Skip to content

Frequently Searched

Tap to search.

Direct Contact

info@maibornwolff.de
A person in uniform is holding a stamp at a counter; in front of it are a washing machine, a robotic arm, a charging station, and a tractor, all bathed in blue and red light

CRA Consulting

Comply with the Cyber Resilience Act and implement it technically in the product

BMW Group Logo
DeutscheBahn_logo-2
Creditreform Logo
DERTOUR
jochen-schweizer
Dräger Logo
kuka
BMW Group Logo
DeutscheBahn_logo-2
Creditreform Logo
DERTOUR
jochen-schweizer
Dräger Logo
kuka
ProSieben_Logo_2015-2
Mercedes
Volkswagen Logo
DEKRA
stihl
Sonax_logo
Weidmüller logo
Das Logo der Bundesagentur für Arbeit
ProSieben_Logo_2015-2
Mercedes
Volkswagen Logo
DEKRA
stihl
Sonax_logo
Weidmüller logo
Das Logo der Bundesagentur für Arbeit
HomeServicesIoTCRA Consulting

From requirements analysis to a compliant, networked product—all from a single source

The EU Cyber Resilience Act (CRA) will make cybersecurity mandatory for all connected products with digital components starting in December 2027. For manufacturers, this means that security will go from being an optional feature to a legal requirement throughout the entire product lifecycle. The real challenge rarely lies in understanding the requirements, but rather in their technical implementation within the device—where firmware, update pathways, and the supply chain converge.

This is exactly where we come in. MaibornWolff combines regulatory expertise with deep engineering know-how: We don’t just advise you on which obligations apply to your products; we work with you to implement them technically—from Security by Design (SBOM) to secure over-the-air updates. This way, CRA compliance becomes not just a paperwork process, but a maintainable, compliant product.

Less Technology. Better Business.

What the Cyber Resilience Act Means for Manufacturers

The Cyber Resilience Act is the first EU regulation to establish mandatory cybersecurity requirements for all connected products with digital components on the EU market. It has been in effect since December 2024; its requirements take effect in phases. Those who get a head start on regulatory compliance gain one thing above all else: planning certainty and market access.

An overview of the key deadlines:

  • As of December 10, 2024: The regulation has taken effect.
  • Effective September 11, 2026: Vulnerabilities that are actively being exploited must be reported via the European reporting platform to the relevant CSIRT—in Germany, the BSI—and to ENISA.
  • Effective December 11, 2027: All product requirements are mandatory; the CE marking serves as proof of compliance.

The core obligations for manufacturers include “security by design,” vulnerability management throughout the entire support period, a machine-readable SBOM, mandatory reporting, and CE marking of compliant products. The support period is at least five years—but must correspond to the expected useful life and, in the case of household appliances, industrial equipment, or elevators, is significantly longer than ten years. Manufacturers must specify this period before the product is sold; it thus becomes a promised product characteristic. Violations can be penalized with fines of up to 15 million euros or 2.5% of global annual revenue. The CRA also interacts with NIS-2, the Radio Equipment Directive (RED), and the AI Act—a well-thought-out implementation therefore often covers multiple requirements at once.

Existing Equipment Is Also Affected: When Retrofitting Becomes Mandatory

The CRA is not just an issue for new products. The decisive factor for each individual device is the date on which it first enters the EU market: If this date is December 11, 2027, or later, the CRA applies in full—even for a product line that has been in production unchanged for years, and even for goods that have already been produced and are still in inventory.

Anyone who makes a significant modification to a device that has already been delivered is, for legal purposes, placing it on the market anew. Security updates do not trigger this, but a major functional update can. As a result, retrofitting security features is becoming a prerequisite for continued market access for many manufacturers—an issue that is causing quite a stir, particularly in the machinery and plant engineering sectors as well as among home appliance manufacturers.

