The countdown to the EU Cyber Resilience Act (CRA) has already begun. With the legal obligation to report actively exploited vulnerabilities and severe incidents starting in September 2026 and full enforcement by December 2027, manufacturers of products with digital elements are preparing for a new cybersecurity regulatory landscape.
Brightsight’s role in the CRA ecosystem
Our teams bring extensive experience across a broad range of cybersecurity evaluation and compliance frameworks, including Common Criteria, SESIP, EUCC, IEC 62443, ETSI EN 303 645, ISO/SAE 21434, EMVCo and PCI. This multidisciplinary expertise provides a strong foundation for supporting manufacturers as they prepare for Cyber Resilience Act compliance.
Brightsight's journey towards becoming a CRA Notified Body
CURRENT STATUS
Accreditation in progress
Brightsight is progressing through the accreditation process required to operate as a CRA Notified Body for Module B and Module H.
NEXT MILESTONE
Temporary accreditation granted (TAB)
NOTIFICATION PHASE
Notification as a CRA
Notified Body
FINAL MILESTONE
CRA Notified Body designation
What this means for you
While our formal designation is being finalized, your compliance journey should not wait. By engaging with Brightsight today for gap assessments and security evaluations, you can begin assessing your product's readiness against the CRA's Essential Requirements
and start building valuable technical evidence early in the development process.
Once our Notified Body status is officially granted, relevant technical evidence generated during earlier evaluation activities may be considered as part of future conformity assessment activities, where appropriate. This approach can help reduce duplicated effort, improve efficiency and support a smoother path towards CRA compliance and access to the European market.
What are the CRA conformity paths and which one should you choose?
Module B
Module H
While both routes can be used to demonstrate compliance with CRA requirements, they are designed for different situations. Module B focuses on the assessment of a specific product, whereas Module H focuses on the manufacturer's quality management system and its ability to consistently deliver compliant products.
Successfully completing the applicable conformity assessment is a crucial step toward issuing the EU Declaration of Conformity and affixing the mandatory CE marking to your product, ensuring uninterrupted access to the European Market.
Module B - a direct focus on the product
- Review of product design and cybersecurity architecture
- Assessment of technical documentation and supporting evidence
- Verification of compliance with applicable CRA requirements
- Independent evaluation by a qualified CRA Notified Body
Module H - a direct focus on the quality management system (QMS)
The Notified Body evaluates whether cybersecurity is systematically integrated into the organization's design, development, testing, vulnerability handling, update management, and post-market monitoring activities. This process includes:
- Evaluation of the Quality Management System (QMS)
- Assessment of risk management and cybersecurity governance processes
- Review of technical documentation and supporting evidence
- Verification of vulnerability handling processes
- Independent evaluation by a qualified CRA Notified Body
Reusing evidence: Accelerating your "Speed-to-Market"
Manufacturers that have already invested in cybersecurity evaluations, testing and certification activities may be able to build on existing results rather than starting from scratch. Where relevant and appropriate, existing technical evidence can support future conformity assessment activities, helping reduce duplicated effort, improve efficiency and streamline the path towards CRA compliance.
Your clear path to CRA compliance
- Understand CRA requirements: Through training and awareness sessions.
- Assess readiness: Via gap assessments and reviews of your architecture and processes.
- Address findings: Use assessment results to prioritize improvement actions and enhance CRA readiness.
- CRA conformity assessment (Module B and Module H): Once formally designated as a CRA Notified Body, we will perform the formal assessment activities required under the applicable CRA conformity assessment path (Module B or Module H).



