
Last updated: 2026-10-09
Managing directors hear "CRA audit" from project leads, customers and consultants. Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), does not define it; Article 3 contains no "audit". In the articles the word appears only in the confidentiality provision of Article 63(1)(b). An audit is described as a procedural step only in Annex VIII, in two conformity assessment procedures involving a notified body.
In the context of the CRA it can mean one of three things in particular: an audit by a notified body as part of conformity assessment, an audit of a supplier by its customer, or an independent assessment commissioned by management. Below we separate them, describe the third in detail and set out the cost drivers. As of 9 October 2026, the Article 14 reporting obligation has applied since 11 September 2026, Chapter IV on notified bodies since 11 June 2026, and the rest of the Regulation applies from 11 December 2027 (Article 71(2)).
Three kinds of CRA audit compared
For management the last row matters most: only the first form is part of a procedure the Regulation prescribes for certain products.
| Notified body audit | Audit by a customer | Independent assessment for management | |
|---|---|---|---|
| Who reviews | notified body | the customer or a third party it appoints | independent third party or internal audit |
| Commissioned by | the manufacturer, through its application | the customer | the manufacturer's management |
| Basis | Article 32, Annex VIII Part II (module B) and Part IV (module H) | agreement between the companies; the background is the due diligence obligation under Article 13(5) | engagement by management |
| Subject | vulnerability handling processes (module B) or quality system (module H) | whatever the companies agree | CRA programme, evidence, reporting capability |
| Result | module B: EU-type examination certificate (Part II point 6); Annex VIII sets no result document for the periodic audits under point 8; module H: notification with the conclusions of the audit and the assessment decision; for surveillance audits an audit report | whatever the companies agree | report with ratings, findings and recommendations |
| Required by the Regulation? | yes, where the manufacturer follows module B and C or module H | no, the Regulation does not mention supplier audits | no, voluntary |

Notified body audits: part of conformity assessment
Before placing a product with digital elements on the market, the manufacturer carries out the chosen conformity assessment procedure or has it carried out (Article 13(12)). Article 32(1) lists internal control (module A), EU-type examination followed by conformity to EU-type based on internal production control (modules B and C), full quality assurance (module H) and, where available and applicable, a European cybersecurity certification scheme. A notified body is a conformity assessment body designated in accordance with Article 43 (Article 3(29)).
The routes available depend on the product class. For class I important products under Annex III, modules B and C or module H are required where harmonised standards, common specifications or certification schemes at assurance level at least "substantial" have not been fully applied or do not exist (Article 32(2)). Class II falls under Article 32(3), critical products under Annex IV under Article 32(4). Classification is a legal question for the individual case; see CRA product classes and conformity assessment and CE marking.
Module A: no third-party audit
Under internal control, the manufacturer declares conformity on its sole responsibility (Annex VIII Part I point 1). No notified body is involved and no audit is provided for.
Modules B and C: type examination with periodic audits
In EU-type examination, the notified body examines the design and development of the product and the manufacturer's vulnerability handling processes and, if the result is positive, issues an EU-type examination certificate (Annex VIII Part II points 1 and 6). Under point 8 it carries out periodic audits to ensure that the vulnerability handling processes set out in Part II of Annex I are implemented adequately. Module C rests with the manufacturer and provides for no audit (Annex VIII Part III).
Module H: audit of the quality system
Under full quality assurance, a notified body chosen by the manufacturer assesses its quality system (Annex VIII Part IV point 3.1). The audit includes an assessment visit to its premises, where such premises exist; the auditing team reviews the technical documentation. The notification to the manufacturer contains the conclusions of the audit and the reasoned assessment decision (point 3.3). During subsequent surveillance the manufacturer gives access to its sites and records (point 4.2), and the body carries out periodic audits and provides an audit report (point 4.3).
Under Article 32(6), the specific interests and needs of microenterprises and small and medium-sized enterprises, including start-ups, are taken into account when setting the fees for conformity assessment procedures, and those fees are reduced proportionately to their specific interests and needs.
