Understand your legal obligations.
Get a legal assessment of whether your products fall within the CRA, your role in the supply chain and the obligations that apply to your business.

Your product. Your obligations. Your legal partner.
We provide specialist legal advice to help technology companies understand their CRA obligations, manage regulatory risk and prepare for compliance.
until the Cyber Resilience Act applies in full · 11 December 2027
Reporting duties are already in force for products on the market.
Understanding your legal obligations and addressing gaps takes time — get legal advice before the full requirements apply.
FOR THE COMPANIES
BUILDING WHAT’S NEXT
The CRA creates legal obligations throughout a product’s lifecycle. We interpret the regulation for your business and advise on scope, responsibilities and compliance — not technical implementation.
Get a legal assessment of whether your products fall within the CRA, your role in the supply chain and the obligations that apply to your business.
Identify gaps against the CRA’s legal requirements. We advise on manufacturer, importer and distributor duties, reporting obligations and the allocation of responsibilities in your supply chain.
Get legal guidance on the applicable conformity assessment route, documentation duties and regulatory reporting. We review the legal requirements; your technical team remains responsible for implementation and technical evidence.
Not every digital business is automatically in scope. Standalone SaaS, product-linked cloud services and supply-chain roles need a product-specific review.
11 December 2027 is the finish line for preparation, not the starting point. The first obligations are already in force.
Rules for notifying conformity assessment bodies begin to apply.
Manufacturers must notify actively exploited vulnerabilities and severe incidents via the ENISA single reporting platform: early warning in 24 hours, notification in 72 hours, final report in 14 days or one month. These duties cover products already on the market.
The full framework applies, including product cybersecurity requirements and conformity obligations, subject to transitional rules.
From 11 December 2027, a product in scope of the CRA cannot be placed on the EU market unless it carries CE marking confirming that it meets the regulation’s cybersecurity requirements. The mark itself is not new — what changes is that cybersecurity becomes part of the legal basis for it. That legal basis is what we advise on.
Legal advice on which conformity assessment route your product falls into: internal control, or a notified body for the higher-risk classes. This is what drives your cost and your timeline.
Guidance on the EU declaration of conformity: its legal content, who signs it, how long it must be kept, and what it commits your company to.
Advice on what your technical documentation must legally demonstrate, and which part of that duty falls on you, your supplier or your distributor.
When the CE mark must be affixed, who may lawfully affix it, and the consequences — withdrawal, recall or penalties — of placing a product on the market without it.
We advise on the legal requirements behind CE marking. Testing, security audits and the technical evidence itself remain with your engineering team.
Our focus is the legal framework governing products with digital elements. We provide dedicated CRA legal advice tailored to your business, your products and your role in the European market.
Clear interpretation of the CRA’s legal requirements for leadership, legal and product teams, grounded in your specific circumstances.
Legal support for startups, SMEs and established technology companies, whether you act as a manufacturer, importer or distributor.
Advice on obligations, regulatory risk, conformity and reporting before 11 December 2027. Engineering and cybersecurity implementation stay with your technical team.
The CRA covers many hardware and software products with digital elements made available on the EU market, including components. Scope depends on the product, its connectivity, your role and any applicable exclusions. A product-level review is the right starting point.
Standalone SaaS is not automatically covered. Remote data processing solutions may be included when they are developed by or under the responsibility of a manufacturer and are necessary for a product to perform a function. We assess the actual product architecture, not just the business label.
No. Reporting obligations have already applied since 11 September 2026: manufacturers must notify actively exploited vulnerabilities and severe incidents through the ENISA single reporting platform, with an early warning within 24 hours and a notification within 72 hours. Those duties cover products already on the market. The full product requirements and conformity obligations then apply from 11 December 2027.
The CRA includes distinct obligations for manufacturers, importers and distributors. Importers and distributors need to carry out relevant verification, traceability and cooperation duties. Selling under your own brand or substantially modifying a product can also change your role.
No. Squdo provides legal advice on CRA scope, obligations, regulatory risk, conformity and reporting. We do not carry out engineering, cybersecurity testing or technical implementation, and our advice is not a product certification. The preliminary online check is indicative only, not a legal opinion.
Understand your obligations. Address legal risk. Prepare with specialist legal support.