Business impact

Market access risk

This is the principal risk, and it is not gradual: without CE marking a product cannot be placed on the Union market.

Calculation to produce for the committee:

Line Value
Turnover made in the European Union _____ €m
Share made by products with digital elements _____ %
Turnover exposed _____ €m
Share of that turnover carried by class II or Critical products _____ %
Turnover dependent on a notified body _____ €m

The last line is what should trigger the decision: it is the turnover whose continuity depends on a third party whose lead time you do not control.

Financial exposure

Three components, detailed in Exposure and risk register:

  1. Administrative — up to EUR 15 m or 2.5 % of worldwide turnover.
  2. Commercial — turnover lost during a prohibition or withdrawal, plus recall costs for a hardware product.
  3. Contractual — penalties, terminations and indemnities under your contracts.

To which is added civil liability exposure: Directive (EU) 2024/2853 covers software and takes the absence of security updates into account when assessing defectiveness.

The cost of compliance

Item Nature Horizon
Tooling Investment then subscription Recurring
Headcount PSIRT, compliance, security engineering Recurring
On-call cover Technical and legal rota Recurring
Notified bodies Initial assessment per product and maintenance Per product, per cycle
Certification of critical products Evaluation laboratory, certificate maintenance Per product, long cycle
Maintaining 5–10 year support Preserved build chains, backports, archiving The most underestimated
Training Development, legal, procurement One-off then recurring

The most underestimated item is the second to last: retaining the ability to produce a fix for a version shipped eight years ago requires preserved build environments, available skills and an organisation that spends time on it with no revenue attached.

The opportunities

They are real and rarely highlighted, although they carry part of the funding case.

The SBOM has become a commercial argument. Large accounts and public buyers already ask for it in tenders. Producing one meets an obligation and shortens sales cycles.

Customer security questionnaires can be answered in hours rather than weeks once the evidence exists. Across a meaningful volume of tenders, the saving is measurable.

Acquisition and fundraising diligence now covers the CRA. A clean file avoids a liability warranty or a price holdback.

Technical debt becomes visible and quantifiable. The inventory reveals abandoned components, frozen versions and single-maintainer dependencies. It is the first time that information is available across the whole portfolio.

Response time to a major incident falls from weeks to hours. The value of that gain is measured against the cost of the last public supply chain incident.

The knock-on effect

CRA compliance covers a large share of what is expected elsewhere:

External requirement Covered by CRA work
NIS 2 — supply chain security, incident management Largely
DORA — for your financial-sector customers Partly
Customer security questionnaires Largely
ISO/IEC 27001 — asset and vulnerability control Partly
Licence audits Largely, through the SBOM
Acquisition diligence Largely

Presenting the programme as a shared evidence base rather than a regulatory silo changes how it gets funded.

The message to take away

The CRA turns good practice into a condition of market access. The cost of compliance is real and recurring; the cost of non-compliance is discontinuous and potentially fatal for a product line. The trade-off is not “do it or not”, but at what pace and over what scope.