Customer audits of suppliers
The second form arises in the supply chain. Under Article 13(5), a manufacturer integrating third-party components exercises due diligence so that they do not compromise the cybersecurity of the product. According to recital 34, the appropriate level depends on the nature and level of risk of the component, taking into account one or more of these actions:
- verifying that the manufacturer of the component has demonstrated conformity, for example by checking the CE marking,
- verifying that the component receives regular security updates,
- verifying that the component is free from vulnerabilities registered in the European vulnerability database or other publicly accessible databases,
- carrying out additional security tests.
Neither Article 13(5) nor recital 34 mentions an audit at the supplier. Whether a customer can require an audit, a questionnaire or specific evidence depends on the agreements between the companies, such as the supply contract or purchasing terms. Scope, process and confidentiality are governed by those agreements as well. Reviewing such clauses is a matter for the legal department or outside counsel.
For suppliers, a component placed on the market separately can itself be a product with digital elements under Article 3(1), with its own manufacturer obligations. Whether that applies has to be clarified legally in the individual case.
The independent assessment for management
The third form has no basis in the Regulation and is voluntary. Obligations under Articles 13 and 14 rest with the company; upon a reasoned request from the market surveillance authority the manufacturer provides all information and documentation necessary to demonstrate conformity with Annex I (Article 13(22)). For non-compliance with Annex I and infringements of Articles 13 and 14, Article 64(2) provides for fines of up to EUR 15 million or, for undertakings, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. These fines are directed at the manufacturer as economic operator, so where the manufacturer is a company, at the company itself; whether members of management can also be fined personally depends on the German implementing law and is covered in CRA liability of management.
A status report from your own project tells you what has been done. An independent assessment shows, based on samples, how much of it is evidenced. Blackfort Technology offers this as the CRA readiness audit, described below.
The process in five steps
- Engagement and scope: initial call with management on products, review areas, contacts and dates, followed by a proposal with a clearly defined scope.
- Documents: your team provides the existing evidence and read access to code, build and ticket system, on your infrastructure if you prefer.
- Samples and interviews: we check the evidence ourselves and talk to project lead, development and operations.
- Report: rating per product and review area, findings with evidence, recommendations by urgency; with your consent, including the project lead's response.
- Closing meeting: walk-through with management. You then decide what comes next.
The five review areas
Each area is checked with samples from the actual evidence. We agree the areas and products with you beforehand.
| Review area | Key question | CRA reference |
|---|---|---|
| Scope and product register | Are all products and variants with digital elements recorded, with the role and product class assumed and the reasons? Are open legal questions flagged for counsel? | Article 3(1), Annexes III and IV |
| Risk assessment and Annex I | Is there a documented risk assessment per product, and can the requirements be traced to code, configuration and tests? | Article 13(2) to (4), Annex I Part I |
| Vulnerabilities and SBOM | Is a software bill of materials (SBOM, the list of contained software components) produced per release? Are vulnerabilities rated and remediated? Is there a coordinated vulnerability disclosure policy? | Annex I Part II |
| Reporting capability | Who decides on the early warning, due without undue delay and at the latest within 24 hours of becoming aware? Are there deputies, a runbook and access to the single reporting platform? | Article 14(1) to (4) |
| Documentation and governance | Is the technical documentation started and the support period determined? Do ownership, deadlines and budget match the open points? | Annex VII, Article 13(8) |
What management receives
A one-page result with a rating per product and review area, the main risks and the decisions that rest with you; findings with the sample reviewed; recommendations by urgency, from the reporting obligation that already applies to what must be done by 11 December 2027; the project lead's response, if received in time; and a closing meeting. Ratings are evidenced, partly evidenced or not evidenced. "Evidenced" means the sample reviewed was complete and traceable; it is not a statement of conformity. How to check the evidence yourself is described in checking CRA readiness against evidence.
What your company prepares
The review assesses the existing position, so preparing mainly means collecting what exists: product list with classification, risk assessments, SBOMs and vulnerability status, the disclosure policy, the Article 14 reporting procedure (see reporting process and PSIRT), the Annex VII technical documentation as far as it exists, and the programme plan, plus read access to code, build and ticket system and interview partners from project lead, development and operations. We agree the scope beforehand so that your team can plan the effort.
