Approved product under the CRA – Ted Strandberg on how companies can start preparing now

The EU Cyber Resilience Act (CRA) sets out extensive cybersecurity requirements for products with digital elements. But what happens when a product is assessed against those requirements, and what role do standards play in the process?

We spoke with Ted Strandberg, growth area leader for cybersecurity certification at RISE. He is responsible for developing RISE’s testing and certification offerings against the coming regulations and standards, and is also national chair of SIS/TK 318/AG 61 – Cybersecurity in products. RISE is already a notified body for the cybersecurity provisions of the Radio Equipment Directive (RED), and is currently exploring the notified body role under the CRA as well.

Ted Strandberg, growth area leader for cybersecurity certification at RISE

Here’s what you need to know:

  • The CRA applies in full from 11 December 2027. Many of the technical standards are still under development.
  • Four product categories determine the level of scrutiny. From self-declaration to mandatory EU certification.
  • Complex products with long development cycles may struggle to meet the requirements in time, given the short window between the publication of the standards and the point at which the regulation takes effect.
  • The CRA introduces cybersecurity into CE marking, with requirements on both the product and the processes – for example risk analysis, vulnerability handling and updates.
  • Start with training and early planning. The work needs to run in parallel with product development, not be done afterwards.

What a notified body does – and where RISE stands in the CRA work

A notified body is an independent party with the right to assess whether products meet the requirements of EU harmonisation legislation. It is Swedac, Sweden’s national accreditation body, that approves and supervises the organisations wishing to become notified bodies within a given regulation. RISE holds that role in many areas.

When a new regulation or directive is introduced, an organisation can apply to become a notified body to certify against it. Once an application is submitted, Swedac visits the applicant and reviews how they plan to assess whether products meet the requirements or not. Since the legal text usually does not spell out technical requirements in detail, standards are used to fill that gap. The simplest approach is to wait until suitable standards are in place and use those.

– We are currently at a stage where these standards are approaching publication, and it makes sense to start developing testing methods linked to them. We are now identifying which product types and standards to test against, and which we will seek notified body status for, says Ted Strandberg.

Accredited testing body vs notified body

Being an accredited testing body and being a notified body are two different roles that often go hand in hand. RISE can be accredited to test a product against a specific standard, and on that basis issue accredited test reports.

Being a notified body is a broader assignment. It means having the right to issue an official certificate confirming that a product meets the requirements of an entire regulation, such as the RED or the CRA. Such a certificate is required for products in the higher categories, for example Class II and critical products under the CRA, and can then be used when the manufacturer CE marks the product. Both approvals are applied for from Swedac, but separately.

– It’s a bit tricky, says Ted.

Ted’s own work has a product focus. He is building RISE’s testing and certification offerings within cybersecurity, and has been part of CEN/CENELEC JTC 13 working group 8, which developed the standard for the cybersecurity requirements linked to the Radio Equipment Directive.

Right now, the focus is on working group 9, where RISE and other stakeholders are developing the standards linked to the CRA. The harmonised standards are still under development, which means accreditation cannot be granted until they are published.

In parallel, RISE is already preparing on the accreditation side. Once the new standards are ready, RISE aims to hold accreditation to test against them, and priorities are set by what Swedish industry will need most.

How an assessment actually works

When a product comes in for assessment, RISE takes as its starting point the standard the manufacturer has chosen to refer to. The process follows the methodological requirements set by Swedac, and is the same regardless of client or product.

Assessment happens step by step and in dialogue:

  1. The manufacturer submits technical documentation to RISE.
  2. RISE goes through the current standard requirement by requirement.
  3. The manufacturer receives feedback on what meets the requirements and what needs to be supplemented.
  4. The iteration continues until all requirements are met.
  5. An accredited test report is issued.

The category the product falls into determines the level of scrutiny required.

Four product categories under the CRA

The CRA divides products with digital elements into four categories based on cybersecurity risk. The category determines the level of scrutiny required.

CategoryExamplesAssessmentWhat it means*
Default category (~90%)Mobile apps, smart speakers, computer games, photo editing software, word processorsSelf-declarationThe manufacturer is responsible for their own documentation. Authorities can carry out checks afterwards.
Class IWeb browsers, password managers, antivirus, VPN, routers, smart home assistantsSelf-declaration if a harmonised standard is followed, otherwise notified bodyThe manufacturer can choose: follow a harmonised standard and self-declare, or have a notified body carry out the assessment.
Class IIHypervisors, firewalls, telecom network functionsNotified body mandatoryThe manufacturer cannot self-declare conformity. The notified body makes the final assessment.
Critical productsSmart electricity meters, smart cards (e.g. bank cards), specialised hardware for cryptographyNotified body mandatory, possibly EU certificationThe highest level of scrutiny. A notified body is always required, and for certain product types EU cybersecurity certification is also mandatory.

