Does the CRA Apply to My Startup?
Short answer: If you're selling software or connected hardware in the EU, probably yes.
Quick Decision Tree
Ask yourself these questions:
- Do you sell software (apps, SaaS, SDKs, libraries)?
- Do you sell hardware that connects to networks?
- Are you selling to EU customers (even from outside EU)?
If you answered yes to any combination above, CRA likely applies.
What's Covered
Covered by CRA
- Mobile apps
- Desktop software
- SaaS platforms (with caveats)
- SDKs and libraries
- IoT devices
- Connected hardware
- Embedded systems
Not Covered
- Pure consulting services
- SaaS where data never leaves your servers*
- Open source (non-commercial)
- Internal tools (not sold)
- Medical devices (covered by MDR)
- Automotive (covered by UNECE)
*SaaS exemption is complex—see below
Top Startup Concerns Answered
"We're pre-revenue. Does CRA apply?"
CRA applies when you place a product on the EU market. Until you launch and sell, you're not technically in scope. But start building compliance into your product now—retrofitting security is 10x more expensive than building it in from the start.
"We're outside the EU. Why should we care?"
If you sell to anyone in the EU, CRA applies. If you sell to a US company that resells in the EU, CRA applies. The EU is a €17 trillion economy. Most startups can't ignore it.
"Will this block our launch?"
Full enforcement is December 2027. You have time—but not unlimited time. Products placed on market before that date must be compliant. Start the assessment now to understand your gap.
"Do we need expensive third-party certification?"
Most startups: No. Unless you're building security-critical infrastructure (firewalls, VPNs, identity systems), you can self-certify using Module A conformity assessment. That's internal documentation, not expensive third-party audits.
Minimum Viable CRA Compliance (Startup Edition)
You don't need to boil the ocean. Here's what actually matters for most startups:
Secure Defaults
Ship with security enabled: HTTPS, strong auth, no default passwords. This is day-one stuff.
Usually Already DoneDependency Tracking (SBOM)
Know what's in your software. Run npm list, pip freeze, or equivalent. Export to CycloneDX or SPDX format.
SBOM Guide →Vulnerability Disclosure Channel
Create a security.txt file and a way for researchers to report issues. Takes 10 minutes.
Generate security.txt →Update Mechanism
Can you push security patches to customers? For web apps, this is automatic. For mobile/desktop, ensure auto-update is enabled by default.
Document Your Security
Write down what you do for security. Threat model, security testing, incident response. This becomes your "technical documentation file."
Not sure which requirements apply to your specific product?
Take the Free Assessment →Special Case: SaaS & B2B Startups
SaaS Exemption is Nuanced
The CRA generally exempts "remote data processing" (pure SaaS). But if your SaaS:
- Includes downloadable components (desktop apps, mobile apps)
- Requires on-premise agents or libraries
- Provides SDKs that customers embed in their products
...then those components are in scope.
B2B Considerations
If you sell to other businesses that resell to consumers, your product may be incorporated into their CRA obligations. They'll ask you about compliance during procurement. Having documentation ready becomes a competitive advantage.
When to Start (Honest Answer)
Pre-Seed / Seed
Build security in from day one. Costs almost nothing if you plan for it.
Priority: Secure defaults, dependency tracking
Series A+
You're scaling. Formalize your security practices and start documentation.
Priority: VDP, SBOM automation, threat modeling
Growth / Enterprise
Enterprise customers will ask about CRA. Have answers ready.
Priority: Full documentation, conformity assessment prep
Cost Estimates for Startups
| Activity | DIY Cost | With Consultant |
|---|---|---|
| Initial Gap Assessment | Free (use this tool) | €2,000-5,000 |
| SBOM Implementation | 1-2 days eng time | €1,000-3,000 |
| VDP & security.txt | 1 hour (free templates) | €500-1,000 |
| Technical Documentation | 1-2 weeks eng time | €5,000-15,000 |
| Third-Party Audit (if required) | N/A | €10,000-50,000+ |
Startup Advantage
You're building new. Legacy companies have to retrofit security into decades-old codebases. You can build it right from the start for a fraction of the cost.
Find Out Exactly What You Need
Take our free 6-minute assessment to get personalized recommendations for your startup's product type and risk category.
Free 5-Min Assessment