Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CRA compliance cost per product: EUR 18,400 self-assessment, EUR 25,000 third-party assessment, EUR 42,700 additional secure development

CRA Compliance Cost: The Complete 2026 Budget Breakdown

The CRA compliance cost is unusually hard to budget, because the single number most manufacturers want — what a notified body will charge to assess their product — does not exist yet. Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force on 10 December 2024. Its reporting duties started on 11 September 2026. Everything else applies from 11 December 2027. Yet as of 11 September 2026, not one conformity assessment body had been listed in the Commission’s NANDO database under the regulation, and no CRA harmonised standard had been cited in the Official Journal.

So this guide does two things. It prices the parts that can be priced, using the European Commission’s own impact assessment rather than vendor guesswork. And it is blunt about the parts nobody can price yet, because that gap is where most budgets will break.

Free gap assessment

Where do you stand on the Article 21 measures?

Score scope, all ten measures, the management-body duties and the reporting clocks, free.

Run the free NIS2 gap assessment →  or  View premium report sample

What the CRA compliance cost is made of

Four buckets, and they behave very differently. Two are one-off engineering spend, one is a gate you pass before shipping, and one never stops.

Cost bucketWhat triggers itWhen you pay
Secure product developmentAnnex I Part I essential requirements — secure default configuration, attack surface reduction, integrity and confidentiality controlsOnce per product, then at each substantial modification
Vulnerability handlingAnnex I Part II — SBOM, coordinated disclosure policy, security update distributionContinuous, for the whole support period
Conformity assessmentArticle 32 — internal control, or a notified body, depending on product classBefore placing on the market, and again after substantial modification
Documentation, CE marking and reportingAnnex VII technical documentation, the EU declaration of conformity, the CE mark, and Article 14 reporting to ENISAAt launch, then on every reportable event

Most published CRA compliance cost guides stop at bucket three. That is a mistake: the Commission’s own modelling puts more money in buckets one and four combined than in conformity assessment.

The Commission’s own figures for CRA compliance cost per product

The impact assessment behind the CRA proposal (SWD(2022) 282, published 15 September 2022) put euro figures on every bucket above. It is a public document, and almost nobody quotes it. Here is what it says at the level of a single product.

Line itemCommission estimateBasis given in the impact assessment
Development cost of an average product with digital elementsEUR 140,000Market modelling used as the unit for every other estimate
Additional secure development, per productEUR 42,700A 30.5% uplift on development cost where no comprehensive security measures are in place
Self-assessment (internal control)EUR 18,400One-off plus recurrent; roughly two FTE months at about EUR 29 per hour
Third-party assessment by a notified bodyEUR 25,000Averaged from France’s CSPN (EUR 25,000–35,000), the Dutch BSPA (about EUR 40,000) and Radio Equipment Directive estimates of EUR 5,000 to EUR 50,000 and above
Technical documentation, declaration of conformity, CE marking and ENISA reporting9% of product development costPrimary data collected for the supporting study

Two caveats matter more than the numbers. First, these are 2022 estimates against the proposal, not the regulation that was finally adopted. Second, and more usefully, the Commission did not treat those figures as net new spend. It assumed half of manufacturers already meet the security requirements, and applied business-as-usual factors of 40% for hardware and 25% for software — meaning a large share of the gross figure is money mature teams already spend.

The worked examples in the assessment make that concrete. Testing a router was costed at EUR 126,000 in total, but with business-as-usual at 90%, so the incremental bill is a tenth of the headline. Connected garden equipment came in at EUR 25,000 with only 20% business-as-usual, so almost all of it is new. Self-assessment of software for telecom networks and complex IT systems was put at EUR 30,000 to EUR 50,000, again with 90% already being done. The lesson is simple: your CRA compliance cost depends far less on your product’s price than on how much security engineering you already do.

Aggregated, the Commission expected the chosen option to cost businesses around EUR 29 billion — EUR 13.13 billion in secure development, EUR 8.1 billion in testing and EUR 7.8 billion in other conformity obligations — across a market of up to EUR 1,485 billion in turnover and 615,272 companies and products, 99.58% of them SMEs. That is roughly 2% of affected turnover, set against an expected reduction in incident costs of EUR 180 billion to EUR 290 billion a year.

CRA compliance cost by conformity assessment route

Article 32 decides whether you write a cheque to a notified body or not, and it is the largest single swing in any CRA budget. Our guide to CRA conformity assessment walks the modules in detail; the cost consequences look like this.

Product categoryRoute under Article 32Notified body?
Default products (the large majority)Internal control, module ANo
Annex III class I — important productsModule A only if harmonised standards, common specifications or a European cybersecurity certification scheme have been applied in full; otherwise module B plus C, or module HConditional
Annex III class II — important productsModule B plus C, module H, or a European cybersecurity certification scheme at assurance level substantialAlways
Annex IV — critical productsA European cybersecurity certification scheme under Article 8(1); failing that, the class II routesAlways

If you have not yet worked out which row you sit in, do that before costing anything — our CRA classification guide covers Annex III and Annex IV.

The variable that decides your CRA compliance cost in 2026

Read the class I row again. Self-assessment is available only where harmonised standards, common specifications or a certification scheme have been fully applied. None of those exists yet.

No CRA harmonised standard has been cited in the Official Journal. The deadlines in the standardisation request slipped by two months during 2026, moving the horizontal standards on secure development and vulnerability handling to 31 October 2026 and the product-specific ones to the end of December 2026; seventeen vertical ETSI drafts went to public enquiry with comment windows closing between mid-September and mid-November 2026. Citation in the Official Journal comes after all that, not with it.