MaibornWolff: Your Partner for CRA Consulting and Implementation

Unlike certification bodies or pure compliance consultants, we have the technical implementation expertise that the CRA fundamentally requires. We speak the language of your hardware engineers as well as that of cloud platforms—and approach compliance from a product perspective.

Consulting + Implementation

We determine which CRA requirements apply to your products and implement them technically—rather than simply providing an expert opinion. A single point of contact from analysis through to a compliant device.

Security by Design

We embed security into the architecture and development process from the very beginning, not as an afterthought. This meets the CRA’s core requirement and reduces long-term maintenance and retrofitting costs.

Level of Engineering Expertise

OTA update architectures, Secure Boot, SBOM in the CI/CD pipeline: We’ve built these components into real-world product fleets—not just designed them—with over 10 years of IoT experience.

Technology-independent

We do not have our own platform product and recommend the solution that best fits your needs and existing architecture—based on a vendor-neutral and honest evaluation.

Philipp Lindemann Quote (Small)
Key to the project's success: The team did not attempt to impose security on the development teams from the outside by taking on a "police role." Instead, it empowered our teams to systematically assess security themselves.
Philipp Lindemann, then project manager, MAN Truck & Bus SE

These companies already rely on our expertise

Our CRA Services: From Assessing the Current Situation to a Compliant Product

Depending on the initial situation, we get involved at the appropriate stage. The result is always the same: a clear path to CRA compliance that is technically sound and works in practice.

Abstract Lines

1. CRA Readiness Check and Impact Analysis

First, we’ll work with you to determine which of your products fall under the CRA and which risk class they belong to. We’ll assess the current status of your firmware, update capabilities, and supply chain, and pinpoint exactly where action is needed. This gives you a solid foundation for planning, rather than relying on guesswork.

Determine Your CRA Status in 2 Minutes

Whether you, as a manufacturer of hardware, software, or connected products, are subject to the Cyber Resilience Act—and how urgent the need for action is—depends on your current situation. Our free online assessment shows you in about two minutes where you stand and what your next steps should be.

2. Security Assessment and Vulnerability Analysis

3. Security by Design in Product Architecture

4. SBOM, Vulnerability Management, and Reporting Processes

5. Secure OTA Updates Throughout the Product Lifecycle

6. Documentation and the Process for Obtaining CE Marking

Not sure where you stand with the CRA?

Whether it's a readiness check, a security assessment, or a full implementation: We step in exactly where you need support. Talk to our CRA experts about your next step.

Who Should Consider CRA Consulting

The CRA affects all manufacturers of connected products with digital components. The need for action is particularly urgent in industries with long product life cycles and large device fleets:

  • Machinery and Plant Engineering — networked machines with a long service life, often requiring retrofitting.
  • Home Appliances and Consumer IoT — connected mass-market products with app integration and OTA capability.
  • Energy and Building Technology — PV/Storage, Charging Infrastructure, Building Automation, some of which are related to NIS-2.
  • Industrial and safety technology, sensor technology — networked devices, some of which are safety-critical.
  • AgTech and veterinary technology — connected agricultural machinery and equipment for the veterinary sector. Unlike medical devices intended for human use, they are not regulated under any other framework and therefore fall directly under the CRA.

Still need to win over internal stakeholders? We provide the factual basis you need to clearly demonstrate the need for action to management and the board—from the timeline to the effort involved.

There’s a clear order for implementation: First come the elements tied to the hardware that can’t be updated later—bootloaders, memory layout, and key storage. Next come the SBOM and fleet overview, because vulnerability assessment and reporting deadlines depend on them. Documentation comes last, as it results from the measures taken previously. Each step can be commissioned individually; it’s possible to opt out after any step, and both the source code and documentation belong to the customer.

And the investment pays off twice: The CRA compels manufacturers to adopt exactly the infrastructure they need for digital services anyway. Once built correctly, this infrastructure not only complies with the regulation but also allows manufacturers to remotely maintain and expand their products and monetize them through additional services.

