The CRA compliance cost is unusually hard to budget, because the single number most manufacturers want — what a notified body will charge to assess their product — does not exist yet. Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force on 10 December 2024. Its reporting duties started on 11 September 2026. Everything else applies from 11 December 2027. Yet as of 11 September 2026, not one conformity assessment body had been listed in the Commission’s NANDO database under the regulation, and no CRA harmonised standard had been cited in the Official Journal.
So this guide does two things. It prices the parts that can be priced, using the European Commission’s own impact assessment rather than vendor guesswork. And it is blunt about the parts nobody can price yet, because that gap is where most budgets will break.
Free gap assessment
Where do you stand on the Article 21 measures?
Score scope, all ten measures, the management-body duties and the reporting clocks, free.
Run the free NIS2 gap assessment → or View premium report sample
What the CRA compliance cost is made of
Four buckets, and they behave very differently. Two are one-off engineering spend, one is a gate you pass before shipping, and one never stops.
| Cost bucket | What triggers it | When you pay |
|---|---|---|
| Secure product development | Annex I Part I essential requirements — secure default configuration, attack surface reduction, integrity and confidentiality controls | Once per product, then at each substantial modification |
| Vulnerability handling | Annex I Part II — SBOM, coordinated disclosure policy, security update distribution | Continuous, for the whole support period |
| Conformity assessment | Article 32 — internal control, or a notified body, depending on product class | Before placing on the market, and again after substantial modification |
| Documentation, CE marking and reporting | Annex VII technical documentation, the EU declaration of conformity, the CE mark, and Article 14 reporting to ENISA | At launch, then on every reportable event |
Most published CRA compliance cost guides stop at bucket three. That is a mistake: the Commission’s own modelling puts more money in buckets one and four combined than in conformity assessment.
The Commission’s own figures for CRA compliance cost per product
The impact assessment behind the CRA proposal (SWD(2022) 282, published 15 September 2022) put euro figures on every bucket above. It is a public document, and almost nobody quotes it. Here is what it says at the level of a single product.
| Line item | Commission estimate | Basis given in the impact assessment |
|---|---|---|
| Development cost of an average product with digital elements | EUR 140,000 | Market modelling used as the unit for every other estimate |
| Additional secure development, per product | EUR 42,700 | A 30.5% uplift on development cost where no comprehensive security measures are in place |
| Self-assessment (internal control) | EUR 18,400 | One-off plus recurrent; roughly two FTE months at about EUR 29 per hour |
| Third-party assessment by a notified body | EUR 25,000 | Averaged from France’s CSPN (EUR 25,000–35,000), the Dutch BSPA (about EUR 40,000) and Radio Equipment Directive estimates of EUR 5,000 to EUR 50,000 and above |
| Technical documentation, declaration of conformity, CE marking and ENISA reporting | 9% of product development cost | Primary data collected for the supporting study |
Two caveats matter more than the numbers. First, these are 2022 estimates against the proposal, not the regulation that was finally adopted. Second, and more usefully, the Commission did not treat those figures as net new spend. It assumed half of manufacturers already meet the security requirements, and applied business-as-usual factors of 40% for hardware and 25% for software — meaning a large share of the gross figure is money mature teams already spend.
The worked examples in the assessment make that concrete. Testing a router was costed at EUR 126,000 in total, but with business-as-usual at 90%, so the incremental bill is a tenth of the headline. Connected garden equipment came in at EUR 25,000 with only 20% business-as-usual, so almost all of it is new. Self-assessment of software for telecom networks and complex IT systems was put at EUR 30,000 to EUR 50,000, again with 90% already being done. The lesson is simple: your CRA compliance cost depends far less on your product’s price than on how much security engineering you already do.
Aggregated, the Commission expected the chosen option to cost businesses around EUR 29 billion — EUR 13.13 billion in secure development, EUR 8.1 billion in testing and EUR 7.8 billion in other conformity obligations — across a market of up to EUR 1,485 billion in turnover and 615,272 companies and products, 99.58% of them SMEs. That is roughly 2% of affected turnover, set against an expected reduction in incident costs of EUR 180 billion to EUR 290 billion a year.
CRA compliance cost by conformity assessment route
Article 32 decides whether you write a cheque to a notified body or not, and it is the largest single swing in any CRA budget. Our guide to CRA conformity assessment walks the modules in detail; the cost consequences look like this.
| Product category | Route under Article 32 | Notified body? |
|---|---|---|
| Default products (the large majority) | Internal control, module A | No |
| Annex III class I — important products | Module A only if harmonised standards, common specifications or a European cybersecurity certification scheme have been applied in full; otherwise module B plus C, or module H | Conditional |
| Annex III class II — important products | Module B plus C, module H, or a European cybersecurity certification scheme at assurance level substantial | Always |
| Annex IV — critical products | A European cybersecurity certification scheme under Article 8(1); failing that, the class II routes | Always |
If you have not yet worked out which row you sit in, do that before costing anything — our CRA classification guide covers Annex III and Annex IV.
The variable that decides your CRA compliance cost in 2026
Read the class I row again. Self-assessment is available only where harmonised standards, common specifications or a certification scheme have been fully applied. None of those exists yet.
No CRA harmonised standard has been cited in the Official Journal. The deadlines in the standardisation request slipped by two months during 2026, moving the horizontal standards on secure development and vulnerability handling to 31 October 2026 and the product-specific ones to the end of December 2026; seventeen vertical ETSI drafts went to public enquiry with comment windows closing between mid-September and mid-November 2026. Citation in the Official Journal comes after all that, not with it.
Meanwhile the supply side is empty. Chapter IV, the rules on notifying conformity assessment bodies, has applied since 11 June 2026, and NANDO still showed zero notified bodies under Regulation (EU) 2024/2847 on 11 September 2026. Article 35(2) only asks Member States to strive to ensure a sufficient number by 11 December 2026 — a best-efforts target, not a binding one.
