Cyber Resilience Act · CRA ReadinessCyber Resilience Act · CRA Readiness

Van productscope naar aantoonbare cyberweerbaarheidFrom product scope to demonstrable cyber resilience

De CRA raakt producten met digitale elementen op de EU-markt. De kernvraag is niet alleen óf uw product in scope valt, maar ook welke rol u in de keten heeft, welke productcategorie van toepassing is en welk technisch bewijs u vóór de deadlines moet kunnen laten zien.The CRA affects products with digital elements on the EU market. The key question is not only whether your product is in scope, but also which role you have in the supply chain, which product category applies, and which technical evidence you must be able to show before the deadlines.

10 vragen quick · 15 deep10 questions quick · 15 deepCxO én IT-perspectiefCxO and IT perspectivesNL / ENNL / EN
ScopeScopeSecure-by-designSecure-by-designSBOMSBOMKwetsbaarhedenVulnerabilitiesUpdatesUpdatesIncidentmelding 24u / 72uIncident reporting 24h / 72hEvidenceEvidenceLifecycleLifecycle
Valt mijn product onder CRA?Is my product covered by the CRA?

Begin bij uw rol in de productketenStart with your role in the product chain

De CRA maakt onderscheid tussen economische rollen. Uw feitelijke positie bepaalt welke verplichtingen direct op u rusten. Onderstaande vier ingangen helpen om de juiste vragen te stellen; ze vervangen geen juridische kwalificatie.The CRA distinguishes between economic roles. Your actual position determines which obligations apply directly to you. The four entry points below help frame the right questions; they do not replace a legal qualification.

01 · Fabrikant01 · Manufacturer

U brengt het product onder eigen naam op de marktYou place the product on the market under your own name

Dit is de kernrol voor secure-by-design, risicobeoordeling, vulnerability handling, updates, technische documentatie en conformiteit.This is the core role for secure-by-design, risk assessment, vulnerability handling, updates, technical documentation, and conformity.

Scanvraag:Scan question:Zijn product, processen en bewijs vanaf ontwerp tot supportperiode aantoonbaar ingericht?Are product, processes, and evidence demonstrably organised from design through the support period?
02 · Importeur / distributeur02 · Importer / distributor

U brengt of levert een product van een andere fabrikant op de EU-marktYou place or make available another manufacturer's product on the EU market

De focus ligt op controle van CE-markering, documentatie, fabrikantverplichtingen en handelen bij twijfel over conformiteit of kwetsbaarheden.The focus is on checking CE marking, documentation, manufacturer obligations, and acting when there is doubt about conformity or vulnerabilities.

Scanvraag:Scan question:Kunt u aantonen dat het product en de ketenpartners aan de vereiste voorwaarden voldoen?Can you demonstrate that the product and supply-chain parties meet the required conditions?
03 · Integrator03 · Integrator

U combineert of wijzigt digitale producten en componentenYou combine or modify digital products and components

“Integrator” is geen aparte wettelijke CRA-rol. Bij een substantiële wijziging en opnieuw beschikbaar stellen op de markt kunt u voor het gewijzigde product als fabrikant worden behandeld.“Integrator” is not a separate statutory CRA role. If you substantially modify a product and make it available on the market again, you may be treated as the manufacturer for the modified product.

Scanvraag:Scan question:Verandert uw integratie de functie, het risicoprofiel of de cybersecurity-eisen van het product?Does your integration change the product's function, risk profile, or cybersecurity requirements?
04 · Afnemer04 · Buyer / user

U koopt of gebruikt het product binnen uw organisatieYou buy or use the product within your organisation

Een afnemer is niet automatisch een economische operator onder de CRA. Wel heeft u belang bij leveranciersbewijs, supporttermijnen, kwetsbaarheidsprocessen en veilige updates.A buyer is not automatically an economic operator under the CRA. You still have a strong interest in supplier evidence, support periods, vulnerability processes, and secure updates.

Scanvraag:Scan question:Kunt u bij inkoop en beheer voldoende bewijs vragen om productrisico en lifecycle te beheersen?Can you request enough evidence in procurement and operations to manage product risk and lifecycle?
ProductcategorieProduct category

Standaard, important of critical?Standard, important, or critical?

De categorie beïnvloedt de conformiteitsroute. “Standaard” is hier een praktische pagina-aanduiding voor producten die niet onder de Important- of Critical-lijsten van Annex III en IV vallen; het is geen formele CRA-categorienaam.The category affects the conformity route. “Standard” is used here as a practical page label for products that are not listed as Important or Critical in Annexes III and IV; it is not a formal CRA category name.