Your Benefits: Compliance That Holds Up Technically

Market Access Secured

By ensuring timely CRA compliance, you secure access to the EU market and the CE marking—without the risk of non-approval just before the deadline.

Product Safety

Security by Design, SBOM, and secure updates truly protect your products throughout their entire lifecycle—not just on paper.

Predictable Costs

A prioritized roadmap makes costs transparent. Setting the course early on helps avoid costly retrofits and field deployments later on.

One partner instead of many

Consulting, engineering, and operations all from a single source: fewer points of contact, clear accountability, and faster implementation.

MaibornWolff uses its own tools for threat analysis and ongoing vulnerability management: ThreatSea for structured threat analysis and SecObserve for continuous vulnerability management during operations—which sets it apart from a pure consulting firm.

Our References and Projects

MaibornWolff has already implemented the CRA’s requirements in specific security projects—ranging from a certifiable secure software development lifecycle to threat and risk analyses and platform hardening in the field.

  • A person wearing a high-visibility vest stands in front of a lit industrial facility at night in the fog; a reflection on the wet ground.
    A New Approach to Workplace Safety: Live Monitoring and Management of Gas Detectors in the Cloud
    About the Monitoring Reference
    CybersecurityEmbedded Systems & RoboticsIoT

    Cloud Platform for Live Monitoring and Management of Mobile Gas Detectors

    About the Monitoring Reference

    Cloud-native microservices, IoT gateway, scalable Kubernetes backend (Azure)

    About the Monitoring Reference

    Real-time alerts worldwide in under 10 seconds, 140,000+ devices

    About the Monitoring Reference
  • A fleet of self-driving trucks from MAN on a spacious test site.
    MAN - ATLAS L4. Control Center for the autonomous truck
    To the MAN reference
    CloudData/Data PlatformsApps

    Control center for the technical monitoring of driverless trucks

    To the MAN reference

    UX design, product strategy, data structure, vehicle data visualization

    To the MAN reference

    Monitoring, remote support, mission management, reports for commercial autonomous transport solutions

    To the MAN reference
  • Two people in white protective suits stand in front of a pipeline through which green glowing data streams are pumped
    NETZSCH: Development of an IoT platform
    To the NETZSCH reference
    CloudData/Data PlatformsIoT

    Unified IoT platform for 3 business units, harmonization of existing IoT solutions

    To the NETZSCH reference

    IoT device connectivity, visualization software for data analysis, cloud infrastructure, operations

    To the NETZSCH reference

    Quick testing in the cloud infrastructure, fast integration of use cases such as predictive maintenance, process optimizations, etc.

    To the NETZSCH reference
  • A shot from space with a view of the earth. A satellite hovers in the foreground. A forest fire can be seen on the ground below.
    OroraTech - Security & Compliance Support
    To the OroraTech reference
    CloudCybersecurityIT Consulting & Strategy

    Risk threat analyses for satellite startup

    To the OroraTech reference

    Security process definition, IT security risk register, action plan

    To the OroraTech reference

    Future-proof IT security for successful growth

    To the OroraTech reference
  • A modern high-rise building with an eye-catching orange-purple color gradient featuring a central, transparent exterior elevator unit.
    TK Elevator: Health Check Connectivity for the IoT gateway of elevators
    To the TKE reference
    CybersecurityIoTEmbedded Systems & Robotics

    IoT gateway (MAX Box) for data connection between elevator & IoT platform

    To the TKE reference

    Examination of code quality, architecture, operations & organization

    To the TKE reference

    Optimization of IoT gateway connectivity & digitalization of elevators

    To the TKE reference
  • A person stands on a platform at sunset with digitally superimposed graphics.
    inCTRL Solutions: Modernization of the IoT platform for water treatment plants
    To inCTRL reference
    CloudIoTIT Modernization