The budgeting consequence is uncomfortable but honest. If you make an Annex III class I product, you cannot assume the cheap route, because the standard that unlocks it may not be citable in time. And the EUR 25,000 third-party figure above was modelled on a functioning market. A scarce one prices differently. Carry a contingency on that line, not a point estimate.
What you are already paying for, since September 2026
There is one part of the CRA compliance cost that is not a 2027 problem. Article 69(3) applies the Article 14 reporting duties to every in-scope product placed on the market before 11 December 2027, whether or not it is ever modified. Almost every other EU digital rule sells against a future obligation. This one is live now.
The clocks are short. For an actively exploited vulnerability: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. For a severe incident: 24 hours, 72 hours, then a final report within one month of the notification. ENISA’s single reporting platform went live on 11 September 2026. The spend here is not a licence fee — it is an out-of-hours rota, a triage procedure and a named person who can decide within a day. Budget it as headcount time. Our CRA reporting deadline guide sets out the full sequence.
A realistic three-year model
The CRA compliance cost figures below are our own arithmetic applied to the Commission’s unit costs, not a published estimate, and they assume one product, one market and no substantial modification. Treat them as typical ranges for planning.
| Scenario | Year 1 | Years 2 and 3, combined |
|---|---|---|
| Default product, self-assessed, team already doing secure development | EUR 20,000–45,000 | EUR 10,000–25,000 |
| Default product, security programme starting from a low base | EUR 55,000–90,000 | EUR 15,000–35,000 |
| Annex III class I, harmonised standard available and applied | EUR 35,000–70,000 | EUR 15,000–35,000 |
| Annex III class I or II routed to a notified body | EUR 60,000–130,000 | EUR 25,000–60,000 |
The recurring years are not small, and that surprises people. Vulnerability handling, security update distribution and reporting readiness run for the whole support period, which Article 13(8) sets at a minimum of five years, or the expected use time where that is shorter. Article 13(9) then requires each security update to stay available for at least ten years after it is issued, or the remainder of the support period if that is longer. A product shipped in 2028 can still be generating compliance obligations in 2043.
Four ways to cut the CRA compliance cost
Three of these levers are written into the regulation and are routinely left on the table.
Ask for the SME fee reduction. Article 32(6) requires that conformity assessment fees take the interests and needs of microenterprises and SMEs into account, and that they be reduced proportionately. Put the request in writing when you approach a body, and keep the reply.
Use the simplified technical documentation form. Article 33(5) lets microenterprises and small enterprises supply every element of the Annex VII technical documentation in a simplified format, to be specified by the Commission in an implementing act — and notified bodies shall accept that form. Watch for its publication before you commission a full documentation package.
Apply a harmonised standard the day one is cited. For a class I product that single act moves you from a notified body back to internal control. It is the largest discount available under the regulation.
Reuse the management system you already run. Annex I Part II vulnerability handling maps closely onto processes an ISO 27001 or IEC 62443 programme already documents. If you run one, you are not starting at zero — and the same logic that makes NIS2 compliance cost lower for certified organisations applies here. The Commission also published free practical guidance on 27 July 2026 (Communication C(2026) 5252), with 67 worked examples aimed squarely at smaller manufacturers.
What getting it wrong costs
Article 64 sets three tiers. Failing the Annex I essential requirements or the Article 13 and 14 obligations attracts fines of up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher. A second tier, covering obligations including those on importers, distributors, technical documentation and conformity assessment procedures, reaches EUR 10 million or 2%. Supplying incorrect, incomplete or misleading information to a notified body or a market surveillance authority reaches EUR 5 million or 1%. Microenterprises and small enterprises are carved out of fines for missing the specific early-warning deadlines in Article 14(2)(a) and 14(4)(a). Our breakdown of CRA penalties has the full list.
CRA compliance cost FAQ
How much does CRA compliance cost for one product? Using the Commission’s unit figures, a self-assessed product sits in the region of EUR 20,000 to EUR 90,000 in the first year depending on how much secure development you already do, with a notified body adding roughly EUR 25,000 in a normal market. Recurring costs are driven by the support period, not by the assessment.
Do I need a notified body? Only if your product is in Annex III or Annex IV. Class II and Annex IV products always involve a third party. Class I products need one unless you have fully applied a harmonised standard, common specification or certification scheme — and none is available yet.
Is there an annual CRA certification fee? No. The CRA is CE marking, not certification: there is no certificate to renew and no annual licence. Where module H applies, the quality system is subject to ongoing surveillance by the notified body, which does carry a recurring fee.
Does the CRA compliance cost apply to open source? Free and open-source software developed or supplied outside a commercial activity is largely out of scope, and Article 32(5) lets in-scope FOSS manufacturers use the Article 32(1) procedures provided the Annex VII technical documentation is made public when the product is placed on the market.
When does the spending actually start? It already has. Article 14 reporting has applied since 11 September 2026, including to products placed on the market years ago.
Where to start
The honest summary is that the engineering half of the CRA compliance cost is knowable today and the assessment half is not, so the sensible order is to spend on what you control: classification, Annex I evidence, vulnerability handling, and a reporting process that can move in 24 hours. Documentation is the part most manufacturers underestimate and the part that transfers directly into a notified body’s review fee if it is thin.
If you would rather not draft Annex VII from scratch, our EU CRA Toolkit gives you 74 editable templates covering classification, essential requirements, vulnerability handling, technical documentation, conformity assessment and the Article 14 reporting workflow, for $99. For the wider picture, start with our pillar guide to the EU Cyber Resilience Act, and read the official position on the European Commission’s Cyber Resilience Act page.