StandaardStandard

Overige producten met digitale elementenOther products with digital elements

De essentiële cybersecurity-eisen blijven gelden. De fabrikant bepaalt via risicobeoordeling en de toepasselijke conformiteitsroute hoe dit wordt aangetoond.The essential cybersecurity requirements still apply. The manufacturer determines through risk assessment and the applicable conformity route how compliance is demonstrated.

  • Secure-by-design en secure-by-defaultSecure-by-design and secure-by-default
  • Vulnerability handling en updatesVulnerability handling and updates
  • Technische documentatie en evidenceTechnical documentation and evidence
Important · Class I / IIImportant · Class I / II

Producten met verhoogde cyberfunctie of systeemimpactProducts with elevated cybersecurity function or system impact

Annex III bevat Important-productcategorieën. Class I en Class II kennen zwaardere conformiteitsroutes, afhankelijk van categorie en gebruikte normen of certificering.Annex III lists Important product categories. Class I and Class II are subject to stricter conformity routes, depending on the category and the standards or certification used.

  • Onder meer OS, VPN, netwerkbeheer, SIEM en PKI in Class IIncluding OS, VPN, network management, SIEM, and PKI in Class I
  • Onder meer hypervisors en firewalls in Class IIIncluding hypervisors and firewalls in Class II
Critical · Annex IVCritical · Annex IV

Kritieke productcategorieën met aanvullende conformiteitsvereistenCritical product categories with additional conformity requirements

Annex IV bevat Critical-productcategorieën. Voor deze categorieën kan Europese cybersecuritycertificering op een voorgeschreven assurance-niveau onderdeel van de conformiteitsroute worden.Annex IV lists Critical product categories. For these categories, European cybersecurity certification at a prescribed assurance level can become part of the conformity route.

  • Classificatie vóór architectuur- of certificeringsbesluitClassify before architecture or certification decisions
  • Bewijs en lifecycle vanaf productontwerp meenemenBuild evidence and lifecycle into product design from the start
De tijdlijnThe timeline

2024 → september 2026 → december 20272024 → September 2026 → December 2027

Drie momenten die bepalen wanneer u wat aantoonbaar moet hebben.Three moments that determine when you must be able to demonstrate what.

10 december 202410 December 2024

De CRA is in werking getreden.The CRA entered into force.

11 september 202611 September 2026

De meldplichtfase voor actief misbruikte kwetsbaarheden en ernstige beveiligingsincidenten is van toepassing: vroegwaarschuwing binnen 24 uur en hoofdrapportage binnen 72 uur.The reporting phase for actively exploited vulnerabilities and severe security incidents applies: early warning within 24 hours and main notification within 72 hours.

11 december 202711 December 2027

Volledige toepassing van de overige CRA-eisen, waaronder productsecurity, vulnerability handling, technische documentatie en conformiteit.Full application of the remaining CRA requirements, including product security, vulnerability handling, technical documentation, and conformity.

De CRA-ketenThe CRA chain

Van scope tot lifecycle: acht schakels die op elkaar moeten aansluitenFrom scope to lifecycle: eight links that need to connect

01
ScopeScope

Product, marktrol, uitzondering en categorie vaststellen.Determine product, market role, exemption, and category.

02
Secure-by-designSecure-by-design

Risico's en security-eisen vanaf ontwerp meenemen.Build risks and security requirements into design.

03
SBOMSBOM

Componenten en afhankelijkheden herleidbaar maken.Make components and dependencies traceable.

04
VulnerabilitiesVulnerabilities

Detecteren, triëren, herstellen en monitoren.Detect, triage, remediate, and monitor.

05
UpdatesUpdates

Veilige updates, integriteit en supportproces borgen.Secure updates, integrity, and support processes.

06
Incident reportingIncident reporting

24u / 72u-processen vooraf operationeel maken.Make 24h / 72h processes operational in advance.

07
EvidenceEvidence

Technische documentatie, besluiten en uitvoering aantoonbaar maken.Make technical documentation, decisions, and execution demonstrable.

08
LifecycleLifecycle

Supportperiode, wijzigingen, end-of-life en productonderhoud beheersen.Manage support period, changes, end-of-life, and product maintenance.