    IoT & software modernization, integration of new functions

    To inCTRL reference

    Data warehouse setup, integration of microservices, automated quality assurance, Continuous Integration & Continuous Deployment (CI/CD)

    To inCTRL reference

    Improved resilience, maintainability & further development capability of the platform

    To inCTRL reference
  • A red MAN truck drives along an empty road under a clear night sky with shining stars.
    MAN: Efficient threat analysis for control units
    See MAN reference
    CybersecurityIoTEmbedded Systems & Robotics

    Protection of digitalized trucks against virtual attacks

    See MAN reference

    Risk analysis based on 4x6 methodology, ThreatSea, ISO21434

    See MAN reference

    Quick identification of relevant threats for immediately effective security measures

    See MAN reference
  • Person uses Miele app in modern kitchen.
    Miele domestic appliances are networked worldwide
    See Miele reference
    CloudIoTEmbedded Systems & Robotics

    Further development of the IoT platform for connected home appliances

    See Miele reference

    Container-based architecture, open standards, modular design

    See Miele reference

    Quick availability & scalability of digital services, high added value for users

    See Miele reference
  • Header_Stiehl-IMOW-16-9
    STIHL: Control iMOW robotic mower via app
    See STIHL reference
    CloudAppsIoT

    Control and configuration of the robotic mower via smartphone

    See STIHL reference

    Development of app, web, cloud platform and direct Bluetooth communication

    See STIHL reference

    Digital benefits for users, app controllability, remote software updates

    See STIHL reference
  • Header_ifm
    ifm services: Remote maintenance of systems and machines
    See ifm services reference
    CloudIoTEmbedded Systems & Robotics

    Fully integrated remote access in the IoT platform

    See ifm services reference

    Full stack cloud application, RUST-based clients, UX design

    See ifm services reference

    Analysis of sensor data from production as a basis for sustainable decisions for customers

    See ifm services reference
  • Man checks MAN trucks at sunset.
    MAN: Secure Software Development Life Cycle
    See MAN reference
    CybersecurityIT Consulting & StrategyQuality Engineering

    Protection of digitalized vehicles against virtual attacks & digital threats

    See MAN reference

    SSDLC in vehicle backend systems (UNECE R155), cybersecurity management system

    See MAN reference

    Guidelines, methodologies & tools for independent risk identification, assessment & treatment by employees

    See MAN reference
  • The dashboard of a car shows a display with a notification about a remote software upgrade.
    BMW Group: Remote software upgrade for vehicles
    See BMW Group reference
    CloudCybersecurityIoT

    Software upgrades without the need to visit a service center

    See BMW Group reference

    Backend system for over-the-air communication with the vehicle, 24/7 support

    See BMW Group reference

    IT security, more comfort, on-demand provision of new features

    See BMW Group reference
  • A person in a modern office checks proof of identity on the web on a laptop and smartphone.
    Creditreform: Secure proof of identity on the web
    See Creditreform reference
    CybersecurityWeb & Portal PlatformsBanking/Insurance/FSI

    Fast, customer-friendly & fraud-proof digital identity verification

    See Creditreform reference

    Pilot for the forgery-proof storage & management of identity & company information in a Decentralized Identity (DID)

    See Creditreform reference

    Verified data reusable across different providers

    See Creditreform reference
  • Technician installs solar panel on roof at sunset
    SMA: Development of a Web UI for ennexOS platform
    See SMA reference
    Digital Design/UX DesignIoTWeb & Portal Platforms

    Creation of a unified customer experience across all products, smooth generational transition for customers, secure, agile operation

    See SMA reference

    WebUI for the digitalization & automation of energy management processes, open-source solution for energy flow visualization

    See SMA reference

    Energy flow & cost optimization, operational reliability, customer-friendliness

    See SMA reference
  • A person stands in a modern, abstract room and holds a tablet in their hands.
    Weidmüller: Progression of the Industrial Service Platform
    See Weidmüller reference
    CloudIoTWeb & Portal Platforms