Meanwhile the supply side is empty. Chapter IV, the rules on notifying conformity assessment bodies, has applied since 11 June 2026, and NANDO still showed zero notified bodies under Regulation (EU) 2024/2847 on 11 September 2026. Article 35(2) only asks Member States to strive to ensure a sufficient number by 11 December 2026 — a best-efforts target, not a binding one.

The budgeting consequence is uncomfortable but honest. If you make an Annex III class I product, you cannot assume the cheap route, because the standard that unlocks it may not be citable in time. And the EUR 25,000 third-party figure above was modelled on a functioning market. A scarce one prices differently. Carry a contingency on that line, not a point estimate.

What you are already paying for, since September 2026

There is one part of the CRA compliance cost that is not a 2027 problem. Article 69(3) applies the Article 14 reporting duties to every in-scope product placed on the market before 11 December 2027, whether or not it is ever modified. Almost every other EU digital rule sells against a future obligation. This one is live now.

The clocks are short. For an actively exploited vulnerability: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. For a severe incident: 24 hours, 72 hours, then a final report within one month of the notification. ENISA’s single reporting platform went live on 11 September 2026. The spend here is not a licence fee — it is an out-of-hours rota, a triage procedure and a named person who can decide within a day. Budget it as headcount time. Our CRA reporting deadline guide sets out the full sequence.

A realistic three-year model

The CRA compliance cost figures below are our own arithmetic applied to the Commission’s unit costs, not a published estimate, and they assume one product, one market and no substantial modification. Treat them as typical ranges for planning.

ScenarioYear 1Years 2 and 3, combined
Default product, self-assessed, team already doing secure developmentEUR 20,000–45,000EUR 10,000–25,000
Default product, security programme starting from a low baseEUR 55,000–90,000EUR 15,000–35,000
Annex III class I, harmonised standard available and appliedEUR 35,000–70,000EUR 15,000–35,000
Annex III class I or II routed to a notified bodyEUR 60,000–130,000EUR 25,000–60,000

The recurring years are not small, and that surprises people. Vulnerability handling, security update distribution and reporting readiness run for the whole support period, which Article 13(8) sets at a minimum of five years, or the expected use time where that is shorter. Article 13(9) then requires each security update to stay available for at least ten years after it is issued, or the remainder of the support period if that is longer. A product shipped in 2028 can still be generating compliance obligations in 2043.

Four ways to cut the CRA compliance cost

Three of these levers are written into the regulation and are routinely left on the table.

Ask for the SME fee reduction. Article 32(6) requires that conformity assessment fees take the interests and needs of microenterprises and SMEs into account, and that they be reduced proportionately. Put the request in writing when you approach a body, and keep the reply.

Use the simplified technical documentation form. Article 33(5) lets microenterprises and small enterprises supply every element of the Annex VII technical documentation in a simplified format, to be specified by the Commission in an implementing act — and notified bodies shall accept that form. Watch for its publication before you commission a full documentation package.

Apply a harmonised standard the day one is cited. For a class I product that single act moves you from a notified body back to internal control. It is the largest discount available under the regulation.

Reuse the management system you already run. Annex I Part II vulnerability handling maps closely onto processes an ISO 27001 or IEC 62443 programme already documents. If you run one, you are not starting at zero — and the same logic that makes NIS2 compliance cost lower for certified organisations applies here. The Commission also published free practical guidance on 27 July 2026 (Communication C(2026) 5252), with 67 worked examples aimed squarely at smaller manufacturers.

What getting it wrong costs

Article 64 sets three tiers. Failing the Annex I essential requirements or the Article 13 and 14 obligations attracts fines of up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher. A second tier, covering obligations including those on importers, distributors, technical documentation and conformity assessment procedures, reaches EUR 10 million or 2%. Supplying incorrect, incomplete or misleading information to a notified body or a market surveillance authority reaches EUR 5 million or 1%. Microenterprises and small enterprises are carved out of fines for missing the specific early-warning deadlines in Article 14(2)(a) and 14(4)(a). Our breakdown of CRA penalties has the full list.

CRA compliance cost FAQ

How much does CRA compliance cost for one product? Using the Commission’s unit figures, a self-assessed product sits in the region of EUR 20,000 to EUR 90,000 in the first year depending on how much secure development you already do, with a notified body adding roughly EUR 25,000 in a normal market. Recurring costs are driven by the support period, not by the assessment.

Do I need a notified body? Only if your product is in Annex III or Annex IV. Class II and Annex IV products always involve a third party. Class I products need one unless you have fully applied a harmonised standard, common specification or certification scheme — and none is available yet.

Is there an annual CRA certification fee? No. The CRA is CE marking, not certification: there is no certificate to renew and no annual licence. Where module H applies, the quality system is subject to ongoing surveillance by the notified body, which does carry a recurring fee.

Does the CRA compliance cost apply to open source? Free and open-source software developed or supplied outside a commercial activity is largely out of scope, and Article 32(5) lets in-scope FOSS manufacturers use the Article 32(1) procedures provided the Annex VII technical documentation is made public when the product is placed on the market.

When does the spending actually start? It already has. Article 14 reporting has applied since 11 September 2026, including to products placed on the market years ago.

Where to start

The honest summary is that the engineering half of the CRA compliance cost is knowable today and the assessment half is not, so the sensible order is to spend on what you control: classification, Annex I evidence, vulnerability handling, and a reporting process that can move in 24 hours. Documentation is the part most manufacturers underestimate and the part that transfers directly into a notified body’s review fee if it is thin.

If you would rather not draft Annex VII from scratch, our EU CRA Toolkit gives you 74 editable templates covering classification, essential requirements, vulnerability handling, technical documentation, conformity assessment and the Article 14 reporting workflow, for $99. For the wider picture, start with our pillar guide to the EU Cyber Resilience Act, and read the official position on the European Commission’s Cyber Resilience Act page.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.