Legal path in 10 steps
Thirty minutes, ten steps, in order. Each step ends with the question you should be able to answer before moving on.
1. Understand what kind of text this is — 3 min
Read The CRA framework and Regulation (EU) 2024/2847.
A Regulation, not a Directive: directly applicable, no transposition. Union harmonisation legislation under the new legislative framework: the grammar of CE marking, applied to cybersecurity.
Be able to answer: why will there be no national transposition law capable of pushing the deadline back?
2. Determine whether your products are in scope — 5 min
Read Scope then Exclusions.
Watch three points: components placed on the market separately are products in their own right; remote data processing solutions inseparable from the product are in scope; pure SaaS falls under NIS 2 instead.
Be able to answer: is your cloud offering a remote data processing solution within the meaning of the Regulation, or an out-of-scope service?
3. Classify each product — 4 min
Read Criticality classes.
This is the page that drives budget and schedule: the class determines whether a notified body is mandatory.
Be able to answer: which of your products cannot self-assess?
4. Know what CE marking requires — 3 min
Read CE marking.
Seven cumulative conditions before affixing, including the technical documentation and the EU declaration of conformity.
Be able to answer: which pieces are missing today for your flagship product?
5. Understand where the SBOM fits — 3 min
Read What the CRA requires of the SBOM then Technical documentation.
The SBOM is a constituent part of the technical documentation, not a side deliverable.
Be able to answer: why does a file without a usable SBOM legally weaken the CE marking?
6. Internalise the reporting deadlines — 4 min
Read Reporting to ENISA then Reporting duties, legal view.
24 hours, 72 hours, 14 days. Do not confuse this with the GDPR’s 72 hours or with NIS 2 notification: one event can trigger all three.
Be able to answer: who, here, has authority to decide on a report at 3 a.m. on a Sunday?
7. Size the exposure — 3 min
The fine is not the worst of it: a ban on, or withdrawal from, the Union market is.
Be able to answer: what is 2.5 % of your consolidated turnover, and what share of your turnover is made in the Union?
8. Secure the supply chain by contract — 3 min
Read Contract clauses.
Your reporting deadlines depend on how fast your suppliers react: their notification deadlines must be strictly shorter than yours.
Be able to answer: do your current supplier contracts let you meet 24 hours?
9. Handle intellectual property — 2 min
Read Open source licensing — in particular the family × scenario matrix — then Intellectual property.
The CRA does not mandate licence compliance, but the SBOM it does mandate is precisely the tool that makes licence compliance demonstrable. That is the strongest funding argument on the Legal side.
10. Lock the market gate — 2 min
Read Pre-market checklist.
Fifteen points, one page, printable and signable. It is the deliverable that gives Legal’s veto its substance.
Next
User information, Support period and Evidence retention complete the path. The glossary and FAQ answer point questions.