Engineer reviewing code and security dashboards on dark monitors
EU Cyber Resilience Act legal specialists

Is your product ready
for the EU Cyber
Resilience Act?

Your product. Your obligations. Your legal partner.
We provide specialist legal advice to help technology companies understand their CRA obligations, manage regulatory risk and prepare for compliance.

Focused exclusively on the CRABuilt for technology companies

until the Cyber Resilience Act applies in full · 11 December 2027

Reporting duties are already in force for products on the market.
Understanding your legal obligations and addressing gaps takes time — get legal advice before the full requirements apply.

Understand the timeline

FOR THE COMPANIES
BUILDING WHAT’S NEXT

Software & SaaSIoT & smart devicesRoboticsConnected hardwareIndustrial tech
Clarity. Readiness. Confidence.

Specialist legal advice.
For your digital products.

The CRA creates legal obligations throughout a product’s lifecycle. We interpret the regulation for your business and advise on scope, responsibilities and compliance — not technical implementation.

01

Understand your legal obligations.

Get a legal assessment of whether your products fall within the CRA, your role in the supply chain and the obligations that apply to your business.

Legal opinion on scope & obligations
02

Address your legal exposure.

Identify gaps against the CRA’s legal requirements. We advise on manufacturer, importer and distributor duties, reporting obligations and the allocation of responsibilities in your supply chain.

Legal compliance review & advice
03

Navigate conformity & reporting.

Get legal guidance on the applicable conformity assessment route, documentation duties and regulatory reporting. We review the legal requirements; your technical team remains responsible for implementation and technical evidence.

Legal support for regulatory obligations

Not every digital business is automatically in scope. Standalone SaaS, product-linked cloud services and supply-chain roles need a product-specific review.

The clock is already running

One regulation.
Three milestones to know.

11 December 2027 is the finish line for preparation, not the starting point. The first obligations are already in force.

Applied since

11 June 2026

Conformity assessment bodies

Rules for notifying conformity assessment bodies begin to apply.

Live now

11 September 2026

Reporting obligations

Manufacturers must notify actively exploited vulnerabilities and severe incidents via the ENISA single reporting platform: early warning in 24 hours, notification in 72 hours, final report in 14 days or one month. These duties cover products already on the market.

Your preparation deadline

11 December 2027

Full CRA application

The full framework applies, including product cybersecurity requirements and conformity obligations, subject to transitional rules.

CE marking under the CRA

CE marking becomes
mandatory for your product.

From 11 December 2027, a product in scope of the CRA cannot be placed on the EU market unless it carries CE marking confirming that it meets the regulation’s cybersecurity requirements. The mark itself is not new — what changes is that cybersecurity becomes part of the legal basis for it. That legal basis is what we advise on.

CE

Do we need a notified body?

Legal advice on which conformity assessment route your product falls into: internal control, or a notified body for the higher-risk classes. This is what drives your cost and your timeline.

CE

What must the declaration state?

Guidance on the EU declaration of conformity: its legal content, who signs it, how long it must be kept, and what it commits your company to.

CE

What does the law require us to document?

Advice on what your technical documentation must legally demonstrate, and which part of that duty falls on you, your supplier or your distributor.

CE

Who is legally responsible for the mark?

When the CE mark must be affixed, who may lawfully affix it, and the consequences — withdrawal, recall or penalties — of placing a product on the market without it.

We advise on the legal requirements behind CE marking. Testing, security audits and the technical evidence itself remain with your engineering team.

Specialist by design

Not another regulation.
Our entire focus.

Our focus is the legal framework governing products with digital elements. We provide dedicated CRA legal advice tailored to your business, your products and your role in the European market.

Legal expertise. Product-specific advice.

Clear interpretation of the CRA’s legal requirements for leadership, legal and product teams, grounded in your specific circumstances.

Advice tailored to your legal role.

Legal support for startups, SMEs and established technology companies, whether you act as a manufacturer, importer or distributor.

Legal support, not technical delivery.

Advice on obligations, regulatory risk, conformity and reporting before 11 December 2027. Engineering and cybersecurity implementation stay with your technical team.

The questions that matter

Less uncertainty.
More clarity.

Does the CRA apply to my product?

The CRA covers many hardware and software products with digital elements made available on the EU market, including components. Scope depends on the product, its connectivity, your role and any applicable exclusions. A product-level review is the right starting point.

Are SaaS companies covered by the CRA?

Standalone SaaS is not automatically covered. Remote data processing solutions may be included when they are developed by or under the responsibility of a manufacturer and are necessary for a product to perform a function. We assess the actual product architecture, not just the business label.

Is 11 December 2027 our only deadline?

No. Reporting obligations have already applied since 11 September 2026: manufacturers must notify actively exploited vulnerabilities and severe incidents through the ENISA single reporting platform, with an early warning within 24 hours and a notification within 72 hours. Those duties cover products already on the market. The full product requirements and conformity obligations then apply from 11 December 2027.

What if we are an importer or distributor?

The CRA includes distinct obligations for manufacturers, importers and distributors. Importers and distributors need to carry out relevant verification, traceability and cooperation duties. Selling under your own brand or substantially modifying a product can also change your role.

Does your legal advice include technical implementation?

No. Squdo provides legal advice on CRA scope, obligations, regulatory risk, conformity and reporting. We do not carry out engineering, cybersecurity testing or technical implementation, and our advice is not a product certification. The preliminary online check is indicative only, not a legal opinion.

Reporting is live. Full application 11 December 2027.

Your next product milestone?
CRA readiness.

Understand your obligations. Address legal risk. Prepare with specialist legal support.