A New Compliance Discipline: Key Insights from Building the Kroll Cyber Resilience Act Framework | Kroll

Cyber

September 4, 2026

A New Compliance Discipline: Key Insights from Building the Kroll Cyber Resilience Act Framework

From September 11, 2026, manufacturers will be required to comply with the Cyber Resilience Act’s (CRA) vulnerability reporting and notification obligations. The broader CRA cybersecurity requirements applicable to products with digital elements become enforceable on December 11, 2027. With harmonized standards still under development, many organizations are now using the period between these milestones to assess and improve their readiness for implementation.

In response, the Kroll Risk Advisory team has developed a 62-control CRA Readiness Framework designed to help organizations assess, prioritize and improve their ability to meet CRA obligations across governance, product security, vulnerability management, incident reporting and supporting operating processes. The development process highlighted many areas that set up the CRA, and the steps required to comply with it, apart from other regulations. The development process highlighted many areas that set the CRA, and the steps required to comply with it, apart from other regulations.

This article provides an overview of these important differences and explains how Kroll's CRA Readiness Framework enables organizations to evaluate preparedness, identify capability gaps, and establish a practical roadmap toward CRA implementation. The framework is intended as a readiness assessment methodology, not a product-level compliance checklist or conformity assessment tool.

DOWNLOAD THE KROLL CRA FRAMEWORK PREVIEW

The Imperative for a CRA-Specific Framework

Every chief information security officer we work with already runs a credible security program. Most hold ISO 27001, many align with NIST CSF 2.0 and a few have layered in IEC 62443 or NIST SSDF for product engineering. The assumption is that those certifications carry them most of the way to CRA conformity, but this is not the case.

While the CRA ultimately applies to products with digital elements, organizations must first establish the governance, engineering, vulnerability management, reporting and lifecycle management capabilities required to demonstrate compliance. Our framework focuses on assessing those organizational capabilities and operating models that support CRA implementation across one or more product families This distinction changes who is accountable, what evidence is required and where the audit lands.

A connected multifunction printer manufacturer we advised this year held ISO 27001 across three sites and operated a mature software development life cycle (SDLC). Its progression gap to CRA readiness still amounted to nine months of net-new work, almost none of which was visible through the enterprise security program. That pattern repeats across sectors, which is why we developed a framework that evaluates organizational readiness specifically through the lens of CRA requirements, rather than relying solely on traditional enterprise security assessments

The Kroll Cyber Resilience Act Framework: Built Around Regulatory Focus

The Kroll CRA Readiness Framework consists of 62 controls structured across eight domains, derived from CRA Annex I, Annex II and Articles 13 to 28. The framework is designed to assess an organization's readiness to operationalize CRA requirements across its product portfolio rather than determine the compliance status of an individual product. It is important to note that each domain is weighted according to where the regulation places its emphasis, not where security teams are most comfortable.

A New Compliance Discipline: Key Insights from Building the Kroll Cyber Resilience Act Framework | Kroll

Product Security Design and Vulnerability Management together carry 45% of the weight. This is intentional. The CRA is, at its core, a product engineering regulation communicated in compliance language. In our view, treating it purely as a governance exercise is the fastest way to fail a conformity assessment.

A Readiness Assessment Model, Not a Compliance Checklist

The framework is intentionally designed as a readiness assessment rather than a compliance audit. A compliant/non-compliant determination is typically made during product-specific conformity assessment activities. Before that stage, organizations need visibility into the maturity of the capabilities that will ultimately support compliance. Manufacturers need to know where they are on the curve, what good looks like for their product class and how much runway they have to close the gap. We score every control on a six-point maturity scale to measure organizational capability, process maturity and operational effectiveness. The assessment highlights areas requiring investment before December 11, 2027, rather than issuing a pass/fail compliance outcome.

This matters operationally. A manufacturer at Level 2 in Vulnerability Management may have sufficient time to improve its capability before the December 11, 2027, CRA implementation date if it has a credible and funded remediation plan. By contrast, a manufacturer with no SBOM capability and no coordinated vulnerability disclosure process faces a significantly greater readiness challenge. The maturity model clearly defines the difference in a way that a red/amber/green dashboard does not.

