For most manufacturers, the realisation that the Cyber Resilience Act applies to their products brings the same first instinct. Hire consultants, and plenty of them.

With the compliance deadline approaching and consultant day rates that run past €1,200, the whole exercise starts to look like an open-ended bill before any real work has begun. Hiring in that expertise is the obvious move, and the most expensive one. Yet the strongest and lowest cost route to CRA compliance runs through the people you already employ.

Your engineers understand your products better than any outside expert ever will, and with the right knowledge and platform behind them, they are well placed to lead on CRA compliance from the inside.

We dive into how to build CRA capability inside your own team, where a consultant is still worth bringing in, and why the legal risk of CRA compliance is one you cannot hand to anyone else.

 

We spoke with Conor McGovernan, CPO and Co-Founder of Cyber Cert Labs, as a subject expert on the CRA. Conor co-founded the Dublin-based company in 2022 alongside CEO Patricia Shields, after a career in cybersecurity across financial services, telecoms, logistics and digital services.

There he set out to take the pain out of the CRA, building two platforms, Attestra Academy to train product teams to own compliance internally and Attestra AI to guide manufacturers through the full CRA journey, from vulnerability reporting to a CE mark.

The default CRA plan comes with a day rate attached

When the CRA lands on a manufacturer’s desk, hiring consultants can feel like the only way to hit the deadline with any confidence, and on the surface that looks like the safe choice.

Bring in an outside expert and they start by learning your business and products, then how the CRA applies to each one, before handing over their recommendations. When the budget runs dry or the engagement ends, everything they worked out leaves with them, and you are back where you started the next time a product ships or a regulator asks a question.

The CRA makes that loss worse, because compliance is not a one-off project with a finish line. As ongoing legislation, the CRA governs how you secure your products for as long as they stay on the market, so paying a day rate for work that never stops becomes a bill without an end, and a business that leans on outside help stays dependent on that help for the life of every product.

For Conor, avoiding that trap was the deliberate design choice behind Attestra Academy.

“We didn’t want it to be a consultancy led, expensive process for manufacturers that relies on external skills and expertise that are not in house. We wanted to empower manufacturers.”

Attestra Academy solves this problem by upskilling the workforce you already have as you become CRA compliant, so the product and CRA knowledge builds inside the business and grows with the regulation rather than leaving with an invoice attached.

Why you cannot outsource your way to CRA compliance

Plenty of manufacturers have approached the CRA the way they would approach any new requirement, asking for the checklist and the consultant who can take it off their plate.

The instinct is understandable, but the CRA does not reward it. This is a requirement you cannot simply hand out and forget. As Conor puts it, “The CRA is not a checklist. It’s not something you can outsource.” It needs to become a living, breathing part of your product manufacturing life cycle.

Three things make that true, and each one reinforces why responsibility has to stay within your own team.

1. You sign the declaration, so you carry the risk

Before you can affix the CE mark to a product, you as the manufacturer sign a declaration of conformity. That is a legal attestation, bound by European health and safety law, stating that your product meets the requirements of the CRA.

If a market surveillance authority later asks you to defend that declaration, you want to be standing on ground you understand. A document prepared entirely by an outside consultant is a weak place to stand, because the detail behind it never lived inside your business. Your name is on the attestation, so the risk is yours to carry.

As Conor explains, “You’re going to put the CE mark on your product, and you’re going to sign a declaration of conformity which means you really need to be sure you are on solid ground internally.”

2. The decisions are continuous and specific to your product

Security by design and by default runs through the whole product lifecycle, from design and manufacturing through to testing and post-market monitoring. These are not one-time tasks. They are continuous activities, and the calls they require can only be made well by someone who understands the product in front of them.

That is where the limits of an external expert become clear. “I can’t tell you what to do because I don’t make your product,” Conor says.

An outside expert can help you surface the risks and weigh the options. The decisions themselves belong with the people who designed the product, because they are the ones who know what it does, who uses it, and how it connects to everything around it. As Conor puts it, these are “continuous activities that happen all the time”, which is why “the knowledge needs to live inside the company.”

3. Your engineers already know the hardest part

The cybersecurity knowledge can be taught. The deep product knowledge behind CRA compliance is far harder to come by, and your engineers already hold it. Years of building the product have given them an understanding of what is inside it, how it behaves and how every part connects, and that understanding cannot be bought in.

That is why, in Conor’s view, “companies that manufacture products, they know their products best.” Nobody knows their product like they do: they know “exactly what’s in it, how it works, what’s connected to what.” That puts them in the best position to take the lead on the CRA.

This is also why a new CISO style hire will not solve the problem on its own. A Chief Information Security Officer operates technology. Your engineers create it, and the CRA is concerned with how the product itself is built.

Conor draws a clear distinction: “you’re not operating the technology, you’re creating it.” For manufacturers, that means CRA compliance needs to sit close to the people who understand the product, rather than being treated as something that can be handed over to a new security function or an external consultant.

You are probably less ready than you think

Most manufacturers believe the security work they have already done puts them further along the CRA path than it really does. When Cyber Cert Labs scanned the market, it found the opposite, and two things explain the gap.

Existing security trends tend to protect companies rather than products

Firewalls, staff logins and office systems guard the business, while the risks the end user faces once the product is in their hands often sit untouched. As Conor puts it, manufacturers have often “thought about cybersecurity to protect themselves as a company, but not often what protections they need to put into their products for the users, their customers.”

