There is no CRA licence, no registration charge and no annual levy. Search for the price of Cyber Resilience Act compliance and what comes back is consultancy day rates, which tell you what firms charge rather than what the Regulation requires. The Regulation itself is more useful on the question, because it says exactly who has to involve somebody else — and for most products the answer is nobody.
The default is that you assess your own product
Article 32(1) gives the manufacturer four ways to demonstrate conformity with the essential cybersecurity requirements in Annex I. The first is the internal control procedure, based on module A, set out in Annex VIII Part I. Annex VIII describes it plainly: internal control is the procedure whereby the manufacturer “ensures and declares on its sole responsibility” that the product satisfies the requirements. No notified body examines it. No certificate is issued. No fee is charged, because there is nobody to charge one.
Under module A the manufacturer does four things:
- Draws up the technical documentation described in Annex VII.
- Takes the measures necessary so that design, development, production and vulnerability handling — and the monitoring of those processes — actually deliver compliance with Parts I and II of Annex I.
- Affixes the CE marking to each individual product that satisfies the requirements.
- Draws up a written EU declaration of conformity for each product and keeps it with the technical documentation at the disposal of national authorities for ten years after the product is placed on the market, or for the support period, whichever is longer.
That last retention period is the one that surprises people. Ten years is a long time to be able to produce a document about a product you stopped selling in year two, and it is a filing problem rather than an engineering one.
Which products lose the self-assessment route
This turns on what the product is, not on how big the company is. A four-person startup shipping a password manager is in scope for third-party involvement; a large firm shipping a connected kettle is not.
- Annex III class I — identity and access management, browsers, password managers, anti-malware, VPNs, network management systems, SIEM, boot managers, PKI and certificate issuance, network interfaces, operating systems, routers, modems and switches, security-related microprocessors and microcontrollers, security-related ASICs and FPGAs, smart home voice assistants, smart home security products including door locks, cameras, baby monitors and alarms, internet-connected toys with social interactive or location-tracking features, and personal wearables with a health monitoring purpose or intended for children. For these, Article 32(2) only forces you into EU-type examination or full quality assurance if you have not applied harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least ‘substantial’ — or if they do not yet exist. Apply the standards in full and module A remains available to you.
- Annex III class II — hypervisors and container runtimes, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and microcontrollers. Article 32(3) removes the self-assessment option outright.
- Annex IV, critical products — hardware devices with security boxes, smart meter gateways and other devices for advanced security purposes, smartcards and similar. Article 32(4) routes these through a European cybersecurity certification scheme, or failing that the class II procedures.
The Annex III class I condition is the one worth planning around, because it is the only place in the cost question where a decision you make in engineering changes what you pay in assessment. Standards conformance is not free either — but the first standardisation deliverables are scheduled for Q3 2026 on the Commission’s own implementation timeline, so for a class I product this is a live design decision now rather than a 2027 one.
Getting the route wrong is itself fineable
Article 64(3) puts non-compliance with Article 32(1), (2) and (3) in the €10,000,000 or 2% of total worldwide annual turnover tier, whichever is higher. Self-assessing a product that Annex III class II covers is not a cheaper path with a smaller risk attached; it is an infringement of the conformity assessment article.
And the carve-out small manufacturers do get does not reach it. Article 64(10)(a) disapplies fines for micro and small enterprises only in respect of the two 24-hour early-warning deadlines — what that exemption covers and what it leaves alone is worth reading before relying on it. Nothing in Article 64(10) touches Article 32.
The reliefs that are written into the law for you
The CRA is unusually explicit about smaller manufacturers. Four provisions are worth knowing by name.
- Article 32(6) — where fees are set for conformity assessment procedures, the specific interests and needs of microenterprises, small and medium-sized enterprises and start-ups “shall be taken into account” and the fees “shall be reduced proportionately” to them. This is drafted as an obligation, not an encouragement.
- Article 47(2) — notified bodies must carry out assessments proportionately, avoiding unnecessary burdens, taking due account of the size of the undertaking, its sector, structure and complexity, the cybersecurity risk level of the product, and whether production is mass or serial. Article 47(3) then holds the line: proportionality does not lower the degree of rigour required.
