Services  /  Cyber Resilience Act Readiness

Cyber Resilience Act Readiness & Product Security

Prepare for the CRA. Build product security that lasts beyond compliance.

The EU Cyber Resilience Act makes cybersecurity a lifecycle responsibility for products with digital elements. OnShoreWave helps manufacturers understand what applies, organize the work, coordinate the right technical and regulatory specialists, and build a sustainable product-security program.

Manufacturers selling connected hardware, software, and products with digital elements into the European Union face new cybersecurity responsibilities under the Cyber Resilience Act.

The challenge is bigger than completing a compliance checklist. Organizations need to understand which products are in scope, determine likely product classification and conformity routes, establish vulnerability-handling processes, validate product security, organize supporting evidence, manage product changes, and maintain security throughout the supported life of the product.

OnShoreWave brings these activities together into one coordinated program while working with the engineering, security, compliance, and business systems you already use.

Who it's for

Manufacturers, technology companies, industrial-product companies, software providers, connected-device manufacturers, and U.S. organizations that sell or plan to sell products with digital elements into the European Union.

  • Organizations unsure whether CRA applies to particular products
  • Teams evaluating product classification and likely conformity paths
  • Companies managing multiple products, families, firmware versions, or software releases
  • Manufacturers that need product-security testing coordinated with CRA readiness
  • Teams whose vulnerability and incident processes were not designed around CRA requirements
  • Organizations that want to keep their existing engineering and cybersecurity systems
  • Leaders coordinating internal teams, security specialists, regulatory advisers, and conformity resources

A coordinated path from product scope to continuous security.

1. CRA Scope & Route Determination

We start by determining what actually needs to be addressed. Working with the client and appropriate specialists, we organize products with digital elements, product families and versions, connectivity, EU market paths and roles, preliminary classification, likely conformity routes, and assumptions requiring specialist confirmation.

Deliverables: Product inventory, CRA scope memo, product-family strategy, preliminary classification rationale, conformity-route worksheet, testing and evidence plan, and open validation items.

2. CRA Readiness Assessment & Program

Once scope is understood, we evaluate the organization's ability to support the product throughout its lifecycle.

  • Secure product development
  • Vulnerability handling and coordinated disclosure
  • Product and component inventory
  • Software, firmware, and security updates
  • Support periods and vulnerability intelligence
  • Incident awareness, escalation, and CRA reporting processes
  • Evidence and product-change management
  • Technical documentation, ownership, and supplier dependencies

Deliverables: CRA readiness matrix, gap and risk register, prioritized remediation roadmap, process recommendations, documentation roadmap, responsibilities model, and implementation plan.

3. Product Security Testing Coordination

CRA readiness can require technical validation, not simply documentation. OnShoreWave coordinates qualified security-testing resources based on the actual product and attack surface. Depending on the agreed scope, testing may include network, web, API, cloud, application, AI, embedded, firmware, wireless, hardware-interface, credential-storage, and physical attack-surface review, plus remediation validation and retesting.

Deliverables: Defined testing scope, testing coordination, findings mapped to affected products and versions, remediation tracking, retest coordination, and evidence references for the broader CRA program.

4. Technical File & Conformity Readiness Support

Security evidence needs to fit into the manufacturer's broader conformity process. We help organize cybersecurity evidence, connect requirements to supporting artifacts, identify missing evidence, coordinate test reports, track remediation evidence, document product and version history, prepare evidence references, and support technical-file readiness with qualified regulatory, CE, legal, and conformity specialists where required.

Important boundary. The manufacturer remains responsible for its technical file, regulatory determinations, conformity decisions, declarations, and required filings. OnShoreWave is not a notified body, law firm, or conformity-assessment authority.

5. Continuous Product Security

CRA responsibility does not end when an assessment or product release is completed. Ongoing support can include product and version tracking, software and firmware status, vulnerability intelligence, vendor and public advisories, support-period tracking, remediation status, product changes, focused retesting, incident-process support, evidence updates, and periodic program reviews.

Work With the Environment You Already Have

Your CRA program should fit your technology environment, not replace it.

OnShoreWave's approach is intentionally technology-independent.

We can work with information maintained in PLM and product-management platforms; GitHub, GitLab, Azure DevOps, and other engineering systems; Jira and ServiceNow; SBOM and software-composition-analysis platforms; vulnerability-management tools; SIEM and SOC platforms; GRC systems; SharePoint and controlled document repositories; vendor security portals; and client-controlled technical-file repositories.

