It is important to provide support to microenterprises and small and medium-sized enterprises (MSMEs), including start-ups, in the implementation of the CRA to facilitate compliance.
Special attention is needed as MSMEs may not yet have the necessary knowledge and expertise due to their relative market size.
What are the main rules?
The CRA foresees several measures to support MSEMs.
In order to take into account the interests of manufacturers of products with digital elements that are MSMEs, Member States may develop initiatives that are targeted at those manufacturers, including training, awareness raising, information communication, testing and third-party conformity assessment activities, as well as the establishment of regulatory sandboxes.
Furthermore, when preparing guidance for the implementation of the CRA, the Commission should also take into account the perspective of MSMEs. The Commission may also establish a simplified technical documentation form targeted at the needs of micro- and small enterprises to alleviate their administrative compliance burden.
The EU Agency for Cybersecurity (ENISA) has published its Secure by Design and Default Playbook to support MSMEs with the application of these principles throughout the life cycle of a product.
The European Union also provides funding through the Digital Europe Programme for financial and technical support that facilitates MSME’s ability to comply with the CRA and enables those enterprises to contribute to the strengthening of the level of cybersecurity in the Union. Those projects are managed by the European Cybersecurity Competence Centre.
Relevant cooperation bodies
- MSMEs are members of the Expert group on the Cybersecurity of Products with Digital Elements (CRA Expert Group)
- European Cybersecurity Competence Centre
Reference documents and links
There are several projects receiving funding under the Digital Europe Programme that provide financial and technical support for MSMEs:
- OCCTET – ‘Open-source Compliance: Comprehensive Techniques and Essential Tools’
- CONFIRMATE – ‘Conformity assessment, metrics and compliance automation for the Cyber Resilience Act’
- CRACY – ‘CRA made Easy’
- CYBERFORT – ‘Strengthening Cyber Defenses of SMEs for CRA Compliance’
- CURIUM – ‘Transformation into a Trustworthy Certified Digital Valley’
- OSCRAT – ‘Open-Source Cyber Resilience Act Tools’
- CRA-AI – ‘A European collaboration to drive CRA conformity for SMEs using AI Innovation’
- SECURE – ‘Strengthening EU SMEs Cyber Resilience’
- STAN4CR – ‘Standardization in support of the EU Cyber Resilience Act’
- CYBERSTAND - ‘Supporting EU experts in Cybersecurity standardisation activities’
Related Content
Big Picture