What CRA compliance costs, and how to budget for it

A first product costs in the order of 100,000 € to bring into Cyber Resilience Act compliance, and much less for those that follow. What manufacturers of every size are spending today, where the money goes, and how to build the budget.

Every executive conversation about the Cyber Resilience Act reaches the same question: what will it cost? The honest answer is a range, but a range can be budgeted, and the structure of the cost matters more than the total.

Our working figure, drawn from the programmes we have supported, is in the order of 100,000 € for the first product, counting internal effort and external spend together. The second product costs noticeably less, and the cost per product keeps falling as the portfolio moves through, provided the first one is done with reuse in mind.

What manufacturers are spending today

Our figures come from the programmes we support and from the conversations we have with product teams. Investment follows the size of the company far more than the size of the product.

Profile What we see Investment
Large manufacturers Product security has been funded for years. The CRA is a gap-bridging exercise across a wide portfolio, with evidence to produce for every product line and site. 500,000 € to several million
SMEs with a CRA owner One or two people carry the subject and concentrate on what matters most: scoping the portfolio, a risk assessment methodology and a vulnerability handling process. Below 100,000 €
Most other SMEs Not engaged, and often unaware of being in scope. ENISA’s first survey of SMEs, covered in our article on SMEs and the CRA, confirms the picture. Nothing yet
Start-ups selling into the EU A small number act because their main customers demand it, and buy the minimum evidence a customer will accept. 20,000 € to 50,000 €
Component manufacturers Some go beyond the CRA towards EUCC certification: purchasing departments already ask them to demonstrate compliance, and certification has become a sales argument. Above the CRA baseline

Most of our clients are in the first group, and our sample of start-ups is small, so treat those two lines as observations rather than statistics.

Two things are true across every profile. Manufacturers take the regulator seriously, and many describe the CRA as the GDPR of products. And uncertainty holds budgets back: with the harmonised standards still being finalised, most companies are funding the foundations now and holding the product-level spend. We expect investment to step up in 2027 once the standards are settled, at exactly the moment laboratory capacity is scarcest. The deadline that matters is earlier than most plans assume.

Three kinds of cost

CRA spending falls into three categories that behave differently, and a budget that mixes them will be wrong.

Foundations, paid once. Governance, a repeatable risk assessment methodology, the vulnerability handling process and the security of the production phase. These serve the entire portfolio. They are the reason the first product is expensive and the tenth is not.

Per-product costs. The product’s own risk assessment, engineering remediation, technical documentation, testing and conformity assessment. These scale with the number of products, though less than linearly when products share platforms and components.

Running costs. Monitoring and handling vulnerabilities, delivering security updates and keeping documentation current throughout the support period, which the CRA expects to be at least five years in most cases. Over a product’s life this is the largest category, and it is the one most often left out of the business case.

Where the money goes for one product

Technical documentation. Internal cost only if your teams write it, but time is the real price: a first file written without experience can take most of a year, where an experienced author needs one to two months. It is a legal requirement for every product, self-assessed ones included. Written once per product category, it can be reused for the products that follow.

Independent testing. A laboratory assessment covering device, application and cloud typically costs 15,000 € to 25,000 € and takes two to three weeks once it starts. Laboratories run several projects in parallel, so lead time comes on top. Testing via an accredited lab is not mandatory for self-assessed products, but test reports are part of the evidence, and an independent one carries weight.

Remediation. The least predictable line. If testing reveals a gap, the cost is engineering time, and it depends entirely on how early security entered the design. Make sure retesting is included in the laboratory contract, and keep a contingency.

Notified body. Needed only for important and critical products that cannot rely on self-assessment. An EU-type examination typically costs 2,000 € to 5,000 € and takes one to two weeks, depending on the detail of the test report and the exchanges required. For a first product, a combined laboratory and notified body package simplifies the process.

The hidden costs, and why they scale

Four items rarely appear in the first budget. All four are significant, and all four have the same property: the investment is made once and the return grows with every product.

Untracked dependencies. Most products contain software components nobody has listed, and therefore vulnerabilities nobody is watching. The cost appears without warning, as an emergency patch, a delayed launch or a reportable incident. Establishing a reliable component inventory and a way to monitor it takes effort upfront, and the same capability then serves the whole portfolio.

Secure production. The CRA requires products to be designed, developed and produced in line with the essential requirements. That last word carries a great deal. For physical products it means assessing the risks of each factory, usually through an on-site audit, and particularly where manufacturing is outsourced or the supply chain is complex. It also means a secure architecture for provisioning secrets, keys and device identities on the production line. This can be expensive and can lead to a partial redesign. It is also among the most valuable investments in the programme: the work is done per site and per platform, and once in place it secures every unit of every product built there. At volume, the cost per device becomes negligible.

