Who does what in CRA compliance: building the right support team

Seven types of provider offer CRA support, and they solve very different problems. A buyer’s map of the landscape, and how to combine them.

The Cyber Resilience Act’s reporting obligations apply from September 2026, and full application follows in December 2027. Most manufacturers now accept they need outside help. The harder question is which kind, because at least seven types of provider offer “CRA support”, and they solve very different problems. Choosing the wrong one is rarely a disaster, but it costs months, and months are the scarce resource.

Here is how we see the landscape, including where we fit and where we don’t.

Law firms

Lawyers bring rigour on legal interpretation: whether you are a manufacturer, importer or distributor, how obligations flow through supply contracts, what liability exposure looks like. They generally do not assess whether a product’s architecture meets the essential requirements, and they shouldn’t be asked to.

Use them for contracts, economic operator roles and legal risk. Pair them with technical expertise for everything touching the product itself.

Test laboratories

Labs provide independent evidence that a product meets a standard, and that independence is their value. Accredited labs operate under impartiality requirements, which limits how far they can advise on fixing what they find.

Use them for assessment and testing. Arrive prepared, since a lab is an expensive place to discover design problems.

IT service providers

Your IT partner knows your infrastructure, and part of CRA compliance lives there: build pipelines, update infrastructure, access control on development environments. Product security is a different discipline from enterprise IT, with different threat models and lifecycles.

Use them to harden the environment your products are built in.

Large cyber security consultancies

They have depth, skilled people and capacity for well-defined technical work such as threat modelling, secure firmware development or penetration testing at scale. Their model is built around staffing engagements, and product regulation is often a small part of a broad practice.

Use them when you know precisely what you need done and need hands to do it.

Independent freelancers

Good freelancers are flexible and cost-effective for bounded tasks: a pentest, a threat model, a tracking framework. They deliver what you specify, so the quality of the outcome depends on your ability to specify it.

Use them when the direction is set and the task is clear.

Compliance platforms

A growing number of tools automate SBOM generation, vulnerability tracking and technical documentation. These are real needs, and automation is the right answer to them. Documentation describes a secure product. It does not create one.

Use platforms to industrialise evidence once you know what you are evidencing.

Your own team

Nobody knows your products better, and lasting capability can only live in-house. The constraints are familiar: your people are already at capacity, they may lack the mandate to change how other departments work, and they see one company’s experience.

They are the long-term answer. The question is how to get them there faster.

Product security specialists

This is where we sit, so weigh our view accordingly. A specialist’s contribution is pattern recognition: having taken many manufacturers through the same regulation, we know which requirements consume effort, which interpretations hold up, and what to prioritise for a given portfolio. The right specialist works alongside your internal team and leaves it stronger.

Use one to set the strategy, sequence the work and direct the other providers effectively.

Putting it together

Few manufacturers need only one of these. A typical programme combines them, in this order:

  1. A product security specialist For scoping, the roadmap and the sequencing of the other providers.
  2. Your own team For implementation, with the specialist where judgement is needed.
  3. Tooling For the evidence, once the process it documents exists: SBOMs, vulnerability tracking, documentation.
  4. A test laboratory For independent assessment, when the product is ready for it.
  5. A law firm For contracts, economic operator roles and liability.

Strategy before tooling, preparation before testing.

Summary

Provider Best for Limits
Law firms Contracts, economic operator roles, liability and legal risk Do not assess product architecture or technical requirements
Test laboratories Independent assessment and testing against standards Impartiality rules limit advice on fixing findings
IT service providers Hardening build pipelines, update infrastructure, development environments Enterprise IT is a different discipline from product security
Large cyber security consultancies Well-defined technical work at scale: threat modelling, secure firmware, penetration testing Staffing-led model; product regulation is often a small part of the practice
Independent freelancers Bounded, clearly specified tasks at lower cost Outcome depends on your ability to specify the work
Compliance platforms Automating SBOMs, vulnerability tracking and technical documentation Document a secure product; do not create one
Your own team Implementation and lasting in-house capability Limited capacity, mandate and view of what works elsewhere
Product security specialists Strategy, prioritisation, sequencing and directing other providers Complement, not replace, internal teams and independent testing

If you are unsure where to begin, start by scoping your products with CRAscoping or talk to us about sequencing your programme.