NORMQ
CYBER RESILIENCE ACT · CRA
Prepare your company for CRA notifications within 24 hours.

From 11 September 2026, certain notification obligations under the Cyber Resilience Act apply to manufacturers of products with digital elements.
NORMQ prepares the procedures, responsibilities and documentation needed so that, when faced with a potentially reportable event, your company does not have to start improvising with a 24-hour legal deadline.
EUROPEAN REGULATION
11 September 2026
Cyber Resilience Act: the 24-hour
notification obligations are now applicable.
Our work combines regulatory analysis and operational preparation so that your company has a clear procedure in place for potential CRA notifications, with responsibilities, steps and documentation defined in advance.
Official source
Regulation (EU) 2024/2847 — Cyber Resilience Act
Articles 14 and 71
Application of the notification obligations: 11 September 2026
WHAT WE REVIEW
We prepare the process before the clock starts running.
We review how your company would respond to an actively exploited vulnerability or a severe incident potentially subject to notification under the CRA.
Products and scope
Identification of products with digital elements and the responsible teams involved.
Internal detection and escalation
How a potentially reportable event is communicated, assessed and escalated internally.
Responsibilities and notification
Roles, responsible persons, contacts and steps required to activate the procedure.
Documentation and deadlines
Required information and preparation of the 24-hour communication, subsequent notifications and closure.
SERVICES
A protocol in place before the urgency begins.
CRA 24H PROTOCOL
€390 + VAT
Preparation of the basic response procedure for a potential actively exploited vulnerability or severe incident subject to notification.
Includes scope review, internal responsibilities, escalation flow, information checklist and templates for the communications required under the CRA.
CRA 24H PROTOCOL · MULTI-PRODUCT
From €690 + VAT
Preparation of the procedure for companies with multiple products with digital elements, teams involved or internal notification workflows.
Includes definition of responsibilities by product, escalation flows, documentation and communication templates adapted to the company's structure.
PENALTIES
The CRA provides for significant financial
penalties for non-compliance.
Official source: Regulation (EU) 2024/2847 — Article 64(2).
PROCESS
A clear procedure before the clock starts running.
01
Scope review
We identify the products, teams involved and internal responsibilities.
02
Protocol design
We define the escalation flow, responsible persons, contacts and decision points.
03
Documentation preparation
We create checklists and templates for the 24-hour CRA communication and subsequent notifications.
04
Delivery and validation
We review the procedure with your company and leave the documentation ready for use.
FAQ
Frequently asked questions, answered clearly.
What does the CRA 24H Protocol include?
Does NORMQ determine whether a vulnerability or incident must be reported?
Does the service include penetration testing or a cybersecurity audit?
CONTACT
Let’s talk about your CRA preparation.
Tell us about your products with digital elements and your current notification process. We will get back to you to assess the most appropriate scope for your company.
NORMQ
Regulatory and operational preparation services for compliance with the Cyber Resilience Act (CRA).
Legal Notice
Privacy Policy
Cookies

