For management

CRA readiness audit

CRA readiness audit: where does your CRA programme really stand?

Your organisation reports progress on the Cyber Resilience Act. We check how much of it is evidenced. Whether your own team or a service provider is implementing it, Blackfort Technology reviews the CRA programme independently of the project lead, looking at scope, evidence and reporting capability, with samples taken from code, processes and documents. You receive a report you can read without specialist knowledge, with a rating per product and the points that need a management decision.

Why an independent review

As the manufacturer, your company is responsible for the CRA manufacturer obligations. The Article 14 reporting obligation has applied since 11 September 2026; the other manufacturer obligations apply from 11 December 2027 (Article 71(2)). Upon a reasoned request from the market surveillance authority, the manufacturer must provide all information and documentation needed to demonstrate the conformity of the product and its processes with Annex I (Article 13(22)). For non-compliance with the essential cybersecurity requirements in Annex I and the obligations in Articles 13 and 14, Article 64(2) provides for fines of up to EUR 15 million or, for undertakings, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher.

A status report from your own project tells you what has been done. The review shows you, based on samples, where the programme stands: whether all products are covered, whether the evidence exists and can be followed when the market surveillance authority asks for it, and whether the reporting chain is staffed at night and at weekends. To answer that, we look at the evidence ourselves.

The five review areas of the CRA readiness audit arranged in a circle around a centre "Report for management" with a rating per product and review area, findings with evidence and recommendations by urgency. Each with samples from the actual evidence; areas and products are agreed beforehand. 1 Scope and product register: are all products and variants recorded, role and product class justified? 2 Risk assessment and Annex I: is there a risk assessment per product under Article 13(2) to (4), are the Annex I Part I requirements traceable? 3 Vulnerabilities and SBOM: SBOM per release, findings rated and fixed, coordinated vulnerability disclosure policy under Annex I Part II? 4 Article 14 reporting capability: who decides on the early warning, due without undue delay and in any event within 24 hours of becoming aware, are there deputies, a runbook and access to the reporting platform? 5 Documentation and governance: has Annex VII been started, the support period set, are there ownership, deadlines and budget? Footer: no certificate and no statement of conformity.
CRA readiness audit: five review areas with samples, brought together in a report for management.

What management receives

A report you can read without specialist knowledge, with ratings your team can trace back to the evidence.

  1. 01

    Result on one page

    Overall picture with a rating per product and review area, the main risks and the decisions that rest with you.

  2. 02

    Findings with evidence

    For each rating the sample reviewed, so that project lead and development can follow it.

  3. 03

    Recommendations by urgency

    What is needed now, for example for the reporting obligation that already applies, and what must be done by 11 December 2027.

  4. 04

    Project lead response

    With your consent, the project lead sees the findings in advance. If their response arrives within the agreed period, it is included in the report.

  5. 05

    Closing meeting

    Walk-through with management, together with the project lead if you wish.

Management summary: what the result looks like

Extract from the overview of a review report, a fictitious example with two products. Overall status: action needed, evidence partly reliable.

Review areaController AGateway BMain finding
Scope and product registerpartly evidencedevidencedTwo older variants of controller A are missing from the register.
Risk assessment and Annex Ipartly evidencednot evidencedNo documented risk assessment exists for gateway B.
Vulnerabilities and SBOMevidencedpartly evidencedGateway B: an SBOM is produced, findings are not tracked.
Article 14 reporting capabilitynot evidencednot evidencedNo deputy named outside business hours.
Documentation and governancepartly evidencedpartly evidencedSupport period not determined.

Recommendation to management in the example: secure the reporting procedure with deputies at short notice, evidence the risk assessment for gateway B, determine the support period. Fictitious example for illustration, no customer data. "Evidenced" means the sample reviewed was complete and traceable. It is not a statement of conformity.

What we review

Five review areas, each with samples taken from the actual evidence. We agree with you beforehand which areas and products are covered.

Scope and product register

Are all products and variants with digital elements recorded, is it documented for each which role and product class your company assumes and why, and are open legal questions flagged for your legal department or counsel?

Risk assessment and Annex I

Is there a documented risk assessment per product under Article 13(2) to (4), and can the Annex I Part I requirements be traced to code, configuration and tests?

Vulnerabilities and SBOM

Is a software bill of materials produced per release, are vulnerabilities rated and remediated, and is there a coordinated vulnerability disclosure policy under Annex I Part II?

