From September 11, 2026, any manufacturer, importer or distributor of hardware and software products with digital elements made available on the EU market must comply with the Cyber Resilience Act (CRA). The harmonized standards under the CRA are still being drafted, and the first will not be finalized before manufacturers need to act. In response, the Kroll Risk Advisory team has developed a 62-control CRA Framework, drawing on its experience of supporting connected-product manufacturers across the EU with CRA readiness, conformity assessment preparation and European Union Agency for Cybersecurity (ENISA) reporting operations. The development process highlighted many areas that set the CRA, and the steps required to comply with it, apart from other regulations.
This article provides an overview of these important differences and sets out how Kroll’s CRA Framework enables manufacturers to address them, mitigating the potential pitfalls and complexities of compliance.



