CRA Cost Calculator: What will Cyber Resilience Act compliance cost you?
Everyone selling CRA services quotes their own price. Almost nobody helps you estimate the other side of the ledger: the hours your own engineers will spend producing documentation, setting up an SBOM, standing up a vulnerability process and getting fluent in the regulation.
This calculator estimates that internal effort, block by block, from seven questions about your portfolio. The model is published on this page. If you think a number is wrong for your case, you can see exactly which one and why.
By submitting this form, you accept our Terms and acknowledge that Regulus will process your data to provide CRA Cost Calculator. For more details, see our Privacy Policy.
How the estimate is built
The calculator prices seven blocks of work, each as an hour range at EUR 85/h loaded engineering cost:
| Block | First family |
|---|---|
| Scope and classification determination | 8-16 h |
| Cybersecurity risk assessment | 24-40 h |
| Annex I requirements mapping | 24-40 h |
| Technical documentation file | 40-80 h |
| Declaration of Conformity, user information, support period | 8-16 h |
| SBOM tooling and first SBOM (if you have none) | 16-24 h |
| Vulnerability handling and reporting readiness (if you have none) | 16-32 h |
Then it applies what actually moves the total:
- Classification. Important Class I adds roughly 30 percent to the documentation blocks, because self assessment demands harmonised standards applied in full. Class II adds 45 percent plus notified body preparation, and the notified body’s own fees, typically EUR 10,000 to 30,000 per family, come on top.
- Additional families. Each one costs about 45 percent of the first: the decisions carry over, the documents still have to be written.
- Existing documentation. A mature system (ISO 27001, IEC 62443) cuts the analysis blocks by about 30 percent. It never cuts them to zero, because the CRA asks product questions those systems do not answer.
- Radio. WiFi, Bluetooth or cellular adds a block that is not 2027 work at all: those requirements have applied since 1 August 2025.
No estimate survives contact with a real portfolio unchanged. This one is honest about being an estimate, and it shows its working.
Five ways to keep the bill down
Settle the classification before anything else.
Every hour spent documenting under the wrong class is an hour spent twice. It is the cheapest block in the table and the one that multiplies all the others, which is why it is the worst one to guess.
Group your catalogue into families properly.
The unit of work is the family, not the product reference. Fifty references that share a platform, a codebase and an update mechanism can be one technical file. Fifty references documented separately is how a five-figure job becomes a six-figure one.
Do not build processes twice.
The SBOM pipeline, the disclosure policy and the reporting readiness are one-off costs that serve every family you will ever ship. Build them once, centrally, before each product team improvises its own.
Reuse what your certifications already contain.
ISO 27001 and IEC 62443 do not satisfy the CRA, but they feed it: risk methods, asset inventories, secure development evidence. The mistake is not reusing too much, it is assuming the certificate replaces the product file.
Start before 11 September 2026, not before 11 December 2027.
The reporting duties arrive first, they apply to products already on the market, and they are process work with a long lead time. Teams that aim at the 2027 date discover the 2026 one from a CSIRT deadline.
FAQs
How much does CRA compliance cost?
For a single product family in the default category, with little written down, internal effort typically lands between EUR 12,000 and EUR 25,000 of engineering time. Classification is the single biggest multiplier: a Class II product roughly doubles it before notified body fees.
What does a notified body cost under the CRA?
Fees are set by each body and are not published as a tariff, but typical conformity assessment engagements run EUR 10,000 to 30,000 per product family, on top of your internal preparation.
Can our existing ISO 27001 certification reduce the work?
It reduces it, roughly by a third in our model, because policies, asset inventories and risk methods already exist. It does not remove the product-level work: the CRA asks about one product’s threat model, SBOM and support period, not about your organisation.
Is it cheaper to do CRA documentation in-house or to buy it?
The raw writing is 100 to 200 hours for a first family. Bought as a package it is a four-figure sum. The real question is usually not money but calendar: whether your engineers should spend those hours on documentation or on fixing the findings the documentation surfaces.
Do the totals include product changes?
No, and no honest estimate can. If the risk assessment finds that your update mechanism is not secure, fixing that is engineering work with its own budget. The calculator prices knowing and documenting, not remediating.
Early Access for CRA Compliance Tools 🇪🇺
Join Early Access — Save 20%