Source: CRA Annexes III and IV 
*Explains what the assessment requirement means in practice. 

See also: CRA standards play different roles – Angelo D’Amato explains which one will be decisive

The role of standards in an assessment

It is when a harmonised standard is in place that the work of a notified body becomes clearest.

– The Commission decides which standard provides presumption of conformity. Once we know which standard is to be applied, our work becomes considerably easier, says Ted.

The standard provides a common point of reference. It defines what is to be assessed and how. That creates predictability – both for the manufacturer, who knows what must be met, and for the notified body, which knows what must be examined.

But that does not mean the standard alone determines the outcome. Standards and notified bodies complement each other: the standard sets the framework, the notified body makes the actual assessment. For products in Class I, a self-declaration is sufficient if there is a designated harmonised standard that provides presumption of conformity. If no such standard exists, a notified body must carry out the assessment. For Class II, a notified body is always required. For Class II a notified body must always carry out the assessment. There too, the standard is central, it governs what the body assesses against.

This is how standards carry legal weight: by following them, the product gains presumption of conformity, meaning it is considered to meet the requirements of the law. Without that link between legal text, standard and assessment, each company would have had to interpret the requirements on its own, and each notified body would have had to develop its own methodology.

When the standards are not yet in place

The CRA is being introduced in stages, and from 11 December 2027 the requirements will apply in full. Many of the standards that will provide presumption of conformity are still under development (at the time of publication, August 2026). That creates a particular situation for companies that need to prepare for requirements that are not yet fully defined.

– For complex products with development cycles spanning several years, it means manufacturers have very little time between the publication of the technical requirements and the point at which the requirements must be met, says Ted.

RISE and other accredited bodies can help to bridge that gap. Companies can refer to existing standards that are being used as the basis for the ongoing standardisation work. RISE also offers gap analyses, where products already tested against earlier standards are assessed against what is expected in the new ones.

– We follow the entire standardisation process and have a good sense of where things are heading. That means we can help companies start working towards the existing standards that are likely to be closest to the final requirements, says Ted.

The big shift: from product requirements to process requirements

One of the most important shifts with the CRA compared with RED is that the requirements no longer only concern the product itself. They concern, just as much, the processes around the product, how the manufacturer works. Before launch, with risk analysis and vulnerability handling, and after launch, with updates when new vulnerabilities are discovered.

– It’s the way of working that is assessed, says Ted.

This means that manufacturers need routines for the entire product lifecycle, not only up to launch. Vulnerability handling, incident reporting and planned security updates must be in place and documented.

Risk assessment is one area where Ted sees that the methodology is still immature for the cybersecurity field.

– Within technical safety there is a long tradition of risk analysis, but mainly for what is known as safety, meaning protection against accidents and physical harm. Cybersecurity is a different field where threats come from active attackers. That makes risk assessment harder, says Ted.

What smaller companies miss

For small and medium-sized enterprises, the CRA is a particular challenge, not only because of the extent of the requirements, but also because the understanding of what is required is often lacking entirely.

– Some companies that contact us haven’t even been aware that the regulation applies to them. Others assume they can simply submit the product in the same way as for ordinary testing. But that’s not how it works – it’s the company developing the product that has to do the underlying work on risk analysis, documentation and processes, says Ted.

For SMEs facing their first CRA assessment, Ted’s advice is to start with competence.

– Send people on training and set up a plan for the CRA work early on. It’s substantial work that needs to run in parallel with product development, not be done afterwards. Contact a third party early in the process – we deal with this every day, says Ted.

What companies should do now

Ted’s most important advice is not to wait.

– If you haven’t done anything beforehand, there’ll be a great deal to do in a short time. Train your staff, get in touch with a third party and start testing against existing standards now, says Ted.

RISE also offers training linked to the standards it tests against and has specific packages for companies wanting to get started.

See also: Inside ETSI TC CYBER – Kim Nordström on turning CRA law into finished standards

Newsfeed from ETSI

    Feed has no items.
Membership

Be part of shaping the communication of the future

Become a member of our network that brings together Swedish industry experts in IT and telecommunications to influence the development of standards.

Become a member