CRA – Cyber Resilience Act

Manage CRA compliance
continuously, scalably and auditably.

The Cyber Resilience Act (CRA) introduces new obligations regarding product cybersecurity, vulnerability management, incident response, and maintaining compliance throughout the product lifecycle. From December 2027, organizations will also be required to maintain auditable documentation and demonstrate compliance with security requirements through self-assessment or notified body assessment.

It’s a lot of work! What is an effective way to achieve this? 

The PREMIS web application is helpful, supporting teamwork on CRA compliance using process automationenabling integration with security tools and CI/CD pipelines for continuous monitoring of CRA requirements
and reporting results to management.

Goal-oriented compliance

PREMIS provides a logical layout of the CRA’s requirements and the evidence expected. Regulations introduce hundreds of requirements that are formally described from the regulator’s point of view. PREMIS presents them from the point of view of actions and results

Each action and each result is connected to compliance goals. This removes redundant documentation. Conversely, each compliance objective or requirement has a clearly defined set of documents and data that provide evidence of compliance. 

At each moment you see what needs to be done and how complete the collected evidence is. This information is constantly updated, providing access to the conformance current status.

This gives up-to-date information on how complete the evidence is and where the issues lie. Source data comes from system documentation, but also from security testing tools, task management systems, vulnerabilities and inconsistencies, and the CI/CD pipeline.

What will you find in PREMIS?

PREMIS provides a collection of compliance requirements for the CRA Regulation, covering 12 areas. Each area includes a list of requirements with descriptions and cross-references to the Regulation, expected evidence and records, information on what auditors are looking for, common issues, and recommendations.

You can link your documentation and records as evidence of compliance in PREMIS, enabling auditors to review them to verify compliance. Compliance documentation is monitored for validity and changes. Data and reports from IT systems with dynamic content can also be used as evidence of compliance. This is an ongoing process, not a one-time snapshot of compliance status.

Comments and ratings are saved in the application and used in reports. This provides an up-to-date picture of the compliance level and identifies areas requiring improvement. The systematic nature of the process ensures the thoroughness of compliance audit activities and enables issues to be detected quickly before they are escalated.

Cyber Resilience Act Compliance Architecture
The CRA requirements are divided into 12 areas. The areas shaded bright yellow must be implemented by 11 September 2026. These are activities related to reporting exploited vulnerabilities and serious incidents. Activities relating to governance, component management and traceability must also be partially implemented.

What can you gain by using PREMIS?

Achieve compliance faster and more cost-effectively

PREMIS templates provide a straightforward starting point and facilitate rapid progress, while ongoing communication ensures problems are resolved quickly. You have effective control over requirements, evidence and the compliance level.

Be audit-ready
at all times!

Compliance evidence is available and organised on an ongoing basis, not just during audit preparations.
The validity of the evidence and
the need for updates are monitored and reported. This helps
in maintaining audit readiness.

Reduce the risk
of missing requirements

Linking requirements to evidence and responsibilities makes it easier to identify gaps and monitor corrective actions. PREMIS connects all conformance-related information
and provides a knowledge base
that supports the entire process.

Compliance checks
in one place

Integration and centralisation of information reduces the need to search for information across multiple systems and spreadsheets. You avoid many misunderstandings by integrating knowledge in one place.

Scalable compliance management

This single platform can support multiple products, teams, suppliers and standards simultaneously. The compliance module structure can be adapted dynamically to meet the needs of your organisation and any changes that occur.

How does PREMIS support CRA?

PREMIS allows you to build a complete compliance management system, including:

With a goal-oriented compliance approach, an organisation can easily demonstrate which requirements have been met, what evidence supports this and what actions remain to be taken.

Scope of CRA conformance verification

Collaboration between the teams involved

PREMIS is a collaboration and communication platform for all stakeholders:

conformance consultant gives advice for a security standard

The compliance team knows what’s happening, and the IT team knows what’s expected of them.

Everyone can access the compliance project in PREMIS to provide data and compliance evidence, review, comment and evaluate, track changes, conduct analyses, plan compliance work, and report.

Traceability of requirements and evidence

One of the biggest challenges associated with CRA is managing the large number of requirements, procedures, analyses, and documents. PREMIS enables the creation of links between:

Traceability

As a result, organizations can trace the path from a CRA requirement to specific proof of its implementation at any time.
Automated data flows are documented, and the source data and its owner can always be identified.

Audit readiness

PREMIS uses an advanced RBAC (Role-Based Access Control) model for user permission management, ensuring the required level of confidentiality and adherence to the principle of least privilege. Authorised individuals are always provided with up-to-date information on:

Data in PREMIS is linked and updated automatically, enabling management to access aggregated data on audit readiness levels and operational teams to track tasks relating to specific compliance requirements and evidence. In the case of CRA, a significant proportion of the evidence comprises electronic artefacts in vulnerability and incident management systems, as well as in the CI/CD pipeline.

CRA audit readiness

Scaling for product portfolio

CRA applies to the entire product portfolio, not a single project.

PREMIS allows you to:

This ensures that the compliance process remains effective,
even within large organisations that manage multiple products and teams.

Zgodność CRA dla portfolio produktów

How to use PREMIS?

PREMIS Online

The PREMIS Online service allows for quick deployment
without any infrastructure investment. PREMIS can be deployed
in the cloud environment of your choice, including Azure or AWS.

Key benefits:

Self-hosting

PREMIS licences are available for organisations requiring full control over their environment to install on their own infrastructure or private cloud. PREMIS is delivered as a scalable solution in a container architecture.

Key benefits:

Regardless of the chosen implementation method, we support our users in adapting PREMIS to industry requirements and integrating it with other systems. We also develop software that works with PREMIS.

Start today!

PREMIS helps transform CRA compliance from a one-time project into a structured, repeatable, and scalable process. Start with one product and see the efficiency of the PREMIS-supported process.

Want to start quickly and work online?

Need a license for self-hosting?