PortaRegulus
HOME
06 // INTEL · ANALYSIS

What CRA compliance costs an SME.

A time and cost breakdown for a small manufacturer, done by hand and done with tooling.

PortaRegulus Intel CRA · Cost of Compliance 02 Jul 2026

Ask what Cyber Resilience Act compliance will cost a small manufacturer and you get two kinds of answers. Consultants quote a project. Vendors quote a subscription. Neither tells you where the hours actually go. Here is the breakdown we use, in person-days, for a typical SME with a handful of connected products, and what changes when the documentation work is automated.

Update, 12 July 2026. A broader companion analysis pricing the complete 48-item documentation request sheet a consultancy could ask for, including engineering evidence, is published as The 48 documents a CRA audit asks for. Its totals are higher than the figures below because its scope is wider. Where the two differ, the new article supersedes.

The clock matters more than it did a year ago. The CRA's reporting obligations for actively exploited vulnerabilities and severe incidents start on 11 September 2026, ten weeks from the date of this article. The full set of essential requirements applies from 11 December 2027. A product that ships in 2028 needs its technical file, risk assessment and vulnerability handling process finished before then, and the Commission's own impact assessment put industry-wide compliance costs around 29 billion euro. Someone pays that in hours.

What the regulation actually makes you produce

Strip away the recitals and the CRA asks a manufacturer for five deliverables. A cybersecurity risk assessment per product that follows the essential requirements in Annex I Part I. A vulnerability handling process per Annex I Part II, which in practice means an SBOM, a coordinated disclosure policy, a way to ship security updates and someone watching for new vulnerabilities. Technical documentation per Annex VII that holds it all together. A conformity assessment, self-declared for most products in the default category. And an ongoing obligation to report and to keep the whole file current for the support period.

The trap for small teams is that four of those five are documentation exercises that reference each other. The risk assessment cites the asset inventory. The treatment plan cites the risk register. The technical file cites everything. Change one input, say a new radio module or a dropped cloud dependency, and the cross-references go stale. That is why compliance effort does not end at the first declaration.

The manual bill

These figures assume a default-category product, self-assessed under Module A, a team that knows its own product well but is reading the CRA for the first time, and no notified body involvement. They are estimates from doing this work, and your product can move every line.

Work package, first productPerson-days
Scoping, classification, reading the obligations that apply2 – 4
Product context, intended purpose, asset inventory2 – 3
Threat model and risk assessment against Annex I Part I4 – 8
Risk treatment plan, residual risk, acceptance criteria2 – 4
Vulnerability handling setup, SBOM, CVD policy, update path10 – 20
Technical documentation assembly per Annex VII4 – 6
Total, first product25 – 45

At a loaded internal rate of 400 to 600 euro per engineering day, the first product lands between 10,000 and 27,000 euro of internal effort. Run the same scope through an external consultant at 900 to 1,400 euro per day and the invoice reads 30,000 to 60,000 euro. Additional products reuse the process work, so a second and third product typically cost 10 to 20 days each. After that comes maintenance. Keeping the register, the SBOM and the reporting readiness alive is realistically 0.1 to 0.3 of a full-time role across a small portfolio.

Where the hours actually go

Look at the table again and notice what the big lines have in common. The threat model, the risk register and the technical file are structured writing about engineering you have already done. The product knowledge is in the room, in datasheets and in the heads of two or three people. The person-days go into converting that knowledge into clause-shaped documents, keeping fourteen artifacts consistent with each other, and re-converting every time the product moves. This is exactly the kind of work that automates well, because the input already exists and the output format is fixed by the regulation.

The tooled bill, measured

We ran two realistic products through the PortaRegulus CRA workspace this month and measured it. One WiFi and Bluetooth thermo-hygrometer, one 11 kW home EV charger. The input in each case was a product description of roughly one page, the kind every manufacturer already has, plus answers to one or two clarifying questions the intake raised.

From that input the workspace produced the clause 6 risk-management spine end to end. Eleven generated documents covering product context, risk criteria, assessment methodology, treatment and review, about six thousand words per product. An asset register of roughly twenty entries. A threat model of fourteen to sixteen threats drawn from the CRA baseline catalog and matched to the assets. A scored risk register with treatments attached. Machine time was under five minutes per product.

The human share of that workflow is review, and review is where the quality comes from. Reading and correcting the generated set, confirming the asset list, adjusting likelihood and impact where the defaults are wrong for your context takes three to six hours per product. The same spine written by hand is the three lines in the middle of the table, eight to fifteen days. On the risk documentation workflow the reduction is roughly 85 percent.

Three-product SME, initial complianceBy handWith tooling
Risk documentation, all products20 – 35 days2 – 3 days
Vulnerability handling setup, org level10 – 20 days8 – 15 days
Technical file assembly8 – 14 days3 – 5 days
Total38 – 69 days13 – 23 days

Estimates for a default-category, self-assessed portfolio. The tooled column still contains real engineering work that no software should claim to remove.

What tooling does not buy you

This part belongs in any cost article. The tool writes and maintains documentation. It does not generate your SBOM from your build system, it does not build your update infrastructure, and it does not fix the hardcoded credential your threat model just surfaced. Those hours stay in the budget in both columns. Across the full CRA scope, including the engineering evidence, a realistic overall saving is 40 to 50 percent of the initial effort. The 85 percent figure applies to the documentation spine specifically.

The second saving is quieter and shows up later. Because the register, the threat model and the documents live in one workspace, a product change means regenerating the affected artifacts and re-reviewing them in an afternoon. Manual re-editing is what makes most technical files rot between audits. For the ongoing 0.1 to 0.3 FTE maintenance load, expect the tooled number to sit at the bottom of that range.

The short version

By hand, a first product costs an SME 25 to 45 person-days, 10,000 to 27,000 euro internally or up to 60,000 euro consultant-led, and every later change taxes you again. With the documentation workflow automated, the risk-management spine drops from days to hours per product, total initial effort drops by roughly half, and the file stays maintainable. The engineering work stays either way. With reporting obligations live from September 2026, the cheapest option left is starting early, whichever column you choose.

Want the numbers for your products?