    Creation of a centralized, intuitive, expandable portal as the foundation for industrial applications (remote access, data visualization, ML)

    See Weidmüller reference

    Exploration, setup & further development of the base platform for industrial services

    See Weidmüller reference

    Innovative portal for end-to-end solutions, MVP in just 7 months

    See Weidmüller reference

Why In-Depth Engineering at CRA Makes the Difference

Compliance rarely fails due to a lack of will, but rather due to implementation issues. According to the MaibornWolff Technology Efficiency Study 2026 (n = 305 IT managers), overly complex software hinders productivity for 61% of respondents. Applied to the CRA, this means: Those who merely document security requirements but fail to properly integrate them into architecture and update processes end up creating extra work without providing any protection. It is precisely this integration that is our core competency.

Two people are sitting at a table, working together on a laptop.
Make Your Products CRA-Compliant

From impact analysis to technical implementation in the device: Our experts will show you where you stand and how you can achieve CRA compliance in a planned and systematic way. Schedule a no-obligation initial consultation.

FAQ: Frequently Asked Questions About the Cyber Resilience Act

  • We are already certified to IEC 62443, UN R155, EN 303 645, or ISO 27001—is that enough for the CRA?

    That’s the most common question—and the answer is a clear “yes and no.” Existing certifications cover certain aspects, but none cover everything: R155 and R156 largely cover the process side, IEC 62443-4-1 and -4-2 cover a large portion of the technical requirements, and EN 303 645 provides the baseline for consumer IoT. ISO 27001, on the other hand, pertains to the organization, not the product, and contributes little to a device’s CRA compliance. The Readiness Check clarifies which gaps remain in a specific case.

  • Does the CRA also apply to products that are not connected to the Internet?

    In many cases, yes. All that’s needed is a data connection to another device or network—even locally via Bluetooth, a fieldbus, or a service interface. So a device without a permanent Internet connection isn’t automatically left out.

  • We purchase software and modules—so aren't the suppliers responsible?

    The manufacturer remains responsible for the product that bears its own name. In practice, this means that every supplier must provide an SBOM, a commitment regarding the support period, and a reporting channel for vulnerabilities. These requirements must be included in the procurement contracts—and they must be in place before the component is selected.

  • Should we wait until the harmonized standards are available?

    No. A harmonized standard shifts the burden of proof, not the work involved in developing the product. The technical requirements—secure update channels, SBOM, fleet overview—must be established in any case and cannot be implemented on short notice.

  • We don't have our own product safety team. Will that still work?

    Yes, in mixed teams. Since the process must subsequently run at the customer’s site, it is designed from the outset so that the customer’s own organization can carry it out independently. MAN Truck & Bus is proof that this approach works: Today, 22 development teams there follow the Secure-SDLC that was developed collaboratively.

  • Does the effort involved in CRA offer any benefits beyond compliance?

    Yes. The CRA requires manufacturers to implement exactly the infrastructure they need for digital services anyway: secure update channels, fleet overview, and remote maintenance capabilities. Once this foundation is properly established, manufacturers not only comply with the regulation but can also remotely maintain and further develop their products and monetize them through additional services.

  • Does MaibornWolff also handle CRA certification?

    No—and that’s by design. MaibornWolff develops the capabilities and prepares the documentation; the assessment is conducted by the customer or a designated body. Whoever delivers the implementation should not be the one to approve it. This separation is standard practice and a sign of trust, not a shortcoming.

  • Who addresses the legal issues surrounding roles, contracts, and liability?

    MaibornWolff develops the technology and prepares the documentation. For legal issues related to CRA and regulatory matters—such as defining the roles of manufacturers, importers, and distributors; drafting contracts with suppliers; or liability within the supply chain—the company collaborates with the law firm Heuking in Hamburg. We facilitate the initial contact, but you engage their services directly.