Customers are not required to transfer sensitive engineering or security information into an OnShoreWave system.

Continuous intelligence and evidence, when it adds value

SecureFi.AI may be used as an optional product-security intelligence and record layer. Depending on the engagement, it may help maintain product identity, models and versions, support periods, vulnerability and advisory correlations, finding status, remediation and retest dates, evidence references, awareness events, review history, and reporting-support milestones.

SecureFi.AI is not required for an OnShoreWave CRA engagement. Mature organizations can keep their existing systems as the sole operational environment. SecureFi.AI can function as a lightweight monitoring or correlation layer where useful, while raw penetration findings, exploit details, full SBOMs, and the authoritative technical file remain in appropriate client- or specialist-controlled repositories.

Six phases. One coordinated product-security program.

01
Scope
Identify products, versions, product families, EU roles, and preliminary conformity considerations.
02
Assess
Evaluate processes, architecture, documentation, vulnerability handling, and evidence.
03
Test
Coordinate specialists based on the actual product and attack surface.
04
Remediate
Address technical findings and process gaps, then validate corrective actions.
05
Prepare Evidence
Coordinate product-security evidence with qualified regulatory and conformity specialists.
06
Operate
Maintain awareness, product changes, vulnerability intelligence, evidence, and periodic review.

One coordinated program, without pretending one company does everything.

CRA readiness crosses cybersecurity, engineering, product management, regulatory requirements, technical documentation, and business operations. OnShoreWave provides the senior coordination layer.

We help define the problem, establish the program, coordinate internal teams and qualified specialists, track decisions and evidence, and turn CRA preparation into an operating product-security capability.

  • Senior technology and operational leadership
  • Decades of commercial and government technology experience
  • Cybersecurity and emerging-technology work
  • Practical AI and security-risk experience
  • Program coordination across technical and executive teams
  • Technology-independent recommendations
  • Specialist support where specialist competence is required
What this is. CRA readiness advisory, product-security program coordination, implementation support, evidence organization, and ongoing product-security support.

What this isn't. A legal opinion, conformity assessment, certification, notified-body service, or guarantee that a product complies with the Cyber Resilience Act. Product classification, conformity route, reporting obligations, CE documentation, legal interpretation, and regulatory submissions remain the manufacturer's responsibility in consultation with qualified legal, regulatory, and conformity-assessment resources. Technical testing is performed only within the demonstrated capabilities and agreed scope of qualified testing providers.

What manufacturers ask first

Is the Cyber Resilience Act already in effect?

The CRA entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026, and the main obligations apply from 11 December 2027. Organizations selling covered products into the EU should establish applicability, responsibilities, and readiness now.

Does CRA apply to my product?

It depends on the product, its digital elements, connectivity, how it reaches the EU market, applicable exclusions, and the organization's role. CRA Scope & Route Determination is intended to establish the preliminary answer and identify areas requiring specialist confirmation.

Do we need to replace our existing cybersecurity tools?

No. OnShoreWave is technology-independent and is designed to work with existing engineering, security, product, SBOM, vulnerability, GRC, and documentation systems.

Do we have to use SecureFi.AI?

No. SecureFi.AI can provide useful monitoring, correlation, product-security records, and evidence timelines, but it is optional.

Does OnShoreWave perform penetration testing?

OnShoreWave coordinates appropriate technical testing as part of the broader CRA program. Testing is performed by qualified security specialists within their confirmed areas of expertise.

Can OnShoreWave certify that we are CRA compliant?

No. OnShoreWave provides readiness, coordination, and implementation support. Formal conformity determinations remain with the manufacturer and the appropriate qualified advisers and conformity-assessment resources.

What if we manufacture several products?

The first step is determining whether products can reasonably be organized into product families that share development practices, components, software, evidence, or lifecycle processes. The objective is a scalable program rather than treating every product as unrelated.

Can you support us after our initial CRA project?

Yes. Ongoing services can include vulnerability intelligence, product changes, evidence updates, periodic program reviews, security-testing coordination, and SecureFi.AI product monitoring where appropriate.

Start with the products, not the paperwork.

A short discovery conversation can help establish what you sell into Europe, what may fall within CRA scope, and what the next step should be. No obligation, and no assumption that every organization needs a large compliance project.

Book a Free CRA Discovery Call