Building CRA conformance with PREMIS

PREMIS implements a goal-oriented approach, which is effective in achieving and controlling compliance with regulations such as the CRA (Cyber Resilience Act). Achieving cyber resilience requires coordinated processes and maintaining the consistency and currency of many of their results as evidence of compliance. PREMIS makes this easier. There is no substitute for an efficient technical process for monitoring cybersecurity or handling vulnerabilities and incidents, but effective oversight of all processes to achieve and maintain compliance with CRA and other related regulations and standards is equally important.

CRA goes into effect

The Cyber Resilience Act introduces new requirements for manufacturers of products containing digital elements. These include product cybersecurity, vulnerability management, incident reporting, technical documentation, compliance assessment, and security maintenance throughout the product’s support lifecycle.
The regulation is being implemented in two stages. From September 11, 2026, it becomes mandatory to notify actively exploited vulnerabilities and serious incidents.

The full application of the regulation – including but not limited to product safety requirements, secure updates, technical documentation, conformity assessment and cooperation with authorities – will be required from 11 December 2027. It is worth implementing new areas gradually to consistently build and maintain a high level of cyber resilience of products.

The areas of CRA requirements and the scope applicable to each of the two stages of the implementation of the regulation are shown in the tables below. This layout is mapped in the compliance template in PREMIS.

CRA compliance requirements

How does PREMIS supports CRA compliance?

Goal-oriented compliance means managing relationships between compliance objectives, specific requirements, and records and evidence of compliance. For CRA, this is complemented by relations between product versions, threat models, SBOMs, security testing and corrective actions, and technical documentation. This allows you to trace the path from a single CRA requirement to a specific proof of its implementation. This evidence is monitored and kept up to date. Thanks to this, audit readiness is maintained and there is no problem of preparing documentation only during the preparation for the audit.

Key capabilities of PREMIS include:
‒ decomposition of CRA requirements into specific, enforceable duties,
‒ assigning responsibility for the implementation of individual requirements,
‒ collecting and assessing evidence of compliance along with checking its up-to-dateness,
‒ support for communication of all people involved for quick detection and resolution of problems,
‒ traceability between requirements, risks, documentation and products,
‒ Real-time compliance status monitoring,
‒ maintaining audit readiness.

CRA does not apply to a single project, but to the entire product portfolio of an organization. PREMIS enables you to reuse compliance templates, manage multiple products at once, apply a unified approach across teams, and monitor supplier and subcontractor compliance. This ensures that the process remains efficient even in large organizations that manage multiple products and versions.

Continuous process for audit readiness

PREMIS helps transform CRA compliance from a one-time project into a structured, repeatable, and scalable process. An organization can start with a single product and then expand seamlessly into other CRA areas, as well as related regulations and standards. Throughout this growth, it maintains consistency, timeliness, and control over all processes. This is possible thanks to a goal-oriented approach, full traceability of requirements and evidence, and ongoing audit readiness.

The template contains about 100 requirements with suggested evidence and recommendations and comments on what auditors are looking for. At the same time, it is a platform for cooperation between different people and teams. The compliance team typically manages the entire compliance model, and individual teams, including DevSecOps, provide evidence of compliance. Much of this data can be automatically processed by PREMIS, but human supervision over the processes is still crucial.

CRA is a product cybersecurity regulation, and some organizations may also be subject to standards or regulations related to organizational security, such as NIS 2 or ISO 27001. These are two distinct perspectives, but their implementation shares common security controls. The processes are therefore highly integrated. Even so, each regulation or standard requires its own separate compliance demonstration.

The CRA template is easy to use and gives a lot of information and recommendations to support the process. Read more information on the CRA service page. Write to us when you have any questions. We will be happy to support you in an effective implementation