Product security that exists is usually informal

Where product security exists, if any, it is usually informal and poorly documented, which makes it very hard to prove when a regulator asks. In Conor’s experience, “most manufacturers have some level of cybersecurity in their manufacturing process”, but it is “not very formal and it’s not rigorously documented”, making it hard to evidence.

This is why measuring the gap comes first. The size of that gap is not fixed. It depends on how much security you build in today and how complex the product is, and that in turn shapes your budget and the scale of the change ahead. Measuring it early tells you whether you are facing a large job or a small one before you commit real resources to it.

The complexity of the product is a particularly important factor. As Conor explains, “highly complex products tend to cost more to do the CRA than more simple products.” Understanding that complexity early gives you a much clearer sense of the work and budget involved.

Take a free assessment to understand where you stand

A Scope Assessment tells you whether the CRA applies to a given product and, if it does, which obligations apply to it.

A Readiness Assessment then shows how close that product is to meeting those requirements, highlighting the gaps you need to address.

Both are free, giving you a clear picture of what the CRA means for your products and what needs to happen next, before you commit time or budget.

Check your CRA readiness →

What CRA capability looks like inside your own team

If CRA responsibility needs to stay inside the business, the next question is what that looks like day to day.

It starts with giving the people who already understand the product the knowledge to make good security decisions, then giving them a way to apply those decisions consistently and capture the evidence along the way.

That is where the combination of Attestra Academy and Attestra AI comes in.

Build the knowledge around the people who know the product

Your product engineers, product owners and quality teams already understand how your products work. The gap is usually the cybersecurity knowledge needed to apply that product knowledge to the CRA.

Attestra Academy is designed to close that gap. It gives the people already involved in your product lifecycle a practical understanding of what the CRA requires and how to apply it to their own products and processes.

The aim is not to turn every engineer into a cybersecurity specialist. It is to give the people making product decisions enough shared knowledge to recognise the risks, understand their obligations and know when specialist input is needed.

That is the thinking behind the Academy. As Conor explains, “product engineers know their products the best”, and layering cybersecurity knowledge onto that existing expertise creates a much more effective way to retain capability inside the business and “minimise costs”.

Make compliance part of the product lifecycle

Knowledge on its own is not enough. The CRA requires manufacturers to carry out and document activities across the product lifecycle, from development through to placing the product on the market and, ultimately, retirement.

That is where Attestra AI fits.

Rather than treating the technical file as something to assemble at the end, Attestra AI guides your team through the activities that need to happen and captures the evidence as the work progresses. The result is a technical file that grows alongside the product, rather than a compliance exercise that has to be reconstructed afterwards.

Conor describes it as a platform that “guides a manufacturer through the whole process from start to finish” – from “product inception to product development and placing on the market and finally product retiring.”

The important point is that the platform guides your team through the process; it does not remove them from it. The people who understand the product remain responsible for the decisions, while the platform helps them carry out the required activities consistently and maintain the evidence.

That documentation matters because, as Conor puts it, the goal is “more importantly, rigorously documenting what they do so they can evidence it in terms of the CRA requirements.”

Keep specialist expertise available, not permanently on the payroll

Keeping capability in house does not mean doing everything in house.

There will always be areas of product security where specialist expertise is valuable, particularly where the knowledge is highly technical or only needed occasionally. Encryption and firmware security are good examples.

Conor makes the distinction clearly: manufacturers may want “access to external skills, particularly for quite niche areas”, without needing those skills “permanently in house”.

That creates a more sustainable model: build the core CRA capability around your own product team, use a platform to embed the required activities and evidence into the lifecycle, and bring in specialists when a particular problem calls for expertise you do not need every day.

A capability that stays with the product

That is ultimately what the combination of Attestra Academy and Attestra AI is designed to achieve.

Attestra Academy gives your team the knowledge to understand and make the right decisions. Attestra AI helps them put that knowledge into practice across the product lifecycle while building the evidence needed to demonstrate what they have done.

It is no longer a compliance process that sits alongside your product development, but something that becomes part of how your team develops, manages and supports the product.

That is the complete capability Cyber Cert Labs has set out to build. As Conor puts it, “we’ve tried to build this complete solution to help manufacturers have that holistic set of capabilities” across the entire CRA journey.

See how Attestra AI guides your team through the CRA

Attestra AI guides your team through the product lifecycle, helping them carry out the activities the CRA requires and build the technical file as they work.

Start with Attestra AI →

Want to build the knowledge inside your team first?

Explore Attestra Academy →

 

FAQs

Do I need a consultant for CRA compliance?

No, you do not need consultants to lead CRA compliance. With Attestra Academy and Attestra AI, your own product engineers and support teams can manage compliance in-house while they build the knowledge and skills to sustain it. Specialist consultants are worth bringing in for niche areas such as encryption or firmware security, where they supplement your internal capability rather than replace it.

Who needs to comply with the Cyber Resilience Act?

Any manufacturer whose product falls within the scope of the Cyber Resilience Act needs to comply with it. If you are unsure whether your product is in scope, the free Cyber Cert Labs Scope Assessment will tell you.

How much does CRA compliance cost?

It varies from one manufacturer to the next. The cost depends on the size of the gap between your current security and what the CRA requires and on how complex your product is. Measuring that gap first, through a readiness assessment, is the most reliable way to understand the likely cost before you commit budget.

What is a CRA technical file?

A CRA technical file is the documented record of a product’s design, its built-in security, and its post-market monitoring, created across the product lifecycle. It is the evidence you present to prove CRA compliance for each product that falls in scope.