What "independent" means here
If we have contributed to the CRA programme ourselves, we disclose this before the engagement; you decide whether we carry out the review, and parts we implemented ourselves are marked in the report as not independently assessed. Blackfort Technology also advises on implementation. Implementing the recommendations is not part of the review; whether and by whom you have them implemented is your decision. Work by another service provider is assessed against the evidence, without statements about how the provider works. We report to the management that engages us.
CRA audit or CRA gap analysis?
A "CRA compliance check" can mean either service. The CRA gap analysis starts implementation: commissioned by the business unit, product management or development when there is no programme yet, it identifies gaps together with your teams and ends with a gap report per product and a prioritised action plan. The CRA readiness audit is commissioned by management, assesses a running programme with samples from the evidence, from the outside, and ends with a rating per product. The follow-up question is "What do we need to implement?" in one case and "Where do we need to step in?" in the other. Implementation itself is covered by CRA consulting.
What does a CRA audit cost?
There is no fixed price; the effort depends on the form and scope. For a notified body audit, it can depend on the module, the number of products and types and the completeness of the technical documentation; because modules B and H provide for periodic audits, recurring effort is to be expected. Article 32(6) applies to SMEs. For a customer audit, the supplier mainly bears internal effort for preparation and support. For an independent assessment for management, four drivers apply:
- Number of products and variants within the agreed scope,
- number of review areas, from individual areas up to all five,
- maturity and order of the evidence: the more scattered the documents, the more time goes into collecting them and into sampling,
- access to documents and contacts: whether read access and interview slots are available promptly.
For the CRA readiness audit, the initial call is free; you then receive a proposal with a clearly defined scope. Cost drivers of implementation itself are covered in What does CRA compliance cost?
When a repeat review can make sense
An assessment describes the position at the time of the review. Whether and when to repeat it is for management to decide. Possible occasions are new products or variants, a change of project lead or service provider, a notification under Article 14 or a request from the market surveillance authority, changes to development or production that must be taken into account under Article 13(14), and the period before 11 December 2027. In between, the report sets out milestones and evidence you can ask your team for. If Blackfort Technology takes on parts of the implementation after a review and reviews again later, we disclose this beforehand and mark those parts in the report as not independently assessed.
What this kind of CRA audit is not
Blackfort Technology is not a notified body; the report does not replace the conformity assessment under Article 32 and is neither a certificate nor an attestation. We are not an audit firm; the report contains no audit opinion and no attestation. The review is based on samples and does not establish that all requirements are met. We do not provide legal services; legal questions such as scope, role or product class are flagged for your legal department or counsel. Penetration testing is not part of our offering. The CRA obligations remain with your company; see also the Cyber Resilience Act for management.
Note: this article is general information as of 9 October 2026 and does not constitute legal advice. For an assessment of your individual case, please consult your legal department or outside counsel.
Frequently asked questions
What is a CRA audit?+
Is a CRA audit mandatory?+
Who may carry out a CRA audit?+
Do we receive a certificate after the CRA readiness audit?+
What does a CRA audit cost?+
What is the difference between a CRA audit and a CRA gap analysis?+
Can you review work done by another service provider?+
Sources
- Verordnung (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex, deutsche Fassung
- Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex, English version
- VO (EU) 2024/2847, Art. 3 Nr. 1 und 29 (Begriffsbestimmungen)
- VO (EU) 2024/2847, Art. 13 Abs. 2 bis 5, 8, 12, 14, 22 und Erwägungsgrund 34 (Pflichten der Hersteller, Sorgfalt bei Komponenten)
- VO (EU) 2024/2847, Art. 14 (Meldepflichten der Hersteller)
- VO (EU) 2024/2847, Art. 32 (Konformitätsbewertungsverfahren)
- VO (EU) 2024/2847, Art. 63 Abs. 1, Art. 64 Abs. 2, Art. 71 Abs. 2
- VO (EU) 2024/2847, Anhang VIII Teile I bis IV (Module A, B, C, H)
- Blackfort Technology: CRA Readiness Audit (Leistungsbeschreibung)
- VO (EU) 2024/2847, Art. 43, Anhänge I, III, IV und VII
This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).