CRA Insights

Cyber Resilience Act

CRA audit: what it can mean, how it works and what drives the cost

CRA audit: what it can mean, how it works and what drives the cost

Last updated: 2026-10-09

Managing directors hear "CRA audit" from project leads, customers and consultants. Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), does not define it; Article 3 contains no "audit". In the articles the word appears only in the confidentiality provision of Article 63(1)(b). An audit is described as a procedural step only in Annex VIII, in two conformity assessment procedures involving a notified body.

In the context of the CRA it can mean one of three things in particular: an audit by a notified body as part of conformity assessment, an audit of a supplier by its customer, or an independent assessment commissioned by management. Below we separate them, describe the third in detail and set out the cost drivers. As of 9 October 2026, the Article 14 reporting obligation has applied since 11 September 2026, Chapter IV on notified bodies since 11 June 2026, and the rest of the Regulation applies from 11 December 2027 (Article 71(2)).

Three kinds of CRA audit compared

For management the last row matters most: only the first form is part of a procedure the Regulation prescribes for certain products.

Notified body auditAudit by a customerIndependent assessment for management
Who reviewsnotified bodythe customer or a third party it appointsindependent third party or internal audit
Commissioned bythe manufacturer, through its applicationthe customerthe manufacturer's management
BasisArticle 32, Annex VIII Part II (module B) and Part IV (module H)agreement between the companies; the background is the due diligence obligation under Article 13(5)engagement by management
Subjectvulnerability handling processes (module B) or quality system (module H)whatever the companies agreeCRA programme, evidence, reporting capability
Resultmodule B: EU-type examination certificate (Part II point 6); Annex VIII sets no result document for the periodic audits under point 8; module H: notification with the conclusions of the audit and the assessment decision; for surveillance audits an audit reportwhatever the companies agreereport with ratings, findings and recommendations
Required by the Regulation?yes, where the manufacturer follows module B and C or module Hno, the Regulation does not mention supplier auditsno, voluntary
Comparison of three kinds of CRA audit in three columns with the same five rows. Notified body audit: reviewed by the notified body; basis Article 32 and Annex VIII (module B, module H); subject vulnerability handling (module B) or quality system (module H); result for module B the EU-type examination certificate, with no result document set for the periodic audits, for module H the audit conclusions, an audit report during surveillance; required yes, where module B plus C or H is chosen or required under Article 32(2) to (4). Audit by a customer: reviewed by the customer or an appointed third party; basis an agreement, background Article 13(5); subject and result as agreed; required no, the Regulation names no supplier audit. Independent assessment for management, highlighted: reviewed by an independent third party or internal audit; basis an engagement by management; subject CRA programme, evidence, reporting capability; result a report with ratings, findings and recommendations; required no, voluntary. Note: module A (internal control) involves no notified body and no audit; module C rests with the manufacturer and provides for no audit; the Regulation provides for audits of manufacturers only under modules B plus C or H, and where a European certification scheme is used, the scheme applies. Footer: the term ‘CRA audit’ is not defined in Regulation (EU) 2024/2847, as of 9 October 2026.
Notified body, customer, independent assessment: three kinds of CRA audit compared. As of 9 October 2026.

Notified body audits: part of conformity assessment

Before placing a product with digital elements on the market, the manufacturer carries out the chosen conformity assessment procedure or has it carried out (Article 13(12)). Article 32(1) lists internal control (module A), EU-type examination followed by conformity to EU-type based on internal production control (modules B and C), full quality assurance (module H) and, where available and applicable, a European cybersecurity certification scheme. A notified body is a conformity assessment body designated in accordance with Article 43 (Article 3(29)).

The routes available depend on the product class. For class I important products under Annex III, modules B and C or module H are required where harmonised standards, common specifications or certification schemes at assurance level at least "substantial" have not been fully applied or do not exist (Article 32(2)). Class II falls under Article 32(3), critical products under Annex IV under Article 32(4). Classification is a legal question for the individual case; see CRA product classes and conformity assessment and CE marking.

Module A: no third-party audit

Under internal control, the manufacturer declares conformity on its sole responsibility (Annex VIII Part I point 1). No notified body is involved and no audit is provided for.

Modules B and C: type examination with periodic audits

In EU-type examination, the notified body examines the design and development of the product and the manufacturer's vulnerability handling processes and, if the result is positive, issues an EU-type examination certificate (Annex VIII Part II points 1 and 6). Under point 8 it carries out periodic audits to ensure that the vulnerability handling processes set out in Part II of Annex I are implemented adequately. Module C rests with the manufacturer and provides for no audit (Annex VIII Part III).

