Skip to main content Skip to search Skip to main navigation
Menu
Important Standards & legislation Score: 8/10

Cyber Resilience Act: Five-Step Checklist for SMEs by September 2026

The CRA takes effect from September 2026. These 5 steps help SMEs build CRA readiness: vulnerability management, SBOM and reporting obligations.

The Cyber Resilience Act is becoming a challenge for SMEs

The Cyber Resilience Act (CRA) has been in force since December 2024 and confronts small and medium-sized enterprises with new challenges. The first reporting obligations take effect from September 2026, yet state support for SMEs remains limited. Associations such as TeleTrusT are already criticising the fact that the planned assistance falls far short of actual needs.

Unlike other regulations such as NIS-2, the CRA contains no size-dependent exemptions. All manufacturers, importers and distributors of products with digital elements – from software and hardware through to IoT devices – must implement comprehensive cybersecurity measures. Management bears personal liability in the event of an incident.

State support remains inadequate

The current draft bill for the CRA implementing act shows the scale of the problem: the state is planning just 1.28 million euros per year for support. By comparison, the NIS2 act provided four times that amount for training within the federal administration alone. This support gap makes clear that SMEs will have to take implementation into their own hands.

The regulatory window is already closing: companies have only a few months left before the first hard obligations take effect. Anyone not ready by September 2026 risks considerable consequences.

Five steps to CRA readiness

Step 1: Clarify whether you are affected

Every product that can connect directly or indirectly to a device or a network falls under the CRA. This applies to IoT devices as well as to pure software products, regardless of whether a connection is actually established. SaaS solutions and open source components are not affected. Companies must first carry out a complete inventory of their products.

Step 2: Establish reporting processes

From 11 September 2026, actively exploited vulnerabilities and serious security incidents must be reported. The schedule is tight:

  • Initial report within 24 hours
  • Follow-up report within 72 hours
  • Final report no later than 14 days after a remedy becomes available

Companies that do not yet have internal processes for vulnerability management and incident response must establish them now – not as an IT project, but as an operational matter.

Step 3: Embed security by design

The CRA requires security to be part of product development from the outset. The biggest gaps arise where architectural decisions on authentication, data flow control and multi-tenancy are made without an explicit security perspective. SMEs do not need to aim for a perfect process, but must develop a demonstrable and documented approach.

Step 4: Inventory the supply chain and open source dependencies

Many products today consist of a combination of in-house development, open source libraries, cloud services and third-party components. The CRA addresses precisely these risks: manufacturers are also responsible for embedded third-party components. A Software Bill of Materials (SBOM) – a structured overview of all software components used – is the central tool for creating transparency and remaining able to act in an emergency.

Step 5: Make use of funding opportunities

Through the SECURE programme, the EU is providing a total of 16.5 million euros in direct financial support for SMEs that manufacture, develop or distribute products with digital elements. Eligible activities include risk analyses, penetration tests and security assessments. Companies with fewer than 250 employees and up to 50 million euros in annual turnover are entitled to apply.

Seeing regulation as a competitive advantage

The CRA requirements also open up strategic opportunities. Those who are CRA-compliant become the preferred partner in supply chains where clients will have to insist on demonstrable security standards in future. Conversely, anyone unable to deliver risks losing contracts.

Ari Albertini, CEO of FTAPI, emphasises: "The new regulations force companies to think about cybersecurity strategically. This is the moment that decides who will still be perceived as a reliable technology partner in the coming years. SMEs that act now are buying themselves a lead that others will no longer be able to close."

Outlook: the end of an era of voluntary cybersecurity

The CRA marks the end of an era in which cybersecurity was purely a matter for specialists. The BSI has already taken over the leadership of the European market surveillance group AdCo CRA, with Anna Schwendicke responsible for this task. Companies that regard security as an operational and strategic matter of course not only protect their products but also secure their long-term marketability in a regulated Europe.

The time for voluntary measures is running out. SMEs must act now in order to build the necessary CRA readiness by September 2026. Those who wait risk not only compliance problems but also the loss of important market opportunities in an increasingly security-conscious digital economy.