Companies that view security as an operational and strategic given are not only protecting their products but also securing their market viability in a regulated Europe.
Further information is available at www.ftapi.com.