Startup Guide

CRA Compliance for Startups & Small Businesses

You're building fast. Now the EU says your product needs to be secure. Here's what the Cyber Resilience Act means for your startup—without the legal jargon.

Last updated: September 5, 2026

Does the CRA Apply to My Startup?

Short answer: If you're selling software or connected hardware in the EU, probably yes.

Quick Decision Tree

Ask yourself these questions:

  • Do you sell software (apps, SaaS, SDKs, libraries)?
  • Do you sell hardware that connects to networks?
  • Are you selling to EU customers (even from outside EU)?

If you answered yes to any combination above, CRA likely applies.

What's Covered

Covered by CRA

  • Mobile apps
  • Desktop software
  • SaaS platforms (with caveats)
  • SDKs and libraries
  • IoT devices
  • Connected hardware
  • Embedded systems

Not Covered

  • Pure consulting services
  • SaaS where data never leaves your servers*
  • Open source (non-commercial)
  • Internal tools (not sold)
  • Medical devices (covered by MDR)
  • Automotive (covered by UNECE)

*SaaS exemption is complex—see below

Top Startup Concerns Answered

"We're pre-revenue. Does CRA apply?"

CRA applies when you place a product on the EU market. Until you launch and sell, you're not technically in scope. But start building compliance into your product now—retrofitting security is 10x more expensive than building it in from the start.

"We're outside the EU. Why should we care?"

If you sell to anyone in the EU, CRA applies. If you sell to a US company that resells in the EU, CRA applies. The EU is a €17 trillion economy. Most startups can't ignore it.

"Will this block our launch?"

Full enforcement is December 2027. You have time—but not unlimited time. Products placed on market before that date must be compliant. Start the assessment now to understand your gap.

"Do we need expensive third-party certification?"

Most startups: No. Unless you're building security-critical infrastructure (firewalls, VPNs, identity systems), you can self-certify using Module A conformity assessment. That's internal documentation, not expensive third-party audits.

Minimum Viable CRA Compliance (Startup Edition)

You don't need to boil the ocean. Here's what actually matters for most startups:

1

Secure Defaults

Ship with security enabled: HTTPS, strong auth, no default passwords. This is day-one stuff.

Usually Already Done
2

Dependency Tracking (SBOM)

Know what's in your software. Run npm list, pip freeze, or equivalent. Export to CycloneDX or SPDX format.

SBOM Guide →
3

Vulnerability Disclosure Channel

Create a security.txt file and a way for researchers to report issues. Takes 10 minutes.

Generate security.txt →
4

Update Mechanism

Can you push security patches to customers? For web apps, this is automatic. For mobile/desktop, ensure auto-update is enabled by default.

5

Document Your Security

Write down what you do for security. Threat model, security testing, incident response. This becomes your "technical documentation file."

Not sure which requirements apply to your specific product?

Take the Free Assessment →

Special Case: SaaS & B2B Startups

SaaS Exemption is Nuanced

The CRA generally exempts "remote data processing" (pure SaaS). But if your SaaS:

  • Includes downloadable components (desktop apps, mobile apps)
  • Requires on-premise agents or libraries
  • Provides SDKs that customers embed in their products

...then those components are in scope.

B2B Considerations

If you sell to other businesses that resell to consumers, your product may be incorporated into their CRA obligations. They'll ask you about compliance during procurement. Having documentation ready becomes a competitive advantage.

When to Start (Honest Answer)

Pre-Seed / Seed

Build security in from day one. Costs almost nothing if you plan for it.

Priority: Secure defaults, dependency tracking

Series A+

You're scaling. Formalize your security practices and start documentation.

Priority: VDP, SBOM automation, threat modeling

Growth / Enterprise

Enterprise customers will ask about CRA. Have answers ready.

Priority: Full documentation, conformity assessment prep

Cost Estimates for Startups

ActivityDIY CostWith Consultant
Initial Gap AssessmentFree (use this tool)€2,000-5,000
SBOM Implementation1-2 days eng time€1,000-3,000
VDP & security.txt1 hour (free templates)€500-1,000
Technical Documentation1-2 weeks eng time€5,000-15,000
Third-Party Audit (if required)N/A€10,000-50,000+

Startup Advantage

You're building new. Legacy companies have to retrofit security into decades-old codebases. You can build it right from the start for a fraction of the cost.

Find Out Exactly What You Need

Take our free 6-minute assessment to get personalized recommendations for your startup's product type and risk category.

Free 5-Min Assessment