SMEs and the CRA: closing the gap between aware and ready

ENISA’s first SME survey shows that small manufacturers know the Cyber Resilience Act is coming and are not ready for it. A plan that one person can run, and where tools and outside help fit.

In June 2026, ENISA published its first survey of how SMEs are preparing for the Cyber Resilience Act. It covered 194 organisations in 31 countries, and the picture is consistent: around two thirds of respondents had heard of the CRA, and far fewer had turned that awareness into practice. Company size was the strongest predictor of readiness, with micro-enterprises scoring lowest in every domain. Incident response and product lifecycle management were the weakest areas, and reporting obligations apply from 11 September 2026.

None of this surprises us. It does not mean SMEs cannot comply. It means the usual route to compliance was not designed for them.

What it looks like on the ground

In the small manufacturers we work with, CRA compliance usually belongs to one person. Sometimes it is the lead engineer, sometimes whoever looks after cyber security, occasionally the founder. That person has a full-time job already, no budget line for the CRA, and nobody to delegate to.

Most guidance assumes the opposite: a security team, a compliance function, a legal department and a project manager to coordinate them. Advice written for that structure is accurate and unusable. The person reading it does not need a framework. They need to know what to do on Monday.

What the CRA itself provides

The regulation recognises the problem to a degree. It provides for a simplified format of technical documentation for micro and small enterprises, asks notified bodies to take SMEs’ situation into account in their fees, and shields the smallest companies from fines for missing the 24-hour early warning deadline. ENISA has also published a free maturity model to help SMEs assess their organisation.

These measures reduce the burden at the edges. The essential requirements, the risk assessment and the vulnerability handling obligations apply in full, whatever the size of the manufacturer.

A plan one person can run

  1. Scope the portfolio Establish which products fall under the CRA and in which category. Most will be in the default category and eligible for self-assessment, which changes the cost of everything that follows. This takes hours, not weeks. Our free tool CRAscoping gives the category of a product in a few minutes.
  2. Set up reporting first It is the obligation already in force. A small company needs a monitored contact point, a simple triage routine and a named person who knows how and where to report. One page is enough, provided it has been rehearsed once.
  3. Evaluate each product against the requirements A structured, guided assessment turns a regulation into a list of gaps per product. This is the step where a lone owner gains the most, because it replaces interpretation with answers.
  4. Turn the gaps into a budget request Management does not fund “CRA compliance”. It funds a prioritised list of actions with effort, cost and a deadline attached. An assessment that produces this list is what unlocks resources.
  5. Do the first product properly, then reuse SME portfolios share platforms and components. The risk assessment, documentation and processes built for the first product carry over to the others with modest changes.

Where tools and outside help fit

An SME cannot afford a long consulting engagement for steps one to three, and should not need one. This is why we built CRAted, the CRA Toolkit for Evaluation and Decision. It packages the method we use in client work into a guided questionnaire, with automatic compliance evaluation, gap and recommendation tracking, and a view across the product portfolio. It is the successor to REDact, which did the same for RED, and it has a free tier.

It complements ENISA’s maturity model: the ENISA model assesses the organisation, while CRAted assesses each product against the regulation’s requirements.

Expert time is best spent where judgement is needed: reviewing the risk assessment, deciding how to close the difficult gaps, and preparing the first technical file. We offer these as packaged services with a fixed scope, designed for companies where one person carries the programme.

Summary

Step What you get Who needs to see it
Scope the portfolio List of products in scope and their CRA category Management, product owners
Set up reporting Contact point, triage routine, named reporter Support, engineering
Evaluate each product Compliance status and gaps per product The CRA owner
Build the budget case Prioritised actions with effort and deadlines Management, finance
First product, then reuse Risk assessment and documentation that serve as templates Engineering

To find out where you stand, scope your products for free with CRAscoping, evaluate them with CRAted, or talk to us about our SME packages.