431 days to CRA Free quick checkFree check
CRA · Regulation (EU) 2024/2847 · reporting already applies

Cyber Resilience Act (CRA) for the Czech and Slovak market.
Does it apply to you?

The CRA concerns manufacturers, importers and distributors of products with digital elements – smart devices, IoT and software – and since 11 September 2026 manufacturers have been reporting actively exploited vulnerabilities and severe incidents, even for products that have been on the market for years. We check what exactly applies to you.

up to EUR 15 million – or 2.5% of worldwide annual turnover · for breaches of the essential requirements and of the manufacturer’s obligations including reporting (Art. 64(2), applies from 11 December 2027) – in both the Czech Republic and Slovakia; supervision in Slovakia: NBÚ

Free and without obligation · a few questions · no registration

You answer a few questions and within 2 working days you receive your Pravano Kompas: which obligations apply to you in the Czech Republic and in Slovakia. We communicate in English, in writing.

CRA in a nutshell

What it is, who it concerns and since when it applies.

What is the CRA?

The CRA (Cyber Resilience Act) is Regulation (EU) 2024/2847. Products with digital elements – smart devices, IoT and software – must meet cybersecurity requirements by design (security by design), have a vulnerability handling process and carry CE marking for cybersecurity too. The regulation applies directly; it does not wait for a Czech or Slovak act.

Who does the CRA concern?

Manufacturers of smart devices and IoT, software developers, importers of electronics and distributors. Anyone who sells under their own brand or substantially modifies a product has the obligations of a manufacturer. A cloud service on its own does not fall under the CRA (that is covered by NIS2), but remote data processing without which the product cannot perform its function does.

Since when does the CRA apply?

The main obligations apply from 11 December 2027. However, the obligation to report actively exploited vulnerabilities and severe incidents has applied since 11 September 2026 – also for products placed on the market long before – with a 24-hour deadline for the early warning.

What is at stake?

From 11 December 2027, fines of up to EUR 15 million or 2.5% of worldwide annual turnover for breaches of the essential requirements and of the manufacturer’s obligations including reporting (Art. 64(2)); the rules on imposing penalties are laid down by the Member States. Micro and small enterprises are not fined for missing the 24-hour reporting deadlines (Art. 64(10)).

Czech Republic: is there a national act?

The regulation applies directly; it does not wait for a Czech act. The Czech adaptation act, which is to add supervision and offences, was as at 30 September 2026 still only a draft by the Ministry of Industry and Trade (MPO) and had not been submitted to the Chamber of Deputies. We monitor it and will let you know when something changes.

Slovakia: who supervises?

The market surveillance authority for products with digital elements (Art. 52(2) CRA) in Slovakia is the National Security Authority (NBÚ) (Section 5(1)(ag) of Act No. 69/2018 Coll., added by Act No. 318/2025 Coll. with effect from 1 January 2026). NBÚ is also the authority for NIS2 and for the single cybersecurity information system.

What can go wrong

  • The reporting obligation from 11 September 2026 also covers products placed on the market long before.
  • Without a reporting process you will not meet the 24-hour deadline for the early warning.
  • Selling under your own brand or substantially modifying a product makes you a manufacturer with all the obligations.
  • Slovakia: whether the general obligations of Act No. 56/2018 Coll. on conformity assessment (e.g. instructions in the state language) apply to products with digital elements is so far a matter of interpretation.

What we do for you

  • We sort your portfolio: what falls under the CRA and into which class according to the product’s core functionality.
  • We set up a process for reporting vulnerabilities and incidents, including deadlines and a point of contact.
  • We draw up a plan towards December 2027: SBOM, support period, documentation, the route to CE marking.
Scope of the check

What exactly we go through.

Czech Republic

  • Which products fall under the CRA and whether remote data processing concerns them too
  • Classification by core functionality and the resulting conformity assessment route
  • Readiness for reporting from 11 September 2026, including products already on the market
  • Software bill of materials (SBOM) and the vulnerability disclosure policy
  • Support period, free security updates and visibility of the end of support at the time of purchase
  • Role in the chain: manufacturer, importer, distributor or own brand

Slovakia

  • Which products fall under the CRA and whether remote data processing concerns them too
  • Classification by core functionality and the resulting conformity assessment procedure
  • Readiness for reporting from 11 September 2026, including products already on the market
  • Software bill of materials (SBOM) and the vulnerability disclosure policy
  • Support period, free security updates and visibility of the end of support at the time of purchase
  • Role in the chain: manufacturer, importer, distributor or own brand
  • Supervisory authority in Slovakia: the National Security Authority (NBÚ) (Section 5(1)(ag) of Act No. 69/2018 Coll.)

The scope is based on verified facts – every point is linked to a specific provision of the EU act or of the Czech or Slovak law in its current wording. The binding texts are the legislation itself; our English outputs explain it and cite the provisions.

Packages and prices

A fixed price in advance. No hourly billing.

The check is free. A fixed price for the result, not for time. Prices in euros, excluding VAT.

Map

€690

For a manufacturer or importer of products with digital elements

  • Product classification (default / important / critical)
  • Overview of obligations and deadlines
  • Recommended first steps
  • 3 months of Watch free

Delivery usually within 10 working days of confirming the scope and receiving your documents.

