CRA Compliance for Payment Technology Manufacturers

The specialised technical partner for payment technology manufacturers navigating the EU Cyber Resilience Act.

From 11 September 2026, payment technology manufacturers selling into Europe must have CRA vulnerability reporting active. We guide you through every stage of CRA preparation, from the initial applicability assessment through to CE marking readiness by December 2027 and onwards.

17 +

years in payment security

1500 +

PCI & SWIFT CSP assessments per year

Accreditations

QSA · SSA · SWIFT Auditor · SISA

EU + UK

physical presence in Europe

APPLICABILITY

Does the CRA apply to your company?


Any company that manufactures, imports, distributes or sells products with digital elements in the European market is in scope, regardless of where it is incorporated.

POS terminal & payment device manufacturers
Payment processing software providers
HSM manufacturers
Payments SaaS platforms
 
Transaction processors & intermediaries
Smart card & secure element manufacturers
Digital wallet & SoftPOS providers

UK companies: if you export digital products to the European market, you are in scope, even if your company is incorporated in the UK.

11 September 2026
Vulnerability & incident reporting obligations active

Art. 14 — mandatory reporting to ENISA and national authorities. Non-compliance penalties — verify from Art. 64 of Regulation (EU) 2024/2847

11 December 2027
Full CRA enforcement — CE marking required

All security requirements, technical documentation, SBOM and CE marking must be in place. Products without CE marking cannot be sold in Europe.

THE COMPLIANCE JOURNEY

Understand, Design, Evaluate, Prepare: a structured path through every stage


Four stages, one structured engagement. We guide your preparation at each stage, from initial classification through to CE marking readiness.

1

Understand

"Does CRA apply to your company portfolio?"

CRA Applicability, Product Inventory and Classification

2

Design

"How do we structure compliance internally? Product boundaries qualification, Roadmap and Prioritization, Assessment program selection"

CRA Regulatory Framework Consultancy

3

Evaluate

"Where do we stand against essential cybersecurity requirements? Is our product technically secure? Is our development process secure by design? Do we have our SBOM?"

Product Cybersecurity assessment

4

Prepare for CE

Collect evidences to support the assessment report

Conformity Assessment & Notified Body Preparation

Already have compliance work in progress? We step in where needed. This is not a mandatory all-or-nothing package.

SERVICES

Every stage covered.

From applicability assessment to conformity documentation.


Each service addresses a specific CRA obligation.

Start where you are.

The applicability assessment defines the scope of everything that follows.

01

Understand

CRA Applicability, Product Inventory and Classification

CRA obligation: Art. 6, 7 and 8 - product scope and classification

The first question every manufacturer must answer: which of my products fall under the CRA, and for which function? Behind this question, the products inventory and the understanding of their features and their components are key. They are the foundation of the CRA applicability to your portfolio. Everything that follows depends on getting this right.

Deliverable: CRA Product scope inventory + CRA classification

02

Design

CRA Regulatory Framework Consultancy

CRA obligation: Art 13 and 14: manufacturers and reporting obligations across all programmes

Each product definition implies a dedicated framework setup to support the security evaluation and prepare for the assessment program:

  • Product classification
  • Vulnerability management
  • Incident response
  • SDLC assessment
  • Supply chain security
  • SBOM creation

The compliance framework supports the selection of assessment path according to the product classification and the organisation and product security maturity.

September 2026 deadline: the vulnerability management programme can be activated in weeks, fast delivering solutions to meet the Art. 14 obligation.

Deliverable: CRA compliance prioritization and roadmap + Assessment programme selection

03

Evaluate

Product Cybersecurity assessment

CRA obligation: Art 13 and Annex I product risk assessment and security requirements

Art 13 mandates that a risk assessment being performed for each product in scope of CRA. Annex I defines what the CRA requires of your product's security in accordance with the outcome of the risk assessment. Therefore, assessing the product cybersecurity according to CRA requirements measures where your product stands, identifying risks, documenting how each will be treated, and producing the evidence your technical documentation package will need.

Deliverable: Product risk assessment report + cybersecurity requirements gap analysis

04

Prepare for CE

Conformity Assessment & Notified Body Preparation

CRA obligation: Annex VII + Art. 32 — technical documentation and CE marking

CE marking is not granted by default. It is earned through a complete, verifiable documentation package. We prepare everything required: documentation, risk assessment records, security declarations; all supporting evidences to demonstrate your self assessment decision or a complete and audit ready file to be delivered to your notified body for independent evaluation and conform CE mark delivery. Our job is to make sure nothing is missing when you get there.

Deliverable: Conformity package

Not sure where you stand? Every engagement starts with the applicability assessment, a clear picture of your obligations and current gaps, delivered in weeks.

WHY FOREGENIX

Why payment technology manufacturers choose Foregenix


Not every consultancy understands payment industry. Here is what makes the difference.