Technische kernTechnical core

SBOM en vulnerability handling zijn geen losse documentenSBOM and vulnerability handling are not isolated documents

S

SBOM: weten wat er in uw product zitSBOM: know what is inside your product

De scan behandelt de Software Bill of Materials als kernbewijs voor componenten, afhankelijkheden en de relatie met kwetsbaarheden en updates. Niet als een eenmalige export, maar als onderdeel van productbeheer.The scan treats the Software Bill of Materials as core evidence for components, dependencies, and their relationship with vulnerabilities and updates. Not as a one-off export, but as part of product management.

HerleidbaarTraceableWelke component en versie zit in welke release?Which component and version is in which release?
EigenaarschapOwnershipWie beoordeelt kwetsbaarheden en afhankelijkheden?Who reviews vulnerabilities and dependencies?
UpdatepadUpdate pathHoe wordt een kwetsbare component veilig vervangen of gepatcht?How is a vulnerable component safely replaced or patched?
V

Vulnerability handling: van signalering naar herstelbewijsVulnerability handling: from detection to remediation evidence

De CRA vraagt om een proces dat kwetsbaarheden gedurende de productlevenscyclus kan vinden, beoordelen, verhelpen en opvolgen. De scan kijkt daarom naar CVE-monitoring, triage, patchbeleid, disclosure en bewijs van opvolging.The CRA requires a process capable of finding, assessing, remediating, and following up vulnerabilities throughout the product lifecycle. The scan therefore looks at CVE monitoring, triage, patch policy, disclosure, and evidence of follow-up.

DetectieDetectionWeten dat een component geraakt is.Know when a component is affected.
TriageTriageImpact, exploitstatus en prioriteit vastleggen.Record impact, exploit status, and priority.
HerstelRemediationUpdate of mitigerende maatregel leveren en documenteren.Deliver and document an update or mitigating measure.
Meldplicht vanaf 11 september 2026Reporting obligation from 11 September 2026

Incident response moet 24 / 72 uur aankunnen vóórdat er iets gebeurtIncident response must be able to meet 24 / 72 hours before anything happens

24

VroegwaarschuwingEarly warning

Bij een actief misbruikte kwetsbaarheid of ernstig beveiligingsincident: zonder onnodige vertraging en uiterlijk binnen 24 uur na bewustwording.For an actively exploited vulnerability or severe security incident: without undue delay and at the latest within 24 hours after becoming aware.

72

HoofdrapportageMain notification

Uiterlijk binnen 72 uur volgt de inhoudelijke melding met beschikbare informatie over product, aard, impact en genomen of mogelijke maatregelen.Within 72 hours, the substantive notification follows with available information about the product, nature, impact, and measures taken or available.

→

Finale rapportageFinal report

Voor actief misbruikte kwetsbaarheden volgt een eindrapport uiterlijk 14 dagen nadat een corrigerende of mitigerende maatregel beschikbaar is; voor ernstige incidenten geldt een andere finale termijn.For actively exploited vulnerabilities, a final report follows no later than 14 days after a corrective or mitigating measure is available; severe incidents have a different final reporting deadline.

Operationele vraag:Operational question: Wie mag binnen uw organisatie classificeren, melden en inhoudelijk bevestigen — ook buiten kantooruren — en waar staat het bewijs dat die keten is getest?Who in your organisation is authorised to classify, notify, and substantively confirm — including outside office hours — and where is the evidence that this chain has been tested?
Twee perspectievenTwo perspectives

Dezelfde CRA, andere beslisvragen voor CxO en ITThe same CRA, different decision questions for CxO and IT

CxO / bestuurCxO / executive

Bestuurlijk draait CRA-readiness om scope, eigenaarschap, productportfolio, ketenrisico, prioritering en aantoonbare besluitvorming.At executive level, CRA readiness is about scope, ownership, product portfolio, supply-chain risk, prioritisation, and demonstrable decision-making.

  • Welke producten en businesslijnen vallen in scope?Which products and business lines are in scope?
  • Wie is eigenaar van productsecurity en meldplicht?Who owns product security and reporting?
  • Welke afhankelijkheden kunnen markttoegang of continuïteit raken?Which dependencies could affect market access or continuity?
  • Welke besluiten moeten vóór 2027 aantoonbaar zijn genomen?Which decisions must be demonstrably taken before 2027?

IT / engineering / securityIT / engineering / security

Technisch draait CRA-readiness om secure-by-design, componenten, vulnerability handling, updates, logging, incident response en lifecyclebewijs.Technically, CRA readiness is about secure-by-design, components, vulnerability handling, updates, logging, incident response, and lifecycle evidence.

