Cyber Resilience Act (CRA) for the Czech and Slovak market.
Does it apply to you?
The CRA concerns manufacturers, importers and distributors of products with digital elements – smart devices, IoT and software – and since 11 September 2026 manufacturers have been reporting actively exploited vulnerabilities and severe incidents, even for products that have been on the market for years. We check what exactly applies to you.
up to EUR 15 million – or 2.5% of worldwide annual turnover · for breaches of the essential requirements and of the manufacturer’s obligations including reporting (Art. 64(2), applies from 11 December 2027) – in both the Czech Republic and Slovakia; supervision in Slovakia: NBÚ
Free and without obligation · a few questions · no registration
You answer a few questions and within 2 working days you receive your Pravano Kompas: which obligations apply to you in the Czech Republic and in Slovakia. We communicate in English, in writing.
What it is, who it concerns and since when it applies.
What is the CRA?
The CRA (Cyber Resilience Act) is Regulation (EU) 2024/2847. Products with digital elements – smart devices, IoT and software – must meet cybersecurity requirements by design (security by design), have a vulnerability handling process and carry CE marking for cybersecurity too. The regulation applies directly; it does not wait for a Czech or Slovak act.
Who does the CRA concern?
Manufacturers of smart devices and IoT, software developers, importers of electronics and distributors. Anyone who sells under their own brand or substantially modifies a product has the obligations of a manufacturer. A cloud service on its own does not fall under the CRA (that is covered by NIS2), but remote data processing without which the product cannot perform its function does.
Since when does the CRA apply?
The main obligations apply from 11 December 2027. However, the obligation to report actively exploited vulnerabilities and severe incidents has applied since 11 September 2026 – also for products placed on the market long before – with a 24-hour deadline for the early warning.
What is at stake?
From 11 December 2027, fines of up to EUR 15 million or 2.5% of worldwide annual turnover for breaches of the essential requirements and of the manufacturer’s obligations including reporting (Art. 64(2)); the rules on imposing penalties are laid down by the Member States. Micro and small enterprises are not fined for missing the 24-hour reporting deadlines (Art. 64(10)).
Czech Republic: is there a national act?
The regulation applies directly; it does not wait for a Czech act. The Czech adaptation act, which is to add supervision and offences, was as at 30 September 2026 still only a draft by the Ministry of Industry and Trade (MPO) and had not been submitted to the Chamber of Deputies. We monitor it and will let you know when something changes.
Slovakia: who supervises?
The market surveillance authority for products with digital elements (Art. 52(2) CRA) in Slovakia is the National Security Authority (NBÚ) (Section 5(1)(ag) of Act No. 69/2018 Coll., added by Act No. 318/2025 Coll. with effect from 1 January 2026). NBÚ is also the authority for NIS2 and for the single cybersecurity information system.
What can go wrong
- The reporting obligation from 11 September 2026 also covers products placed on the market long before.
- Without a reporting process you will not meet the 24-hour deadline for the early warning.
- Selling under your own brand or substantially modifying a product makes you a manufacturer with all the obligations.
- Slovakia: whether the general obligations of Act No. 56/2018 Coll. on conformity assessment (e.g. instructions in the state language) apply to products with digital elements is so far a matter of interpretation.
What we do for you
- We sort your portfolio: what falls under the CRA and into which class according to the product’s core functionality.
- We set up a process for reporting vulnerabilities and incidents, including deadlines and a point of contact.
- We draw up a plan towards December 2027: SBOM, support period, documentation, the route to CE marking.
What exactly we go through.