Tooling. Risk assessment, requirements management, vulnerability tracking and documentation all benefit from tools. Selection, deployment and integration take time and money once. Every later product uses what is already there.

Training. The usual assumption is that training means teaching developers to write secure code. The CRA touches far more roles than that, and each needs something different. Engineers need to know what the regulation expects of the design and the evidence. Product owners need to know the process: when a risk assessment happens, what it produces, and what must be in place before a release. Executives need enough understanding to make the decisions only they can make, namely which risks to accept and which improvements to fund, in what order. Customer support needs to recognise a vulnerability report when one arrives and to know its part in notifying customers, because the reporting clock does not wait for a ticket to be escalated. A gap in any of these roles shows up as delay, rework or a missed obligation.

Trained teams make fewer costly mistakes, need less external support and produce better evidence, and the benefit compounds across products and years. In one programme we supported, integrating our FAST methodology into the development process, and training the product teams to run it themselves, saved the manufacturer over 150,000 € in penetration tests over 18 months. We provide training courses for each of these audiences.

The common thread is that these costs are only hidden when nobody plans for them. Budgeted as foundations, they are what makes the second product cheap.

What drives the total up or down

  • Product category. Default and important class I products can follow self-assessment. Important class II and critical products add third-party assessment and its lead times.
  • Shared platforms. A portfolio built on common hardware and software amortises almost everything. A portfolio of unrelated designs does not.
  • Number of interfaces. Each protocol, application and cloud service adds documentation and testing scope.
  • Starting maturity. Manufacturers who have been through RED or a similar regime start with reusable material.
  • Timing. Security designed in costs a fraction of security retrofitted. Compliance started late is paid for in delayed launches.

How to build the budget

  1. Budget by product family Group products by platform, fund the first in each family in full, and the rest at a declining rate.
  2. Separate the three categories Foundations are a one-off programme. Per-product costs belong in each product’s business case. Running costs belong in the product’s operating budget for the whole support period.
  3. Put the cost where the decision is CRA compliance is a condition of market access, like safety or radio certification. It belongs in the product P&L, where it can be weighed against revenue, not in the security budget, where it competes with unrelated priorities.
  4. Use it to review the portfolio Some products will not justify the investment. Deciding which to retire, merge or replace before December 2027 is a legitimate outcome of the exercise, and often a valuable one.
  5. Book laboratory capacity early Demand will peak in 2027. Lead times are already the hidden item in most plans.

What we charge for the work

The figures above are what the whole programme costs you, internal effort included. Our own part of it is published, so you can put a real number in the plan rather than a placeholder for consulting.

A CRA portfolio assessment is 5,000 € for one product and 20,000 € for the portfolio of one legal entity, up to ten products. It runs three weeks and ends with the gap analysis, the priorities and the budget range, which is the item most plans are missing.

After that, a retained advisor runs from 2,000 € a month where we review documents and answer the interpretation questions, through 5,000 € to 15,000 € where we work alongside your engineers, to 15,000 € to 30,000 € where a team of ours runs parallel work packages and carries your product security governance, and a premium band from 30,000 € where that team is dedicated to your portfolio, for a group running an enterprise-wide programme across several entities.

Against a first product in the order of 100,000 €, the assessment is a small fraction of the budget and it is the part that tells you where the rest should go.

The other side of the ledger

Non-compliance carries fines of up to 15 M€ or 2.5% of worldwide annual turnover for breaches of the essential requirements, along with the power for authorities to order a product withdrawn from the EU market. For most manufacturers the more immediate cost is commercial: customers and distributors are beginning to require evidence of compliance in tenders and contracts.

Summary

Cost item Typical external cost Elapsed time Scales with
Foundations: governance, risk methodology, vulnerability handling Varies with maturity 3 to 6 months Paid once for the organisation
Securing the production phase Per site, plus provisioning architecture 2 to 3 months per site Sites and platforms, not products
Component inventory and monitoring Internal, plus tooling Ongoing Paid once, serves the portfolio
Tooling Licences and integration Weeks to months Deployed once, reused for every product
Training Per course or per audience Days Roles across the organisation, not products
Technical documentation None if written internally 1 to 2 months with experience, far longer without Product categories, interfaces
Independent testing 15,000 € to 25,000 € 2 to 3 weeks plus lead time Products, interfaces
Remediation and retesting Internal engineering Depends on findings Design maturity
Notified body (important and critical products) 2,000 € to 5,000 € 1 to 2 weeks Products requiring third-party assessment
Running costs Internal, recurring Whole support period Products in the field

For an estimate based on your own portfolio, talk to us, or evaluate your products with CRAted to see where the gaps are.