  • Is de SBOM herleidbaar naar builds en releases?Is the SBOM traceable to builds and releases?
  • Werkt CVE-monitoring door naar triage en patching?Does CVE monitoring feed into triage and patching?
  • Zijn veilige updates en supportperioden technisch geborgd?Are secure updates and support periods technically controlled?
  • Kan het team een 24u/72u-melding onder tijdsdruk uitvoeren?Can the team execute a 24h/72h notification under time pressure?
Scan-previewScan preview

Deze CRA-onderwerpen komen in de scan aan bodThese CRA topics are covered in the scan

De Quick Scan bevat 10 vragen, de Diepgaande scan 15. De vraagstelling sluit aan op uw rol en sector.The Quick Scan has 10 questions, the in-depth scan 15. The questions match your role and sector.

01
Product scope & classificatieProduct scope & classificationWelke producten vallen onder CRA en welke categorie geldt?Which products fall under the CRA and which category applies?
02
Vulnerability handlingVulnerability handlingCVE-monitoring, triage, patching en disclosure.CVE monitoring, triage, patching, and disclosure.
03
Security by designSecurity by designThreat modeling, architectuur en veilige defaults.Threat modelling, architecture, and secure defaults.
04
SBOMSBOMComponenten, versies en afhankelijkheden.Components, versions, and dependencies.
05
Incident reportingIncident reporting24u / 72u-keten, rollen en operationele paraatheid.24h / 72h chain, roles, and operational readiness.
06
Conformiteit & technisch dossierConformity & technical fileCE, documentatie, interne controle en bewijs.CE, documentation, internal control, and evidence.
07
LeveranciersketenSupply chainComponentleveranciers en ketenafhankelijkheden.Component suppliers and supply-chain dependencies.
08
LifecycleLifecycleSupportperiode, updates en end-of-life.Support period, updates, and end-of-life.
09
GovernanceGovernanceEigenaarschap, verantwoordelijkheden en board-awareness.Ownership, responsibilities, and board awareness.
10
Beslisrol / vervolgDecision role / next stepDe laatste vraag legt vast vanuit welke rol de uitkomst wordt gelezen.The final question captures the role from which the result is interpreted.

De scan ordent readiness-signalen en vervolgvraagstukken; hij verklaart een organisatie of product niet automatisch compliant.The scan structures readiness signals and follow-up questions; it does not automatically declare an organisation or product compliant.

Start de CRA Readiness ScanStart the CRA Readiness Scan

Quick: 10 vragen. Diepgaand: 15 vragen. U kiest zelf uw rol en sector.Quick: 10 questions. In-depth: 15 questions. You choose your own role and sector.

Start de CRA Readiness ScanStart the CRA Readiness Scan
Wat krijgt u na de scan?What do you get after the scan?

Een bruikbaar readiness-beeld zonder te doen alsof het een conformiteitsverklaring isA usable readiness view without pretending it is a declaration of conformity

✓

CRA-thema's geordend per antwoord.CRA topics organised by your answers.
U ziet welke onderwerpen in de scan aan bod kwamen en waar vervolgvragen nodig zijn.You see which topics were covered and where follow-up questions are needed.

✓

CxO- en IT-lens.CxO and IT lens.
Dezelfde CRA-context wordt vertaald naar bestuurlijke beslisvragen en technische uitvoeringsvragen.The same CRA context is translated into executive decision questions and technical execution questions.

✓

Evidence-checklist voor vervolg.Evidence checklist for follow-up.
Denk aan SBOM, vulnerability-proces, updatebeleid, incidentprocedure, technische documentatie en lifecyclebewijs.Think SBOM, vulnerability process, update policy, incident procedure, technical documentation, and lifecycle evidence.

✓

Concrete vervolgvraag voor gesprek of interne review.A concrete next question for discussion or internal review.
Geen automatisch juridisch oordeel en geen conformiteitsverklaring.No automated legal judgement and no declaration of conformity.

Volgende stapNext step

Begin bij uw product, rol en bewijs — niet bij een complianceclaimStart with your product, role, and evidence — not with a compliance claim

De CRA Readiness Scan helpt om de juiste productsecurity- en bewijsvragen te ordenen. Voor formele toepasselijkheid, classificatie en conformiteitsbesluiten blijft controle tegen de actuele officiële bron en waar nodig specialistische juridische of conformity-assessment expertise nodig.The CRA Readiness Scan helps organise the right product security and evidence questions. Formal applicability, classification, and conformity decisions still require checking the current official source and, where needed, specialist legal or conformity-assessment expertise.