- Article 33(5) — micro and small enterprises may provide every element of the Annex VII technical documentation in a simplified format, using a form the Commission is to specify by implementing act, and notified bodies must accept it.
- Article 33(1) to (4) — Member States are to run awareness and training activities, open a dedicated communication channel for micro and small enterprises, and support testing and conformity assessment activities; they may establish cyber resilience regulatory sandboxes with access facilitated for smaller firms; and the Commission is to publish SME guidance and advertise available financial support under existing Union programmes.
The simplified form does not exist yet
Article 33(5) is the relief most directly aimed at documentation cost, and as of 30 July 2026 the implementing act specifying the form has not been adopted. It does not appear on the Commission’s CRA implementation timeline, which was last updated on 27 July 2026 and which lists first standardisation deliverables in Q3 2026, the reporting start on 11 September 2026, a delegated act on EUCC presumption of conformity in Q4 2026, notification of sufficient conformity assessment bodies across Member States by 11 December 2026, further standardisation deliverables on 30 October 2027, and full application on 11 December 2027.
Two things follow. Plan against the full Annex VII content, because that is the only specification that currently exists. And note that Article 33(5) is itself in the Article 64(3) fine tier: if you opt to provide the information in a simplified manner, you must use the specified form — which is a duty that only becomes capable of being breached once the form is published.
What Annex VII actually asks for
This is where a small manufacturer’s real cost sits, so it is worth being concrete. Annex VII requires, at least: a general description of the product including intended purpose, the software versions affecting compliance, photographs or illustrations showing external features, marking and internal layout for hardware, and the Annex II user information; a description of design, development and production including system architecture; the vulnerability handling processes, and here the Regulation names them individually — the software bill of materials, the coordinated vulnerability disclosure policy, evidence of a contact address for reporting vulnerabilities, and a description of the technical solutions chosen for secure distribution of updates; the cybersecurity risk assessment under Article 13; the information used to determine the support period; and the list of harmonised standards applied, with descriptions of what was done instead where they were not.
Article 31(2) adds the part that turns this from a project into a practice: the technical documentation must be drawn up before the product is placed on the market and continuously updated, where appropriate, at least during the support period. The SBOM inside it is subject to the same discipline — which is why the SBOM is worth building in 2026 even though the duty runs from 2027.
The Commission published guidance on 27 July 2026
On 27 July 2026 the Commission published C(2026) 5252, a communication on CRA guidance with the guidance itself as an annex. It addresses when products fall within scope — including remote data processing solutions and free and open-source software — what constitutes a substantial modification, how support periods should be understood and applied, and how to meet reporting and risk assessment requirements. The Commission describes particular attention paid to microenterprises and SMEs, with 67 practical examples, use cases, flowcharts and graphs.
It is non-binding, and the Commission says so directly. It does not change an obligation or a date. What it changes is the cost of working out which obligations are yours, which for a small team without a product-security function has been the expensive part. If you priced CRA readiness before last week, the scoping half of that estimate is now built on better information.
So what does it cost
For a manufacturer outside Annex III and Annex IV, the honest answer is that the CRA costs no assessment fee at all, and instead costs the production and maintenance of a technical file, a risk assessment, an SBOM, a disclosure policy, an update channel, and a reporting capability that works on a 24-hour clock. That work is front-loaded and then recurring for the life of the support period. For an Annex III or IV product it costs those things plus a notified body, at a fee the Regulation requires to be reduced proportionately if you are an SME.
The date that decides your urgency is not December 2027. It is 11 September 2026, when the reporting obligations start — and they reach products already in the field, not just what you launch next.
PartsProof builds that file and those runbooks at a flat fee rather than a day rate: $349 for the Readiness Pack, $649 for Readiness Plus with SBOM and runbooks, $899 with a retainer. See what the pack contains or get in touch.
Every figure and date above was verified on 30 July 2026 against the text of Regulation (EU) 2024/2847 as published in the Official Journal, and against the European Commission’s Cyber Resilience Act policy pages and implementation timeline for the guidance publication and the implementation dates. Nothing here is legal advice, and the question of which annex your product falls under is one to settle against the Regulation’s own text.