Start with a CRA Dossier or training
Choose this route when your team needs to understand a particular CRA requirement before deciding whether further support is necessary.
Explore CRA resourcesCRA Consultancy
Turn CRA requirements into a practical, product-specific compliance plan.
Understand how the Cyber Resilience Act applies to your products, identify gaps and establish clear priorities, responsibilities and evidence requirements.
We have your question and will be in touch within two working days.
Comply.Land provides Cyber Resilience Act consultancy for manufacturers of products with digital elements, including software, connected devices, Internet of Things (IoT) products and products incorporating third-party digital components.
We also support importers, distributors, commercial open-source businesses and manufacturers based outside the European Union that are preparing to place products on the EU market. Whether you already have an established presence in the EU, work with an Authorised Representative or are still considering the most appropriate route, we can help you understand your options and responsibilities.
Learn more about our EU Authorised Representative service
Our specialists connect CRA requirements with your product-development processes, vulnerability-management procedures, software supply chain, technical documentation and route to conformity.
Define your CRA route before investing time in documentation, testing or processes that may not apply to your products.
Comply.Land supports organisations that manufacture, import, distribute or place products with digital elements on the European Union market. This includes:
Clarify whether the CRA applies to the relevant products and identify whether the organisation acts as a manufacturer, importer, distributor or another economic operator. We can also help identify relevant exclusions, dependencies and responsibilities involving suppliers, open-source components and other third parties.
Assess whether a product is likely to fall within the default category or qualify as an important Class I, important Class II or critical product with digital elements. Identify the likely conformity-assessment route and the documentation and evidence the organisation may need to prepare.
Compare the organisation's existing product-security processes, technical evidence and documentation with the applicable CRA requirements. Identify what is already in place, what requires improvement and what is missing.
Review how vulnerabilities and severe incidents affecting product security are identified, assessed, escalated, documented and reported. This can include internal responsibilities, evidence preservation, coordinated vulnerability disclosure and preparation for the CRA reporting obligations applicable since 11 September 2026.
Support the preparation or review of documentation demonstrating how a product meets the applicable CRA requirements. This may include cybersecurity risk assessments, security requirements, development evidence, testing records, vulnerability-management procedures, support-period decisions and information provided to users.
Review how the organisation identifies and manages open-source software, commercial components and other digital dependencies included in its products.
Help translate applicable CRA requirements into product-development and maintenance processes, including security by design, security updates, vulnerability remediation and support throughout the product lifecycle.
Help the organisation understand the documentation, evidence, testing and internal decisions required for its likely conformity-assessment route. Comply.Land consultancy and expert review do not replace certification or a formal third-party conformity assessment where one is legally required.
Every engagement is scoped around the products, questions and outcomes agreed with your organisation. Depending on that scope, you may receive:
A written assessment covering the relevant products, organisational role, likely product classification and current level of CRA preparation.
A practical plan identifying gaps, recommended actions, dependencies, responsibilities and priorities.
A structured view of the technical documentation, product-security evidence, vulnerability-management processes and reporting workflows that require development or improvement.
An outline of the likely conformity route and the documentation, evidence, testing and internal decisions required to prepare for it.
The final deliverables are defined in the agreed scope and proposal.
Consultancy is most useful when your organisation has complex products, an uncertain route to compliance, significant documentation gaps or questions requiring product-specific analysis.
You may not need an ongoing consultancy engagement if your team already understands the applicable requirements and can complete most of the preparation internally. Comply.Land offers several ways to obtain the level of support you need.
Choose this route when your team needs to understand a particular CRA requirement before deciding whether further support is necessary.
Explore CRA resourcesA tailored workshop can help engineering, product security, compliance, legal and leadership teams understand their responsibilities, address product-specific questions and agree on practical next steps.
Plan a CRA WorkshopIf your organisation is ready to carry out the preparation work itself, the CRA Compliance Binder provides a structured framework for assembling the required documentation and evidence.
Comply.Land specialists review the completed package against the agreed CRA scope and identify areas requiring further work. Comply.Land's expert review is not certification or a formal conformity assessment by a notified body.
Explore the CRA Compliance BinderConsultancy is appropriate when your organisation needs deeper product analysis, help resolving gaps, continuing access to specialist knowledge or support coordinating implementation across several products and teams.
Discuss CRA consultancyWe discuss your organisation, products, current preparation and the questions or outcomes you need to address. If consultancy is not the most appropriate starting point, we will explain which form of support may suit your current position better.
Comply.Land defines the proposed work, expected deliverables, required information, timing and price.
Our specialists review the relevant products, processes and documentation and work with the appropriate members of your team.
You receive the agreed outputs, priorities and recommendations. Where further implementation support is required, this can be included in the proposal or agreed as a subsequent phase.
Comply.Land combines regulatory knowledge, cybersecurity expertise, software-industry experience and direct involvement in European standardisation.
Our in-house specialists include multiple ETSI Rapporteurs contributing to the development of standards intended to translate CRA requirements into technical specifications and assessment criteria. This involvement helps us connect regulatory obligations with the practical processes, evidence and product decisions organisations need to prepare for compliance.
Meet the Comply.Land teamNot ready for consultancy? If your organisation does not yet need product-specific consultancy, you can begin with:
Consultancy may be appropriate when an organisation is uncertain how the CRA applies to its products, needs help with product classification, has significant documentation or process gaps, or requires product-specific advice that cannot be answered through general guidance.
No. Some organisations have the internal knowledge and resources to complete much of the preparation themselves. In these cases, a Dossier, training course, workshop, focused assessment or the CRA Compliance Binder may provide a more appropriate starting point.
Yes. The scope can cover one product, a product family or a wider portfolio. The proposed approach, timing and deliverables will depend on the number and complexity of the products involved.
Yes. Comply.Land can help manufacturers based outside the EU understand their CRA responsibilities and prepare products for the European market. Where relevant, we can also explain the possible role of an EU Authorised Representative.
Consultancy and expert review do not constitute certification or a formal third-party conformity assessment. Where a formal third-party assessment is required, the appropriate route will depend on the product classification and applicable legal requirements.
The price depends on the products, questions, documentation, number of teams involved and agreed deliverables. Following the initial discussion, Comply.Land provides a proposed scope, timing and price before work begins.
Tell us about your organisation, products and current CRA questions. We will help define the appropriate scope, deliverables and next steps.