Module H: audit of the quality system

Under full quality assurance, a notified body chosen by the manufacturer assesses its quality system (Annex VIII Part IV point 3.1). The audit includes an assessment visit to its premises, where such premises exist; the auditing team reviews the technical documentation. The notification to the manufacturer contains the conclusions of the audit and the reasoned assessment decision (point 3.3). During subsequent surveillance the manufacturer gives access to its sites and records (point 4.2), and the body carries out periodic audits and provides an audit report (point 4.3).

Under Article 32(6), the specific interests and needs of microenterprises and small and medium-sized enterprises, including start-ups, are taken into account when setting the fees for conformity assessment procedures, and those fees are reduced proportionately to their specific interests and needs.

Customer audits of suppliers

The second form arises in the supply chain. Under Article 13(5), a manufacturer integrating third-party components exercises due diligence so that they do not compromise the cybersecurity of the product. According to recital 34, the appropriate level depends on the nature and level of risk of the component, taking into account one or more of these actions:

  • verifying that the manufacturer of the component has demonstrated conformity, for example by checking the CE marking,
  • verifying that the component receives regular security updates,
  • verifying that the component is free from vulnerabilities registered in the European vulnerability database or other publicly accessible databases,
  • carrying out additional security tests.

Neither Article 13(5) nor recital 34 mentions an audit at the supplier. Whether a customer can require an audit, a questionnaire or specific evidence depends on the agreements between the companies, such as the supply contract or purchasing terms. Scope, process and confidentiality are governed by those agreements as well. Reviewing such clauses is a matter for the legal department or outside counsel.

For suppliers, a component placed on the market separately can itself be a product with digital elements under Article 3(1), with its own manufacturer obligations. Whether that applies has to be clarified legally in the individual case.

The independent assessment for management

The third form has no basis in the Regulation and is voluntary. Obligations under Articles 13 and 14 rest with the company; upon a reasoned request from the market surveillance authority the manufacturer provides all information and documentation necessary to demonstrate conformity with Annex I (Article 13(22)). For non-compliance with Annex I and infringements of Articles 13 and 14, Article 64(2) provides for fines of up to EUR 15 million or, for undertakings, up to 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher. These fines are directed at the manufacturer as economic operator, so where the manufacturer is a company, at the company itself; whether members of management can also be fined personally depends on the German implementing law and is covered in CRA liability of management.

A status report from your own project tells you what has been done. An independent assessment shows, based on samples, how much of it is evidenced. Blackfort Technology offers this as the CRA readiness audit, described below.

The process in five steps

  1. Engagement and scope: initial call with management on products, review areas, contacts and dates, followed by a proposal with a clearly defined scope.
  2. Documents: your team provides the existing evidence and read access to code, build and ticket system, on your infrastructure if you prefer.
  3. Samples and interviews: we check the evidence ourselves and talk to project lead, development and operations.
  4. Report: rating per product and review area, findings with evidence, recommendations by urgency; with your consent, including the project lead's response.
  5. Closing meeting: walk-through with management. You then decide what comes next.

The five review areas

Each area is checked with samples from the actual evidence. We agree the areas and products with you beforehand.

Review areaKey questionCRA reference
Scope and product registerAre all products and variants with digital elements recorded, with the role and product class assumed and the reasons? Are open legal questions flagged for counsel?Article 3(1), Annexes III and IV
Risk assessment and Annex IIs there a documented risk assessment per product, and can the requirements be traced to code, configuration and tests?Article 13(2) to (4), Annex I Part I
Vulnerabilities and SBOMIs a software bill of materials (SBOM, the list of contained software components) produced per release? Are vulnerabilities rated and remediated? Is there a coordinated vulnerability disclosure policy?Annex I Part II
Reporting capabilityWho decides on the early warning, due without undue delay and at the latest within 24 hours of becoming aware? Are there deputies, a runbook and access to the single reporting platform?Article 14(1) to (4)
Documentation and governanceIs the technical documentation started and the support period determined? Do ownership, deadlines and budget match the open points?Annex VII, Article 13(8)

What management receives

A one-page result with a rating per product and review area, the main risks and the decisions that rest with you; findings with the sample reviewed; recommendations by urgency, from the reporting obligation that already applies to what must be done by 11 December 2027; the project lead's response, if received in time; and a closing meeting. Ratings are evidenced, partly evidenced or not evidenced. "Evidenced" means the sample reviewed was complete and traceable; it is not a statement of conformity. How to check the evidence yourself is described in checking CRA readiness against evidence.

What your company prepares

The review assesses the existing position, so preparing mainly means collecting what exists: product list with classification, risk assessments, SBOMs and vulnerability status, the disclosure policy, the Article 14 reporting procedure (see reporting process and PSIRT), the Annex VII technical documentation as far as it exists, and the programme plan, plus read access to code, build and ticket system and interview partners from project lead, development and operations. We agree the scope beforehand so that your team can plan the effort.