Article 14 reporting capability

Who decides on the early warning, which is due without undue delay and at the latest 24 hours after becoming aware? Are there deputies, a runbook and access to the single reporting platform?

Documentation and governance

Has the Annex VII technical documentation been started and the support period determined? Does the programme have ownership, deadlines and a budget that matches the open points?

CRA gap analysis or CRA readiness audit?

Two services for two starting points. The gap analysis starts implementation, the audit assesses one that is running.

CRA gap analysisCRA readiness audit
Commissioned bybusiness unit, product management, developmentmanagement
Prerequisiteno CRA programme yetCRA programme already running
Aimidentify gaps and plan measuresassess the status independently
Approachtogether with your teamssamples from the evidence, independent of the project lead
Resultgap report per product and prioritised action planreport for management with a rating per product
Next questionWhat do we need to implement?Where do we need to step in?

More on the gap analysis: https://cra-readiness.de/en/cra-gap-analysis

How the review runs

Five steps from the engagement to the closing meeting.

  1. 1

    Engagement and scope

    Initial call with management: products, review areas, contacts and dates. You then receive a proposal with a clearly defined scope.

  2. 2

    Documents

    Your team provides the existing evidence and read access to code, build and ticket system, on your infrastructure if you prefer.

  3. 3

    Samples and interviews

    We check the evidence ourselves and hold targeted interviews with project lead, development and operations.

  4. 4

    Report

    Rating per product and review area, findings with evidence, recommendations by urgency and, if you wish, the project lead's response.

  5. 5

    Closing meeting

    Joint walk-through with management. You then decide what comes next.

Christian Gebhardt, founder and managing director of Blackfort Technology

Your contact

Christian Gebhardt · Founder and managing director, Blackfort Technology

Christian Gebhardt, founder and managing director of Blackfort Technology, is happy to take your enquiry personally. In a free initial call you work out together what you need; the consulting is carried out by the Blackfort Technology team.

Profile on LinkedIn

What "independent" means here

If Blackfort Technology has contributed to the CRA programme in your company, we disclose this before the engagement; you decide whether we carry out the review. Parts we implemented ourselves are marked in the report as not independently assessed. Blackfort Technology also advises on implementation. Implementing the recommendations is not part of the review; whether and by whom you have them implemented is your decision.

We report to the management that engages us.

Five questions the report answers

What is actually evidenced? Comparison of reported project status, processes in practice and verifiable evidence in the samples.

Where are our critical gaps? Assessment of the main risks, starting with the reporting obligation that already applies.

Do planning and ownership match the open points? Assessment of planning, ownership and implementation status.

Which decisions rest with me? Recommendations by urgency, naming who has to decide.

How do I track progress? Milestones and evidence you can ask your team for in future.

What we do not do

So that expectations are right from the start:

  • We do not provide legal services. Questions that have to be decided legally, such as scope, role or product class, are flagged for your legal department or counsel.
  • We are not a notified body. The report is neither a certificate nor an attestation and does not replace the conformity assessment under Article 32.
  • The review is based on samples. It shows the state of the evidence reviewed and does not establish that all requirements are met.
  • We are not an audit firm. The report contains no audit opinion and no attestation.
  • Penetration testing is not part of our offering.

The CRA obligations remain with your company. We help you meet them and demonstrate that you do.

Frequently asked questions

Who is the review for?+

For the management of manufacturers whose CRA programme is already running, in-house or with a service provider, and who want an independent assessment before releasing budget or answering customers.

Is this a CRA audit, a compliance check or a certification?+

The Regulation does not define a "CRA audit". It refers to audits in the conformity assessment carried out by notified bodies (Annex VIII). Our review is an assessment of where you stand, based on samples, with no certificate and no attestation. The conformity assessment under Article 32 remains a separate step, involving a notified body depending on the product class. A free online self-check is available at https://cra-readiness.de/en/affected.

Can you review work done by another service provider?+

Yes. We assess the results against the evidence and make no statements about how the provider works. With your consent, the project lead can respond to the findings. The report goes to the management that engages us.

What does the review cost?+

It depends on the number of products and review areas. After a free initial call you receive a proposal with a clearly defined scope.

How much work is it for our team?+

Your team provides the existing documents and access and is available for targeted interviews. We agree the scope beforehand so that your team can plan the effort.

Further reading

This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).

Last updated: 2026-10-09

Kontakt aufnehmen

Request a review

Tell us about your products and where your CRA programme stands. The initial call is free and without obligation; we usually reply within one to two working days.