Order Map
✓ Money-back guarantee
Recommended

Guide

€1,490

For a company that wants to know what it is missing for CE marking

Everything in Map, plus:

  • Gap analysis against Annex I requirements
  • Vulnerability handling process
  • Plan towards CE marking
  • Split: in-house / with a partner

Delivery usually 3 to 5 weeks after confirming the scope and receiving your documents.

Order Guide

Ongoing Support

from €2,590

For a company on its way to CE marking

Everything in Guide, plus:

  • Management of implementation
  • Preparation of technical documentation
  • Support on the way to CE marking
  • 6 months of Watch free (instead of 3)

Delivery according to the scope agreed in the confirmation, usually 6 to 10 weeks.

Order Ongoing Support

What each package includes

MapGuideOngoing Support
Scope your productsyour productsyour products, with full support
Map of obligations for your role (with citations of the law) ✓✓✓
Recommended next steps ✓plan towards CE markingplan towards CE marking
Ready-made documents —Annex I gap analysis, vulnerability handling processAnnex I gap analysis, vulnerability handling process
Implementation, support and tailored consultations ——implementation management, technical documentation, path to CE
Indicative delivery time usually within 10 working daysusually 3–5 weeksusually 6–10 weeks
Watch free 3 mo.3 mo.6 mo.
Money-back guarantee ✓——
Price credited on upgrade within 60 days towards Guide——

CRA Watch €129 per month keeps track of rule changes in this area for you: a report every Monday, cancel any time with effect from the end of the month. Order the Watch →

Prices excluding VAT · fixed price for the result · paid by bank transfer against an invoice in EUR due in 14 days (we may ask for payment in advance for Guide and Ongoing Support, and for any package from companies established outside the EU – Terms Art. 4.2). By ordering you agree to the terms and conditions (English translation; the Czech version prevails).

FAQ

What you ask most often.

We have until December 2027, don’t we?
For most obligations, yes – but reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026 and also covers products that have been on the market for a long time. Without a process and a point of contact there is no way to meet the deadlines.
We provide SaaS. Do we fall under the CRA?
A cloud service on its own does not fall under the CRA; that is covered by NIS2. But watch out for remote data processing designed by the manufacturer without which the product cannot perform its function – typically the backend of a smart device or an app. That does fall under the CRA.
We import electronics from Asia. What changes for us?
As an importer you verify that the conformity assessment has been carried out, that technical documentation exists, that the product carries CE marking and that the end of support is visible for it. If you sell it under your own brand or make substantial changes to it, however, you have the obligations of a manufacturer.
Czech Republic: do we also have to deal with a Czech act because of the CRA?
The regulation applies directly; it does not wait for a Czech act. The adaptation act, which is to add supervision and offences, was as at 30 September 2026 still only a draft by the Ministry of Industry and Trade (MPO) and had not been submitted to the Chamber of Deputies – we monitor it and will let you know when something changes.
Slovakia: do we also have to deal with a Slovak act because of the CRA?
The regulation applies directly. Slovakia has already designated the market surveillance authority: the National Security Authority (NBÚ) (Section 5(1)(ag) of Act No. 69/2018 Coll., effective from 1 January 2026). Reporting of actively exploited vulnerabilities from 11 September 2026 goes through the single ENISA/CSIRT platform; Act No. 69/2018 Coll. lays down no further obligations or penalties for manufacturers; whether the general obligations of Act No. 56/2018 Coll. on conformity assessment (e.g. instructions in the state language) apply to products with digital elements is so far a matter of interpretation.
I don’t understand regulations. Can I manage this?
That is exactly our job. We ask in plain language, you answer, and we translate it into documentation and steps.
Is the Map or the Guide the same as an audit with a guarantee of compliance?
No. It is an informative assessment of readiness and support with documentation – not a legal service or an official audit. We help you get ready; final responsibility and the legal interpretation remain with you.
Quick check

3 minutes to fill in. Within 2 working days you know what applies to you.

We will send you the Pravano Kompas: an overview of obligations for your company, deadlines and recommended steps. Free and without obligation.

1 · CRA – a few questions

We only ask for facts about your company. What follows from them is our job – under the rules of the market you sell to.

2 · Four more things

Some obligations depend on whether a company is established in the EU – that is why we ask.

On top of the EU rules we apply the national layer of the market you sell to: local acts, authorities and deadlines.

3 · Where should we send the Pravano Kompas?

By sending the form you acknowledge that the Pravano Kompas is free indicative information, not a legal service, and that we process your data under our Privacy Policy. We prepare the Pravano Kompas with the help of AI and a person approves it. We send marketing messages only with your separate consent. We communicate in English in writing.

Done.

Thank you! We will send you the Pravano Kompas within 2 working days. A confirmation has just been sent to your e-mail – if it does not arrive, please also check your spam or promotions folder.

What happens next: we assess your answers against the full text of the rules, a person checks and approves the result, and the Pravano Kompas comes to you by e-mail within 2 working days.

Meanwhile you can look at the pricing – from the Map of your obligations to complete documentation.

  • Data protected under the GDPR, analytics cookies only with consent
  • No spam – marketing only with your explicit consent
  • Pravano Kompas within 2 working days – prepared with the help of AI, checked and approved by a person
  • Protected (Cloudflare Turnstile)

Prefer to write? info@pravano.cz – a person reads it and replies in English.