CRA-compliant product development
NewTec services to fulfill the legal requirements
Cyber Resilience Act (CRA): The requirements are now binding. All hardware and software products and components that are sold in the EU and contain ‘digital elements’ are subject to the Cyber Resilience Act.
NewTec supports manufacturers in the CRA-compliant development of products with digital elements - for example with a threat and risk analysis in accordance with the Cyber Resilience Act, the integration of security measures or the implementation of secure update processes as well as comprehensive security testing. Our experts work with you to assess your current situation, provide help with classification and support the introduction of necessary processes and secure operation.
Phases of security product development according to CRA
NewTec services to fulfill the legal requirements

To optimise your security and development processes, we determine the maturity level of your processes and make specific recommendations for improvement based on a gap analysis. Our experienced security consultants support the introduction of compliant processes in accordance with the requirements of the Cyber Resilience Act and coach your team in all relevant aspects of security engineering.
- CRA GAP analysis: Maturity assessment of the development and support processes
- Implementation of CRA-compliant processes
- Documentation in accordance with CRA
- Workshops and trainings to build up security awareness and know-how
Our competent security engineers support you in the effective and compliant development of cyber-secure products - from product classification according to CRA to risk analyses (TARA, IRA, DRA) and compliance tests. Our pre-qualified solution modules also help to accelerate your product development and manage security risks.
- Product classification
- Creation of a cyber security management plan
- Development and documentation in accordance with CRA
- Risk analyses during the entire product life cycle (TARA, IRA, DRA)
- Development of secure update strategies
- Consultancy and support with CRA compliance testing

To ensure secure operation, we support you with comprehensive managed services such as vulnerability monitoring, a Product Incident Response Team (PSIRT) or PKI management.
- Automated vulnerability monitoring
- Vulnerability management
- Update management
- Support in the form of a customised Product Security Incident Response Team (PSIRT)
- Provision of a public key infrastructure (PKI)
Feel free to contact us!
For more information or if you have any questions, please send us a message and we will get in touch with you.
