From September 11, 2026, manufacturers will be required to comply with the Cyber Resilience Act’s (CRA) vulnerability reporting and notification obligations. The broader CRA cybersecurity requirements applicable to products with digital elements become enforceable on December 11, 2027. With harmonized standards still under development, many organizations are now using the period between these milestones to assess and improve their readiness for implementation.
In response, the Kroll Risk Advisory team has developed a 62-control CRA Readiness Framework designed to help organizations assess, prioritize and improve their ability to meet CRA obligations across governance, product security, vulnerability management, incident reporting and supporting operating processes. The development process highlighted many areas that set up the CRA, and the steps required to comply with it, apart from other regulations. The development process highlighted many areas that set the CRA, and the steps required to comply with it, apart from other regulations.
This article provides an overview of these important differences and explains how Kroll's CRA Readiness Framework enables organizations to evaluate preparedness, identify capability gaps, and establish a practical roadmap toward CRA implementation. The framework is intended as a readiness assessment methodology, not a product-level compliance checklist or conformity assessment tool.



