# CRA-ready by September 11th, without stopping development

> A manufacturer of agricultural machinery reaches the CRA deadline with the mandatory processes operational and a new product designed secure from the start.

- URL: https://albertoscarpa.com/en/work/cra-ready-by-september-11-without-stopping-development/
- Lingua / Language: English
- Published: 2026-06-25
- Tags: CRA, IEC 62443
- Sector: Agricultural machinery manufacturer
- Service: CRA consulting — mandatory compliance + pilot product
- Duration: Started June 2026, ongoing
- Outcome: Mandatory CRA processes operational before September 11th, 2026

---

## The context

On September 11th, 2026, the Cyber Resilience Act's obligations on vulnerability handling and incident reporting come into force: they apply to anyone placing products with digital elements on the market, regardless of whether the product is certified. A manufacturer of agricultural machinery found itself with two problems on the same table: meeting that deadline on products already in its catalogue, and managing the CRA on a new product still in development, without slowing down its design.

The difficulty wasn't understanding the regulation, but translating it into something a company with an already well-established ISO 9001 quality system could adopt without creating a second, parallel system to maintain.

## The approach

I worked on two tracks in parallel. On the mandatory-deadline track, I produced the map of applicable CRA obligations, a gap analysis of the existing vulnerability-management process, and then the operational documents that were missing: the vulnerability-handling process, the Coordinated Vulnerability Disclosure policy, and a specific checklist of what needed to be ready before September 11th. To avoid duplicating the system, I integrated these processes into the existing ISO 9001 quality management system rather than running a new one alongside it.

On the pilot-product track, I set the CRA classification of the product and the cybersecurity risk analysis on the interfaces actually exposed, so as to fix the security requirements while the product was still on the design table — not after the fact.

## The outcome

The company reaches the deadline with the mandatory CRA processes operational and documented, inside the quality system it already used — no parallel track to maintain. The new product enters development with classification and security requirements already defined: integrating them now costs far less than it would have on a finished product. That's exactly the point I make to industrial manufacturers: a regulatory requirement, addressed at the design stage, becomes just another product decision.
