Business impact
Market access risk
This is the principal risk, and it is not gradual: without CE marking a product cannot be placed on the Union market.
Calculation to produce for the committee:
| Line | Value |
|---|---|
| Turnover made in the European Union | _____ €m |
| Share made by products with digital elements | _____ % |
| Turnover exposed | _____ €m |
| Share of that turnover carried by class II or Critical products | _____ % |
| Turnover dependent on a notified body | _____ €m |
The last line is what should trigger the decision: it is the turnover whose continuity depends on a third party whose lead time you do not control.
Financial exposure
Three components, detailed in Exposure and risk register:
- Administrative — up to EUR 15 m or 2.5 % of worldwide turnover.
- Commercial — turnover lost during a prohibition or withdrawal, plus recall costs for a hardware product.
- Contractual — penalties, terminations and indemnities under your contracts.
To which is added civil liability exposure: Directive (EU) 2024/2853 covers software and takes the absence of security updates into account when assessing defectiveness.
The cost of compliance
| Item | Nature | Horizon |
|---|---|---|
| Tooling | Investment then subscription | Recurring |
| Headcount | PSIRT, compliance, security engineering | Recurring |
| On-call cover | Technical and legal rota | Recurring |
| Notified bodies | Initial assessment per product and maintenance | Per product, per cycle |
| Certification of critical products | Evaluation laboratory, certificate maintenance | Per product, long cycle |
| Maintaining 5–10 year support | Preserved build chains, backports, archiving | The most underestimated |
| Training | Development, legal, procurement | One-off then recurring |
The most underestimated item is the second to last: retaining the ability to produce a fix for a version shipped eight years ago requires preserved build environments, available skills and an organisation that spends time on it with no revenue attached.
The opportunities
They are real and rarely highlighted, although they carry part of the funding case.
The SBOM has become a commercial argument. Large accounts and public buyers already ask for it in tenders. Producing one meets an obligation and shortens sales cycles.
Customer security questionnaires can be answered in hours rather than weeks once the evidence exists. Across a meaningful volume of tenders, the saving is measurable.
Acquisition and fundraising diligence now covers the CRA. A clean file avoids a liability warranty or a price holdback.
Technical debt becomes visible and quantifiable. The inventory reveals abandoned components, frozen versions and single-maintainer dependencies. It is the first time that information is available across the whole portfolio.
Response time to a major incident falls from weeks to hours. The value of that gain is measured against the cost of the last public supply chain incident.
The knock-on effect
CRA compliance covers a large share of what is expected elsewhere:
| External requirement | Covered by CRA work |
|---|---|
| NIS 2 — supply chain security, incident management | Largely |
| DORA — for your financial-sector customers | Partly |
| Customer security questionnaires | Largely |
| ISO/IEC 27001 — asset and vulnerability control | Partly |
| Licence audits | Largely, through the SBOM |
| Acquisition diligence | Largely |
Presenting the programme as a shared evidence base rather than a regulatory silo changes how it gets funded.
The message to take away
The CRA turns good practice into a condition of market access. The cost of compliance is real and recurring; the cost of non-compliance is discontinuous and potentially fatal for a product line. The trade-off is not “do it or not”, but at what pace and over what scope.