1

Real technical testing: software and physical hardware

Our OrionX team performs software testing (PT, SAST, DAST) and physical validation of payment devices (POS terminals, ATMs, HSMs). We don't just audit checklists. We understand payment hardware engineering and binary-level security. We are the only provider that combines regulatory audit and technical testing of software and hardware in a single team.

2

Everything you need to be CE marking-ready

We know what it takes to be CE marking-ready, and we guide your preparation throughout. From initial classification through to the conformity dossier your notified body needs, we build the complete documentation package so you arrive ready. We assist your self assessment and CE conformity attestation definition. When notified body evaluation is required we support your evaluation and evidence demonstration with a robust and complete documentation and control setup.

When assessment path requires third party , the evaluation and granting of CE marking are carried out by an independent certification body.

3

Specialists in payment technology

Generalist competitors don't know payment hardware: the terminals, HSMs and processing platforms that underpin European payment infrastructure. We work with the most relevant payment technology manufacturers in the European market. And the experience is verifiable: PCI DSS QSA status, P2PE expertise and SWIFT CSP assessments are proven credentials for mission-critical financial infrastructure, exactly what the CRA requires.

4

Real European presence

We operate in the UK and Europe. Some competitors claim European coverage without physical presence in Europe. For a CRA compliance engagement with legal, regulatory and operational implications in the EU, you work with a team that knows the environment from within, not from another continent.

5

The speed of a specialist

We are a specialist cybersecurity firm: exclusive focus, direct team, no corporate approval layers. Meeting the September 2026 Art. 14 obligation doesn't require completing the full engagement. The vulnerability management programme alone satisfies it, and we can have it running in very short timeframe.

THE TEAM

A specialist for every stage of your CRA programme


Our CRA engagements are delivered by a team of dedicated specialists, one for programme governance, one for cybersecurity practice, one for supply chain and software security. You work with the right expert throughout the engagement.

CRA Programme Lead

Programme governance · Stakeholder management · Regulatory alignment

Your single point of contact for programme delivery and governance. Manages workstreams across the engagement, translates CRA requirements into operational processes, and keeps delivery aligned with your regulatory deadlines and business objectives.

Senior Cybersecurity Consultant

Secure-by-Design · Product security · Vulnerability management

Expert in Secure-by-Design practices and product security assessment. Evaluates your development processes, governance controls and operational practices against CRA requirements, turning findings into a compliance roadmap your team can act on.

Software Security & Supply Chain Specialist

SBOM · Supply chain governance · Software composition

Expert in software supply chain governance and composition analysis. Analyses your product architecture, third-party dependencies and open-source components against CRA obligations, covering SBOM creation and supply chain risk from the ground up.

Beyond the core team, we draw upon a global network of Foregenix specialists across penetration testing, incident response, cryptography, threat intelligence and regulatory compliance, to address the specific challenges each engagement brings.

 

SOCIAL PROOF

Trusted by payment technology companies across Europe


Payment technology manufacturers and software providers that already work with Foregenix.

"We would recommend Foregenix, particularly to organisations dealing with advanced payment security requirements or transitioning to cloud-based cryptographic services."

Chief Security and Compliance Officer — Verisec

FAQ

Frequently asked questions

Yes, if you manufacture, import, distribute or sell products with digital elements in the European market, the CRA applies to you. This is independent of where your company is incorporated: a UK or US manufacturer selling into Europe is in scope.

 Our article on the Cyber Resilience Act and who it applies to covers this in more detail. 

September 2026 activates vulnerability and incident reporting obligations (Art. 14). The vulnerability management programme must be active before 11 September. December 2027 is the full enforcement date: all security requirements, technical documentation, SBOM and CE marking must be in place.

The entry point is always the CRA Applicability & Classification Inventory, to understand what applies and what you already have. From there, the engagement is defined based on the gaps identified. Not all clients need all five services.

The starting point is always the initial assessment. If you already have progress in place, we step in where needed. There is no mandatory all-or-nothing package.

CE marking is the regulatory evidence that a product meets the CRA's cybersecurity requirements. From December 2027, products without CE marking cannot be sold in Europe. We prepare your complete technical documentation and conformity dossier, so that when you engage your notified body, nothing is missing. 

Our CRA practice is focused on the payments sector, where our accumulated experience translates directly into faster, more precise engagements. That said, our background spans hard-core computing, electronics, and manufacturing processes. That depth of engineering knowledge, across disciplines, not just compliance frameworks, is what sets us apart from general consultancies. As CRA adoption expands across industries, that breadth positions us to support manufacturers in adjacent verticals as well.

The initial assessment takes a matter of weeks and gives you a clear picture of your obligations, your current gaps, and what completing the process will require. Timelines for the full engagement depend on your product portfolio and the complexity of your current security posture.

CRA regulation is already engaged.


Art. 14 reporting obligations are active from 11 September 2026. Start with a CRA Applicability Assessment to know exactly where your company stands.