Ask what Cyber Resilience Act compliance will cost a small manufacturer and you get two kinds of answers. Consultants quote a project. Vendors quote a subscription. Neither tells you where the hours actually go. Here is the breakdown we use, in person-days, for a typical SME with a handful of connected products, and what changes when the documentation work is automated.
Update, 12 July 2026. A broader companion analysis pricing the complete 48-item documentation request sheet a consultancy could ask for, including engineering evidence, is published as The 48 documents a CRA audit asks for. Its totals are higher than the figures below because its scope is wider. Where the two differ, the new article supersedes.
The clock matters more than it did a year ago. The CRA's reporting obligations for actively exploited vulnerabilities and severe incidents start on 11 September 2026, ten weeks from the date of this article. The full set of essential requirements applies from 11 December 2027. A product that ships in 2028 needs its technical file, risk assessment and vulnerability handling process finished before then, and the Commission's own impact assessment put industry-wide compliance costs around 29 billion euro. Someone pays that in hours.
What the regulation actually makes you produce
Strip away the recitals and the CRA asks a manufacturer for five deliverables. A cybersecurity risk assessment per product that follows the essential requirements in Annex I Part I. A vulnerability handling process per Annex I Part II, which in practice means an SBOM, a coordinated disclosure policy, a way to ship security updates and someone watching for new vulnerabilities. Technical documentation per Annex VII that holds it all together. A conformity assessment, self-declared for most products in the default category. And an ongoing obligation to report and to keep the whole file current for the support period.
The trap for small teams is that four of those five are documentation exercises that reference each other. The risk assessment cites the asset inventory. The treatment plan cites the risk register. The technical file cites everything. Change one input, say a new radio module or a dropped cloud dependency, and the cross-references go stale. That is why compliance effort does not end at the first declaration.
The manual bill
These figures assume a default-category product, self-assessed under Module A, a team that knows its own product well but is reading the CRA for the first time, and no notified body involvement. They are estimates from doing this work, and your product can move every line.
| Work package, first product | Person-days |
|---|---|
| Scoping, classification, reading the obligations that apply | 2 – 4 |
| Product context, intended purpose, asset inventory | 2 – 3 |
| Threat model and risk assessment against Annex I Part I | 4 – 8 |
| Risk treatment plan, residual risk, acceptance criteria | 2 – 4 |
| Vulnerability handling setup, SBOM, CVD policy, update path | 10 – 20 |
| Technical documentation assembly per Annex VII | 4 – 6 |
| Total, first product | 25 – 45 |
At a loaded internal rate of 400 to 600 euro per engineering day, the first product lands between 10,000 and 27,000 euro of internal effort. Run the same scope through an external consultant at 900 to 1,400 euro per day and the invoice reads 30,000 to 60,000 euro. Additional products reuse the process work, so a second and third product typically cost 10 to 20 days each. After that comes maintenance. Keeping the register, the SBOM and the reporting readiness alive is realistically 0.1 to 0.3 of a full-time role across a small portfolio.
Where the hours actually go
Look at the table again and notice what the big lines have in common. The threat model, the risk register and the technical file are structured writing about engineering you have already done. The product knowledge is in the room, in datasheets and in the heads of two or three people. The person-days go into converting that knowledge into clause-shaped documents, keeping fourteen artifacts consistent with each other, and re-converting every time the product moves. This is exactly the kind of work that automates well, because the input already exists and the output format is fixed by the regulation.
The tooled bill, measured
We ran two realistic products through the PortaRegulus CRA workspace this month and measured it. One WiFi and Bluetooth thermo-hygrometer, one 11 kW home EV charger. The input in each case was a product description of roughly one page, the kind every manufacturer already has, plus answers to one or two clarifying questions the intake raised.
From that input the workspace produced the clause 6 risk-management spine end to end. Eleven generated documents covering product context, risk criteria, assessment methodology, treatment and review, about six thousand words per product. An asset register of roughly twenty entries. A threat model of fourteen to sixteen threats drawn from the CRA baseline catalog and matched to the assets. A scored risk register with treatments attached. Machine time was under five minutes per product.
The human share of that workflow is review, and review is where the quality comes from. Reading and correcting the generated set, confirming the asset list, adjusting likelihood and impact where the defaults are wrong for your context takes three to six hours per product. The same spine written by hand is the three lines in the middle of the table, eight to fifteen days. On the risk documentation workflow the reduction is roughly 85 percent.
| Three-product SME, initial compliance | By hand | With tooling |
|---|---|---|
| Risk documentation, all products | 20 – 35 days | 2 – 3 days |
| Vulnerability handling setup, org level | 10 – 20 days | 8 – 15 days |
| Technical file assembly | 8 – 14 days | 3 – 5 days |
| Total | 38 – 69 days | 13 – 23 days |
Estimates for a default-category, self-assessed portfolio. The tooled column still contains real engineering work that no software should claim to remove.
What tooling does not buy you
This part belongs in any cost article. The tool writes and maintains documentation. It does not generate your SBOM from your build system, it does not build your update infrastructure, and it does not fix the hardcoded credential your threat model just surfaced. Those hours stay in the budget in both columns. Across the full CRA scope, including the engineering evidence, a realistic overall saving is 40 to 50 percent of the initial effort. The 85 percent figure applies to the documentation spine specifically.
The second saving is quieter and shows up later. Because the register, the threat model and the documents live in one workspace, a product change means regenerating the affected artifacts and re-reviewing them in an afternoon. Manual re-editing is what makes most technical files rot between audits. For the ongoing 0.1 to 0.3 FTE maintenance load, expect the tooled number to sit at the bottom of that range.
The short version
By hand, a first product costs an SME 25 to 45 person-days, 10,000 to 27,000 euro internally or up to 60,000 euro consultant-led, and every later change taxes you again. With the documentation workflow automated, the risk-management spine drops from days to hours per product, total initial effort drops by roughly half, and the file stays maintainable. The engineering work stays either way. With reporting obligations live from September 2026, the cheapest option left is starting early, whichever column you choose.