CRA Readiness at Scale: De-Risking 70+ Products Under the EU Cyber Resilience Act
Situation
A global manufacturer of healthcare education products develops medical training manikins, simulation software, and connected devices used by hospitals, universities, and first responders around the world. As more of its portfolio incorporated network-connected components, embedded software, and data-handling functionality, the organization needed a clear view of its obligations under the EU Cyber Resilience Act (CRA).
The portfolio covered more than 70 products developed across multiple product lines. Each had its own architecture, connectivity profile, documentation maturity, and product-team ownership. No consolidated view existed to show CRA applicability, risk classification, or the appropriate conformity pathway for every product.
The organization engaged Nemko Digital to classify the connected portfolio, assess the current state of compliance readiness, and establish a practical path to conformity. The work had to reduce uncertainty and compliance risk without slowing the organization’s broader mission to expand access to life-saving training and simulation technology.
Challenges
The organization had no unified inventory linking each of its 70+ products to a CRA risk category, applicable obligations, and conformity pathway.
Several products had initially been assumed to fall under the higher-scrutiny Class I — Important category. Without rigorous functional analysis, that assumption could create unnecessary conformity-assessment effort, cost, and time-to-market pressure.
Component suppliers, embedded software providers, and contract manufacturers could introduce CRA-relevant risks that had not previously been assessed through one consistent portfolio-wide method.
Security processes, product documentation, and governance structures had developed organically over time. They were not organized in a way that could be mapped readily to CRA requirements or used to demonstrate readiness.
The CRA introduces triggers that can reset or alter conformity obligations. Without clear internal criteria for what constitutes a substantial modification, product teams risked making inconsistent decisions as products evolved.
Our Approach & Solution
Nemko Digital structured the engagement in two phases: rapid portfolio-wide classification followed by a targeted gap analysis. Working with product, compliance, and technical development teams, Nemko Digital reviewed more than 70 products against CRA classification criteria within the first month.
Each product was evaluated according to its actual functional scope, connectivity, data handling, and intended use rather than category assumptions. This function-first analysis showed that several products initially treated as Class I — Important could be justifiably classified as Default, reducing unnecessary conformity-assessment burden while preserving a documented rationale for every decision.
Nemko Digital then assessed each classified product through three consistent lenses: process and policy, governance, and technical or product documentation. The resulting roadmap focused remediation on five core CRA compliance pillars: vulnerability handling, incident reporting, cyber risk assessment, supply-chain risk management, and substantial-modification determination.
The project then established a governance model that separated corporate oversight, central technical delivery, and local customer-facing responsibilities. A proportionate request journey was designed around authentication, validation, data preparation, delivery, and record-keeping, with historical and real-time access supported where appropriate.
Finally, Nemko Digital reviewed contractual arrangements and consolidated the resulting controls into a formal compliance documentation package. This package captured key decisions, the data-in-scope inventory, policies and procedures, model contract clauses, implementation responsibilities, short-term actions, and handover considerations.
Key Metrics
Within two months from project kick-off to final delivery, Nemko Digital gave the organization a documented view of CRA applicability across its connected portfolio and a practical basis for prioritizing conformity work.
The engagement combined portfolio-scale coverage with consistent product-level analysis, allowing the organization to focus resources on the obligations and gaps that mattered most.
Connected products classified under the EU Cyber Resilience Act
From project kick-off to final portfolio classification and gap-analysis delivery
Assessment lenses applied to each product: process and policy, governance, and technical documentation
Core compliance pillars covered by the readiness roadmap
Value Delivered
Reduced compliance cost and complexity: Function-first analysis allowed several products to move from an assumed Class I — Important classification to a justified Default classification, reducing avoidable conformity-assessment burden.
A clear, defensible pathway to conformity: Every assessed product received a documented, evidence-based classification and corresponding gap analysis, giving the organization a prioritized view of the work required for CRA readiness.
Targeted, risk-based remediation: By assessing gaps across process, governance, and technical documentation, the organization can direct resources to the highest-priority needs rather than applying uniform changes across the entire portfolio.
A reusable framework with stronger internal alignment: The classification method, substantial-modification criteria, and gap-analysis structure can be applied to future products and embedded into product development, helping teams understand the regulatory consequences of design and connectivity decisions earlier.
Download the Full Case Study
Get the complete case study as a PDF for offline reading, sharing with your team, and reference. It includes the portfolio-classification method, three-lens gap analysis, core compliance pillars, key outcomes, and the path to ongoing CRA readiness.

