Manage CRA compliance
continuously, scalably and auditably.
The Cyber Resilience Act (CRA) introduces new obligations regarding product cybersecurity, vulnerability management, incident response, and maintaining compliance throughout the product lifecycle. From December 2027, organizations will also be required to maintain auditable documentation and demonstrate compliance with security requirements through self-assessment or notified body assessment.
It’s a lot of work! What is an effective way to achieve this?
The PREMIS web application is helpful, supporting teamwork on CRA compliance using process automation, enabling integration with security tools and CI/CD pipelines for continuous monitoring of CRA requirements
and reporting results to management.
Goal-oriented compliance
PREMIS provides a logical layout of the CRA’s requirements and the evidence expected. Regulations introduce hundreds of requirements that are formally described from the regulator’s point of view. PREMIS presents them from the point of view of actions and results.
Each action and each result is connected to compliance goals. This removes redundant documentation. Conversely, each compliance objective or requirement has a clearly defined set of documents and data that provide evidence of compliance.
At each moment you see what needs to be done and how complete the collected evidence is. This information is constantly updated, providing access to the conformance current status.
This gives up-to-date information on how complete the evidence is and where the issues lie. Source data comes from system documentation, but also from security testing tools, task management systems, vulnerabilities and inconsistencies, and the CI/CD pipeline.
What will you find in PREMIS?
PREMIS provides a collection of compliance requirements for the CRA Regulation, covering 12 areas. Each area includes a list of requirements with descriptions and cross-references to the Regulation, expected evidence and records, information on what auditors are looking for, common issues, and recommendations.
You can link your documentation and records as evidence of compliance in PREMIS, enabling auditors to review them to verify compliance. Compliance documentation is monitored for validity and changes. Data and reports from IT systems with dynamic content can also be used as evidence of compliance. This is an ongoing process, not a one-time snapshot of compliance status.
Comments and ratings are saved in the application and used in reports. This provides an up-to-date picture of the compliance level and identifies areas requiring improvement. The systematic nature of the process ensures the thoroughness of compliance audit activities and enables issues to be detected quickly before they are escalated.
The CRA requirements are divided into 12 areas. The areas shaded bright yellow must be implemented by 11 September 2026. These are activities related to reporting exploited vulnerabilities and serious incidents. Activities relating to governance, component management and traceability must also be partially implemented.
What can you gain by using PREMIS?
Achieve compliance faster and more cost-effectively
PREMIS templates provide a straightforward starting point and facilitate rapid progress, while ongoing communication ensures problems are resolved quickly. You have effective control over requirements, evidence and the compliance level.
Be audit-ready
at all times!
Compliance evidence is available and organised on an ongoing basis, not just during audit preparations.
The validity of the evidence and
the need for updates are monitored and reported. This helps
in maintaining audit readiness.
Reduce the risk
of missing requirements
Linking requirements to evidence and responsibilities makes it easier to identify gaps and monitor corrective actions. PREMIS connects all conformance-related information
and provides a knowledge base
that supports the entire process.
Compliance checks
in one place
Integration and centralisation of information reduces the need to search for information across multiple systems and spreadsheets. You avoid many misunderstandings by integrating knowledge in one place.
Scalable compliance management
This single platform can support multiple products, teams, suppliers and standards simultaneously. The compliance module structure can be adapted dynamically to meet the needs of your organisation and any changes that occur.
How does PREMIS support CRA?
PREMIS allows you to build a complete compliance management system, including:
- CRA requirements and their decomposition into detailed tasks and responsibilities,
- assigning responsibilities for meeting CRA requirements,
- collecting and assessing compliance evidence,
- automatic data flow from security tools and CI/CD pipeline,
- traceability between requirements, risks, documentation, and products,
- real-time compliance status monitoring,
- managing compliance gaps and action plans,
- controlling changes that impact compliance,
- maintaining audit readiness.
With a goal-oriented compliance approach, an organisation can easily demonstrate which requirements have been met, what evidence supports this and what actions remain to be taken.
Collaboration between the teams involved
PREMIS is a collaboration and communication platform for all stakeholders:
- Management has constant visibility into compliance levels and threats
- Compliance teams manage compliance templates and control the process
- Quality teams focus on process and auditing
- Production and DevSecOps teams receive clear information on what they should provide
- Security teams actively manage vulnerabilities and respond to incidents
- Other teams address cyber resilience in customer and supplier relationships
The compliance team knows what’s happening, and the IT team knows what’s expected of them.
Everyone can access the compliance project in PREMIS to provide data and compliance evidence, review, comment and evaluate, track changes, conduct analyses, plan compliance work, and report.
Traceability of requirements and evidence
One of the biggest challenges associated with CRA is managing the large number of requirements, procedures, analyses, and documents. PREMIS enables the creation of links between:
- regulatory requirements,
- risk assessments,
- threat models,
- SBOM and product models,
- incident register,
- organisational procedures,
- security test results,
- technical documentation,
- conformance declarations,
- corrective actions.
As a result, organizations can trace the path from a CRA requirement to specific proof of its implementation at any time.
Automated data flows are documented, and the source data and its owner can always be identified.
Audit readiness
PREMIS uses an advanced RBAC (Role-Based Access Control) model for user permission management, ensuring the required level of confidentiality and adherence to the principle of least privilege. Authorised individuals are always provided with up-to-date information on:
- compliance levels based on ongoing reviews and audits,
- changes to compliance requirements or evidence (when they occur),
- the status of reported non-compliances and comments,
- the validity of evidence and any updates needed.
Data in PREMIS is linked and updated automatically, enabling management to access aggregated data on audit readiness levels and operational teams to track tasks relating to specific compliance requirements and evidence. In the case of CRA, a significant proportion of the evidence comprises electronic artefacts in vulnerability and incident management systems, as well as in the CI/CD pipeline.
Scaling for product portfolio
CRA applies to the entire product portfolio, not a single project.
PREMIS allows you to:
- reuse compliance templates,
- manage compliance of multiple products simultaneously,
- apply a consistent approach across teams,
- monitor supplier and subcontractor compliance,
- conduct compliance self-assessments of product versions.
This ensures that the compliance process remains effective,
even within large organisations that manage multiple products and teams.
How to use PREMIS?
PREMIS Online
The PREMIS Online service allows for quick deployment
without any infrastructure investment. PREMIS can be deployed
in the cloud environment of your choice, including Azure or AWS.
Key benefits:
- Fast service launch
- Easy access for everyone
- The ability to start with a small number of users
- High security level and 24/7 monitoring
- SLA agreement available
Self-hosting
PREMIS licences are available for organisations requiring full control over their environment to install on their own infrastructure or private cloud. PREMIS is delivered as a scalable solution in a container architecture.
Key benefits:
- Full control over the data
- Implementation of your organisation security policies
- Easy integration with your internal systems
- Tool customization to your specific needs
Regardless of the chosen implementation method, we support our users in adapting PREMIS to industry requirements and integrating it with other systems. We also develop software that works with PREMIS.
Start today!
PREMIS helps transform CRA compliance from a one-time project into a structured, repeatable, and scalable process. Start with one product and see the efficiency of the PREMIS-supported process.
Want to start quickly and work online?
Need a license for self-hosting?