Register your interest to be contacted by a CRA Expert.
From 11 September 2026, payment technology manufacturers selling into Europe must have CRA vulnerability reporting active. We guide you through every stage of CRA preparation, from the initial applicability assessment through to CE marking readiness by December 2027 and onwards.
years in payment security
PCI & SWIFT CSP assessments per year
QSA · SSA · SWIFT Auditor · SISA
physical presence in Europe
APPLICABILITY
Any company that manufactures, imports, distributes or sells products with digital elements in the European market is in scope, regardless of where it is incorporated.
UK companies: if you export digital products to the European market, you are in scope, even if your company is incorporated in the UK.
Art. 14 — mandatory reporting to ENISA and national authorities. Non-compliance penalties — verify from Art. 64 of Regulation (EU) 2024/2847
All security requirements, technical documentation, SBOM and CE marking must be in place. Products without CE marking cannot be sold in Europe.
THE COMPLIANCE JOURNEY
Four stages, one structured engagement. We guide your preparation at each stage, from initial classification through to CE marking readiness.
CRA Applicability, Product Inventory and Classification
CRA Regulatory Framework Consultancy
Product Cybersecurity assessment
Conformity Assessment & Notified Body Preparation
Already have compliance work in progress? We step in where needed. This is not a mandatory all-or-nothing package.
SERVICES
Each service addresses a specific CRA obligation.
Start where you are.
The applicability assessment defines the scope of everything that follows.
CRA Applicability, Product Inventory and Classification
CRA obligation: Art. 6, 7 and 8 - product scope and classification
The first question every manufacturer must answer: which of my products fall under the CRA, and for which function? Behind this question, the products inventory and the understanding of their features and their components are key. They are the foundation of the CRA applicability to your portfolio. Everything that follows depends on getting this right.
Deliverable: CRA Product scope inventory + CRA classification
CRA Regulatory Framework Consultancy
CRA obligation: Art 13 and 14: manufacturers and reporting obligations across all programmes
Each product definition implies a dedicated framework setup to support the security evaluation and prepare for the assessment program:
The compliance framework supports the selection of assessment path according to the product classification and the organisation and product security maturity.
September 2026 deadline: the vulnerability management programme can be activated in weeks, fast delivering solutions to meet the Art. 14 obligation.
Deliverable: CRA compliance prioritization and roadmap + Assessment programme selection
Product Cybersecurity assessment
CRA obligation: Art 13 and Annex I product risk assessment and security requirements
Art 13 mandates that a risk assessment being performed for each product in scope of CRA. Annex I defines what the CRA requires of your product's security in accordance with the outcome of the risk assessment. Therefore, assessing the product cybersecurity according to CRA requirements measures where your product stands, identifying risks, documenting how each will be treated, and producing the evidence your technical documentation package will need.
Deliverable: Product risk assessment report + cybersecurity requirements gap analysis
Conformity Assessment & Notified Body Preparation
CRA obligation: Annex VII + Art. 32 — technical documentation and CE marking
CE marking is not granted by default. It is earned through a complete, verifiable documentation package. We prepare everything required: documentation, risk assessment records, security declarations; all supporting evidences to demonstrate your self assessment decision or a complete and audit ready file to be delivered to your notified body for independent evaluation and conform CE mark delivery. Our job is to make sure nothing is missing when you get there.
Deliverable: Conformity package
WHY FOREGENIX
Not every consultancy understands payment industry. Here is what makes the difference.
Our OrionX team performs software testing (PT, SAST, DAST) and physical validation of payment devices (POS terminals, ATMs, HSMs). We don't just audit checklists. We understand payment hardware engineering and binary-level security. We are the only provider that combines regulatory audit and technical testing of software and hardware in a single team.
We know what it takes to be CE marking-ready, and we guide your preparation throughout. From initial classification through to the conformity dossier your notified body needs, we build the complete documentation package so you arrive ready. We assist your self assessment and CE conformity attestation definition. When notified body evaluation is required we support your evaluation and evidence demonstration with a robust and complete documentation and control setup.
When assessment path requires third party , the evaluation and granting of CE marking are carried out by an independent certification body.
Generalist competitors don't know payment hardware: the terminals, HSMs and processing platforms that underpin European payment infrastructure. We work with the most relevant payment technology manufacturers in the European market. And the experience is verifiable: PCI DSS QSA status, P2PE expertise and SWIFT CSP assessments are proven credentials for mission-critical financial infrastructure, exactly what the CRA requires.
We operate in the UK and Europe. Some competitors claim European coverage without physical presence in Europe. For a CRA compliance engagement with legal, regulatory and operational implications in the EU, you work with a team that knows the environment from within, not from another continent.
We are a specialist cybersecurity firm: exclusive focus, direct team, no corporate approval layers. Meeting the September 2026 Art. 14 obligation doesn't require completing the full engagement. The vulnerability management programme alone satisfies it, and we can have it running in very short timeframe.
THE TEAM
Our CRA engagements are delivered by a team of dedicated specialists, one for programme governance, one for cybersecurity practice, one for supply chain and software security. You work with the right expert throughout the engagement.
Programme governance · Stakeholder management · Regulatory alignment
Your single point of contact for programme delivery and governance. Manages workstreams across the engagement, translates CRA requirements into operational processes, and keeps delivery aligned with your regulatory deadlines and business objectives.
Secure-by-Design · Product security · Vulnerability management
Expert in Secure-by-Design practices and product security assessment. Evaluates your development processes, governance controls and operational practices against CRA requirements, turning findings into a compliance roadmap your team can act on.
SBOM · Supply chain governance · Software composition
Expert in software supply chain governance and composition analysis. Analyses your product architecture, third-party dependencies and open-source components against CRA obligations, covering SBOM creation and supply chain risk from the ground up.
SOCIAL PROOF
Payment technology manufacturers and software providers that already work with Foregenix.
Chief Security and Compliance Officer — Verisec
FAQ
Yes, if you manufacture, import, distribute or sell products with digital elements in the European market, the CRA applies to you. This is independent of where your company is incorporated: a UK or US manufacturer selling into Europe is in scope.
Our article on the Cyber Resilience Act and who it applies to covers this in more detail.
September 2026 activates vulnerability and incident reporting obligations (Art. 14). The vulnerability management programme must be active before 11 September. December 2027 is the full enforcement date: all security requirements, technical documentation, SBOM and CE marking must be in place.
The entry point is always the CRA Applicability & Classification Inventory, to understand what applies and what you already have. From there, the engagement is defined based on the gaps identified. Not all clients need all five services.
The starting point is always the initial assessment. If you already have progress in place, we step in where needed. There is no mandatory all-or-nothing package.
CE marking is the regulatory evidence that a product meets the CRA's cybersecurity requirements. From December 2027, products without CE marking cannot be sold in Europe. We prepare your complete technical documentation and conformity dossier, so that when you engage your notified body, nothing is missing.
Our CRA practice is focused on the payments sector, where our accumulated experience translates directly into faster, more precise engagements. That said, our background spans hard-core computing, electronics, and manufacturing processes. That depth of engineering knowledge, across disciplines, not just compliance frameworks, is what sets us apart from general consultancies. As CRA adoption expands across industries, that breadth positions us to support manufacturers in adjacent verticals as well.
The initial assessment takes a matter of weeks and gives you a clear picture of your obligations, your current gaps, and what completing the process will require. Timelines for the full engagement depend on your product portfolio and the complexity of your current security posture.
Art. 14 reporting obligations are active from 11 September 2026. Start with a CRA Applicability Assessment to know exactly where your company stands.