What "independent" means here

If we have contributed to the CRA programme ourselves, we disclose this before the engagement; you decide whether we carry out the review, and parts we implemented ourselves are marked in the report as not independently assessed. Blackfort Technology also advises on implementation. Implementing the recommendations is not part of the review; whether and by whom you have them implemented is your decision. Work by another service provider is assessed against the evidence, without statements about how the provider works. We report to the management that engages us.

CRA audit or CRA gap analysis?

A "CRA compliance check" can mean either service. The CRA gap analysis starts implementation: commissioned by the business unit, product management or development when there is no programme yet, it identifies gaps together with your teams and ends with a gap report per product and a prioritised action plan. The CRA readiness audit is commissioned by management, assesses a running programme with samples from the evidence, from the outside, and ends with a rating per product. The follow-up question is "What do we need to implement?" in one case and "Where do we need to step in?" in the other. Implementation itself is covered by CRA consulting.

What does a CRA audit cost?

There is no fixed price; the effort depends on the form and scope. For a notified body audit, it can depend on the module, the number of products and types and the completeness of the technical documentation; because modules B and H provide for periodic audits, recurring effort is to be expected. Article 32(6) applies to SMEs. For a customer audit, the supplier mainly bears internal effort for preparation and support. For an independent assessment for management, four drivers apply:

  1. Number of products and variants within the agreed scope,
  2. number of review areas, from individual areas up to all five,
  3. maturity and order of the evidence: the more scattered the documents, the more time goes into collecting them and into sampling,
  4. access to documents and contacts: whether read access and interview slots are available promptly.

For the CRA readiness audit, the initial call is free; you then receive a proposal with a clearly defined scope. Cost drivers of implementation itself are covered in What does CRA compliance cost?

When a repeat review can make sense

An assessment describes the position at the time of the review. Whether and when to repeat it is for management to decide. Possible occasions are new products or variants, a change of project lead or service provider, a notification under Article 14 or a request from the market surveillance authority, changes to development or production that must be taken into account under Article 13(14), and the period before 11 December 2027. In between, the report sets out milestones and evidence you can ask your team for. If Blackfort Technology takes on parts of the implementation after a review and reviews again later, we disclose this beforehand and mark those parts in the report as not independently assessed.

What this kind of CRA audit is not

Blackfort Technology is not a notified body; the report does not replace the conformity assessment under Article 32 and is neither a certificate nor an attestation. We are not an audit firm; the report contains no audit opinion and no attestation. The review is based on samples and does not establish that all requirements are met. We do not provide legal services; legal questions such as scope, role or product class are flagged for your legal department or counsel. Penetration testing is not part of our offering. The CRA obligations remain with your company; see also the Cyber Resilience Act for management.

Note: this article is general information as of 9 October 2026 and does not constitute legal advice. For an assessment of your individual case, please consult your legal department or outside counsel.

Frequently asked questions

What is a CRA audit?+
Regulation (EU) 2024/2847 does not define the term. It can mean an audit by a notified body as part of conformity assessment (Annex VIII Part II point 8 and Part IV points 3.3 and 4.3), an audit of a supplier by its customer, or an independent assessment of the company's own position commissioned by management.
Is a CRA audit mandatory?+
The Regulation itself provides for audits of manufacturers only in conformity assessment under modules B and C or module H (Annex VIII). Article 32 sets out which procedures are available for a product, depending on its product class; where a European cybersecurity certification scheme is used, the procedure follows that scheme. The Regulation does not mention supplier audits, and an assessment for management is voluntary.
Who may carry out a CRA audit?+
Audits within conformity assessment under Annex VIII are carried out by a notified body, i.e. a conformity assessment body designated under Article 43 (Article 3(29)). For customer audits and assessments commissioned by management, the Regulation sets no requirements as to who carries them out.
Do we receive a certificate after the CRA readiness audit?+
No. Blackfort Technology is not a notified body. The report is neither a certificate, an attestation nor an audit opinion and does not replace the conformity assessment under Article 32. It assesses, based on samples, which evidence exists.
What does a CRA audit cost?+
It depends on the form. For an independent assessment for management, the effort is driven by the number of products and variants, the number of review areas, the maturity of the evidence and access to documents. For the CRA readiness audit, the initial call is free; you then receive a proposal with a clearly defined scope.
What is the difference between a CRA audit and a CRA gap analysis?+
The gap analysis starts implementation: it identifies gaps and plans measures together with your teams. The CRA readiness audit assesses a running CRA programme on behalf of management, using samples from the evidence.
Can you review work done by another service provider?+
Yes. We assess the results against the evidence and make no statements about how the provider works. With your consent, the project lead can respond to the findings. The report goes to the management that engages us.

Sources

This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).