The Cyber Resilience Act (CRA) introduces uniform, binding cybersecurity requirements for products with digital elements within the EU. Swiss companies are also affected: any company offering products or software on the EU market – including via online channels – falls under the CRA, regardless of where it is based.
Swiss Infosec AG supports you every step of the way, from the initial impact assessment through to full compliance.
CRA deadlines at a glance: the three key deadlines

11 June 2026
Conformity assessment bodies
The notification of conformity assessment bodies (Articles 35–51 CRA) comes into force. Important for manufacturers: from this date, notified bodies will be available to carry out conformity assessments.

11 September 2026 – Key deadline for manufacturers
Mandatory reporting of vulnerabilities and incidents
The requirement to report actively exploited vulnerabilities to the relevant national CSIRT and ENISA within 24 hours (Art. 14 CRA) comes into force. From this date, manufacturers must have an operational reporting process in place for vulnerabilities and incidents.

11 December 2027
Full implementation of all CRA requirements
CE marking, Software Bill of Materials (SBOM), Security by Design and conformity assessment will become fully applicable for all affected products. Manufacturers who start today will have sufficient time.
Why Swiss Infosec AG? Your advantages at a glance
- More than 35 years of experience in information security
- ISO 27001 Lead Auditors and Implementers – we have in-depth knowledge of the standard
- EU Authorised Representative: Swiss Infosec (Deutschland) GmbH will assume the legal obligation to act as your representative in the EU from December 2027
- Based in Switzerland – familiar with Swiss and EU regulations
Who is affected? Does the CRA apply to your business?
The Cyber Resilience Act applies to all products with digital elements marketed in the EU – regardless of whether the manufacturer is based in the EU. Swiss companies are subject to the same requirements as EU manufacturers.
01 – Software companies
Application software, SaaS products, operating systems and middleware distributed within the EU. This also includes open-source components in commercial products, provided that the product is distributed commercially.
02 – IoT and hardware companies
Connected devices, industrial systems with remote access, smart home products, network components such as routers and switches – in short: anything with a logical or physical data connection to the internet or to other devices.
03 – Exporters and distributors
Anyone who exports CRA-regulated products into the EU or trades in them there is subject to control obligations. If the manufacturer does not have an establishment in the EU, an EU Authorised Representative is mandatory (Art. 23 CRA).
Our services. CRA compliance from A to Z
Swiss Infosec AG supports you throughout the entire CRA implementation process: from the initial assessment of your compliance status through to full documentation and preparation for CE certification.
1. CRA impact assessment and gap analysis
We analyse which of your products fall under the CRA, which risk class applies (Standard, Important, Critical) and what needs to be done by when. The result is a concrete action plan with priorities and a realistic timetable.
- Product classification in accordance with CRA Annexes III, IV
- Risk assessment and risk classification
- Roadmap with prioritised actions
2. Software Bill of Materials (SBOM)
The CRA requires a complete and up-to-date SBOM for each affected product (Annex I, Part II). We can assist with setting up the SBOM process, selecting the right tools and integrating them into your existing development pipeline.
- SBOM creation in accordance with the SPDX or CycloneDX standard
- Tool integration and automation
- SBOM lifecycle management and update processes
3. Vulnerability management and reporting processes
From September 2026, actively exploited vulnerabilities must be reported to ENISA within 24 hours (Art. 14(2) CRA). We can help you set up a CRA-compliant reporting process and vulnerability disclosure programme.
- Establishing and documenting the ENISA reporting process
- CSIRT integration and escalation paths
- Drawing up a Coordinated Vulnerability Disclosure Policy
4. Technical documentation and conformity assessment
We prepare or review the necessary technical documentation and the EU Declaration of Conformity, and prepare you for the conformity assessment – either internally (self-assessment) or through a notified body.
- Technical documentation in accordance with Annex VII of the CRA
- EU Declaration of Conformity
- Preparation for the conformity assessment
5. Using the ISO 27001 SoA as a CRA basis
An existing ISO 27001 certification with an up-to-date Statement of Applicability (SoA) may already cover key CRA requirements. We will show you how your SoA and certification can help you, and where the CRA-specific gaps lie that need to be addressed.
- SoA mapping against CRA requirements
- Identification of CRA-specific gaps (SBOM, ENISA reporting requirements, CE)
- An efficient implementation strategy for ISO 27001-certified organisations
6. CRA awareness and team training
The CRA requires that staff responsible for cybersecurity tasks receive adequate training. We offer bespoke workshops for development, product and compliance teams – practical and tailored to your product portfolio.
- Security by Design – Workshop for development teams
- Compliance workshop for product and legal teams
- CRA awareness training for the entire organisation
Cyber Resilience Act – key questions
Does the Cyber Resilience Act also apply to Swiss companies?
Yes. The CRA applies to all products with digital elements that are offered on the EU market – regardless of where the company is based. Swiss software manufacturers, IoT providers and exporters who supply goods to the EU must meet the same requirements as EU companies. In addition, they usually need an EU Authorised Representative.
What is the SBOM requirement under the Cyber Resilience Act?
A Software Bill of Materials (SBOM) is a machine-readable list of all software components, libraries and dependencies within a product. The CRA requires (Annex I, Part II) manufacturers to create and maintain an SBOM. The aim is to ensure the traceability of vulnerabilities throughout the entire supply chain.
As a manufacturer, when do I need to fulfil which CRA obligations?
There are three key dates: 11 June 2026 (notification system for conformity assessment bodies), 11 September 2026 (24-hour reporting obligation for vulnerabilities and incidents to ENISA/CSIRT) and 11 December 2027 (full implementation: CE marking, SBOM, Security by Design for all affected products)
Does my existing ISO 27001 certification help with the CRA?
Yes, significantly. Many CRA requirements – particularly risk management, vulnerability management and incident response – correspond directly to ISO 27001/27002 controls. A current Statement of Applicability (SoA) is an excellent starting point. However, there remain CRA-specific requirements (SBOM, ENISA reporting obligation, CE documentation) that the SoA alone does not cover.
What fines are incurred for non-compliance with the CRA?
The CRA provides for administrative fines of up to EUR 15 million or 2.5% of global annual turnover (whichever is higher). In addition, market surveillance authorities may prohibit the sale of non-compliant products within the EU internal market.
Is Switzerland planning its own cyber resilience law?
Yes. The Federal Council has tasked the Federal Office for Cyber Security (BACS) with drafting a consultation bill for Swiss legislation on the cyber resilience of digital products by autumn 2026 – explicitly modelled on the EU CRA. Swiss manufacturers should therefore expect a double wave of regulation: the EU CRA now, and the Swiss equivalent expected from 2027/2028.
Ready for the CRA impact assessment?
During a free initial consultation, we will identify which of your products are affected, which deadlines are a priority for you, and what an efficient implementation would look like.