Gap Severity Drives the Roadmap, Not the Other Way Around

Every gap is assigned a severity rating tied to a fixed remediation window. This is the part clients use most because it turns assessment output directly into a budgeted program plan.

A New Compliance Discipline: Key Insights from Building the Kroll Cyber Resilience Act Framework | Kroll

The pattern we see across engagements is consistent: Around a third of clients carry at least one Critical gap in the incident response or vulnerability management domain, and almost all carry at least one High in Technical Documentation. The remediation conversation becomes much easier when the timeline is mathematical rather than negotiable.

Cyber Resilience Act Cross-Mapping: Where the Certificates Help

We mapped all 62 controls against five widely adopted frameworks. The headline number is reassuring. Holding ISO/IEC 27001:2022 together with NIST CSF 2.0 gives a manufacturer roughly 92% topical coverage of the CRA: 36 controls map directly, 21 map partially and only five have no equivalent at all.

That is the good news. The bad news is in those five frameworks. They are the conformity assessment controls (CA.1 through CA.7 plus TD.7), and they sit at the regulatory core of the CRA: product classification documentation, CE marking procedures, DoC preparation, NB engagement, technical file compilation and the EU-specific update mechanism. No security framework addresses them because they were never security work. They are product safety regulation, borrowed wholesale from the world of CE marking on machinery and toys.

This is the gap that catches mature security organizations off guard. It is not a technical weakness; it is an entirely new compliance discipline, and it requires legal, regulatory affairs and product engineering to work together. The security team alone cannot close it.

Key Insights from Building the Kroll CRA Framework

Three notable findings have shaped how we run every CRA engagement since developing our framework:

  • The CRA is more prescriptive than security teams expect: It tells the manufacturer what the product must do at the device level, not what the organization should aspire to. “Secure by default” is not a principle here. It is a testable property with documentation requirements attached.
  • The partial-coverage controls are riskier than the no-coverage ones: The 21 partial mappings create a false sense of readiness. ISO 27001 A.8.8 covers vulnerability management at the organizational level. The CRA requires it per product, with mandatory coordinated disclosure, a public contact point and machine-readable advisories per product family. While this is topically adjacent, it is operationally a very different exercise.
  • The strongest ISO 27001 program we have seen still faces three to six months of net-new work to reach CRA conformity: The certificate is an asset, not a silver bullet. The companies that use it as a springboard are six months ahead of those using it as a shield.

The Urgent Need for a Defensible Approach

The harmonized standards will arrive, with the first draft European standards under the CRA expected to be in force throughout 2026 and into 2027. We will refresh the Kroll framework as they emerge. Until then, manufacturers need a structured way to assess their current status, plan what to fix and arrive ready for a NB audit, rather than merely audit-hopeful.

We have shared the Kroll CRA Framework with clients, peer reviewers and a small number of EU regulatory contacts. We are publishing the methodology openly because the CRA affects every connected-product manufacturer in the European market, and the harmonized standards will not arrive in time to help the December 2027 cohort. The earlier the industry converges on a defensible approach, the fewer products will be pulled from the shelves in 2028.

Download the Framework Preview

We have published a downloadable extract of the 62-control framework, including the eight domain weightings, the maturity model and a sample of the cross-mapping to ISO 27001 and NIST CSF 2.0. It is the same artifact we use in client kick-offs.

DOWNLOAD THE KROLL CRA FRAMEWORK PREVIEW

If you would like the full framework walkthrough with our advisory team, the link above also routes to our booking page.

The Kroll Cyber Risk Advisory team works with connected-product manufacturers across the EU on CRA readiness, conformity assessment preparation and ENISA reporting operations. We support over 3,000 incident response cases worldwide every year, which is where most of this framework was stress-tested before it ever reached a client deck.

Stay Ahead with Kroll

Cyber and Data Resilience

Kroll merges elite security and data risk expertise with frontline intelligence from thousands of incident responses and regulatory compliance, financial crime and due diligence engagements to make our clients more cyber- resilient.

Regulatory Compliance Assessments

Expert support to comply with a wide range of cybersecurity compliance requirements and build long-term cyber resilience.

DORA Compliance Assessment

Understand your gaps and prioritize key requirements for DORA compliance with guidance from Kroll experts.