Insights · cetome.com
Who does what in CRA compliance: building the right support team
The Cyber Resilience Act’s reporting obligations apply from September 2026, and full application follows in December 2027. Most manufacturers now accept they need outside help. The harder question is which kind, because at least seven types of provider offer “CRA support”, and they solve very different problems. Choosing the wrong one is rarely a disaster, but it costs months, and months are the scarce resource.
Here is how we see the landscape, including where we fit and where we don’t.
Law firms
Lawyers bring rigour on legal interpretation: whether you are a manufacturer, importer or distributor, how obligations flow through supply contracts, what liability exposure looks like. They generally do not assess whether a product’s architecture meets the essential requirements, and they shouldn’t be asked to.
Use them for contracts, economic operator roles and legal risk. Pair them with technical expertise for everything touching the product itself.
Test laboratories
Labs provide independent evidence that a product meets a standard, and that independence is their value. Accredited labs operate under impartiality requirements, which limits how far they can advise on fixing what they find.
Use them for assessment and testing. Arrive prepared, since a lab is an expensive place to discover design problems.
IT service providers
Your IT partner knows your infrastructure, and part of CRA compliance lives there: build pipelines, update infrastructure, access control on development environments. Product security is a different discipline from enterprise IT, with different threat models and lifecycles.
Use them to harden the environment your products are built in.
Large cyber security consultancies
They have depth, skilled people and capacity for well-defined technical work such as threat modelling, secure firmware development or penetration testing at scale. Their model is built around staffing engagements, and product regulation is often a small part of a broad practice.
Use them when you know precisely what you need done and need hands to do it.
Independent freelancers
Good freelancers are flexible and cost-effective for bounded tasks: a pentest, a threat model, a tracking framework. They deliver what you specify, so the quality of the outcome depends on your ability to specify it.
Use them when the direction is set and the task is clear.
Compliance platforms
A growing number of tools automate SBOM generation, vulnerability tracking and technical documentation. These are real needs, and automation is the right answer to them. Documentation describes a secure product. It does not create one.
Use platforms to industrialise evidence once you know what you are evidencing.
Your own team
Nobody knows your products better, and lasting capability can only live in-house. The constraints are familiar: your people are already at capacity, they may lack the mandate to change how other departments work, and they see one company’s experience.
They are the long-term answer. The question is how to get them there faster.
Product security specialists
This is where we sit, so weigh our view accordingly. A specialist’s contribution is pattern recognition: having taken many manufacturers through the same regulation, we know which requirements consume effort, which interpretations hold up, and what to prioritise for a given portfolio. The right specialist works alongside your internal team and leaves it stronger.
Use one to set the strategy, sequence the work and direct the other providers effectively.
Putting it together
Few manufacturers need only one of these. A typical programme combines them, in this order:
- A product security specialist For scoping, the roadmap and the sequencing of the other providers.
- Your own team For implementation, with the specialist where judgement is needed.
- Tooling For the evidence, once the process it documents exists: SBOMs, vulnerability tracking, documentation.
- A test laboratory For independent assessment, when the product is ready for it.
- A law firm For contracts, economic operator roles and liability.
Strategy before tooling, preparation before testing.
Summary
| Provider | Best for | Limits |
|---|---|---|
| Law firms | Contracts, economic operator roles, liability and legal risk | Do not assess product architecture or technical requirements |
| Test laboratories | Independent assessment and testing against standards | Impartiality rules limit advice on fixing findings |
| IT service providers | Hardening build pipelines, update infrastructure, development environments | Enterprise IT is a different discipline from product security |
| Large cyber security consultancies | Well-defined technical work at scale: threat modelling, secure firmware, penetration testing | Staffing-led model; product regulation is often a small part of the practice |
| Independent freelancers | Bounded, clearly specified tasks at lower cost | Outcome depends on your ability to specify the work |
| Compliance platforms | Automating SBOMs, vulnerability tracking and technical documentation | Document a secure product; do not create one |
| Your own team | Implementation and lasting in-house capability | Limited capacity, mandate and view of what works elsewhere |
| Product security specialists | Strategy, prioritisation, sequencing and directing other providers | Complement, not replace, internal teams and independent testing |
If you are unsure where to begin, start by scoping your products with CRAscoping or talk to us about sequencing your programme.
About cetome
cetome is an independent product cyber security advisory, in London and Lyon since 2017. We help connected-product manufacturers ship secure products on time, in compliance with the Cyber Resilience Act, RED and other regulations, and we publish our research and tools for the community.
This article: https://cetome.com/insights/who-does-what-in-cra-compliance/ · More insights: https://cetome.com/insights/ · Talk to us: https://cetome.com/contact/