Czech Republic
- Which products fall under the CRA and whether remote data processing concerns them too
- Classification by core functionality and the resulting conformity assessment route
- Readiness for reporting from 11 September 2026, including products already on the market
- Software bill of materials (SBOM) and the vulnerability disclosure policy
- Support period, free security updates and visibility of the end of support at the time of purchase
- Role in the chain: manufacturer, importer, distributor or own brand
Slovakia
- Which products fall under the CRA and whether remote data processing concerns them too
- Classification by core functionality and the resulting conformity assessment procedure
- Readiness for reporting from 11 September 2026, including products already on the market
- Software bill of materials (SBOM) and the vulnerability disclosure policy
- Support period, free security updates and visibility of the end of support at the time of purchase
- Role in the chain: manufacturer, importer, distributor or own brand
- Supervisory authority in Slovakia: the National Security Authority (NBÚ) (Section 5(1)(ag) of Act No. 69/2018 Coll.)
The scope is based on verified facts – every point is linked to a specific provision of the EU act or of the Czech or Slovak law in its current wording. The binding texts are the legislation itself; our English outputs explain it and cite the provisions.
A fixed price in advance. No hourly billing.
The check is free. A fixed price for the result, not for time. Prices in euros, excluding VAT.
Map
For a manufacturer or importer of products with digital elements
- Product classification (default / important / critical)
- Overview of obligations and deadlines
- Recommended first steps
- 3 months of Watch free
Delivery usually within 10 working days of confirming the scope and receiving your documents.
Order MapGuide
For a company that wants to know what it is missing for CE marking
Everything in Map, plus:
- Gap analysis against Annex I requirements
- Vulnerability handling process
- Plan towards CE marking
- Split: in-house / with a partner
Delivery usually 3 to 5 weeks after confirming the scope and receiving your documents.
Order GuideOngoing Support
For a company on its way to CE marking
Everything in Guide, plus:
- Management of implementation
- Preparation of technical documentation
- Support on the way to CE marking
- 6 months of Watch free (instead of 3)
Delivery according to the scope agreed in the confirmation, usually 6 to 10 weeks.
Order Ongoing SupportWhat each package includes
| Map | Guide | Ongoing Support | |
|---|---|---|---|
| Scope | your products | your products | your products, with full support |
| Map of obligations for your role (with citations of the law) | ✓ | ✓ | ✓ |
| Recommended next steps | ✓ | plan towards CE marking | plan towards CE marking |
| Ready-made documents | — | Annex I gap analysis, vulnerability handling process | Annex I gap analysis, vulnerability handling process |
| Implementation, support and tailored consultations | — | — | implementation management, technical documentation, path to CE |
| Indicative delivery time | usually within 10 working days | usually 3–5 weeks | usually 6–10 weeks |
| Watch free | 3 mo. | 3 mo. | 6 mo. |
| Money-back guarantee | ✓ | — | — |
| Price credited on upgrade within 60 days | towards Guide | — | — |
CRA Watch €129 per month keeps track of rule changes in this area for you: a report every Monday, cancel any time with effect from the end of the month. Order the Watch →
Prices excluding VAT · fixed price for the result · paid by bank transfer against an invoice in EUR due in 14 days (we may ask for payment in advance for Guide and Ongoing Support, and for any package from companies established outside the EU – Terms Art. 4.2). By ordering you agree to the terms and conditions (English translation; the Czech version prevails).
What you ask most often.
We have until December 2027, don’t we?
We provide SaaS. Do we fall under the CRA?
We import electronics from Asia. What changes for us?
Czech Republic: do we also have to deal with a Czech act because of the CRA?
Slovakia: do we also have to deal with a Slovak act because of the CRA?
I don’t understand regulations. Can I manage this?
Is the Map or the Guide the same as an audit with a guarantee of compliance?
In depth: the national rules explained.
3 minutes to fill in. Within 2 working days you know what applies to you.
We will send you the Pravano Kompas: an overview of obligations for your company, deadlines and recommended steps. Free and without obligation.
- Data protected under the GDPR, analytics cookies only with consent
- No spam – marketing only with your explicit consent
- Pravano Kompas within 2 working days – prepared with the help of AI, checked and approved by a person
- Protected (Cloudflare Turnstile)
Prefer to write? info@pravano.cz – a person reads it and replies in English.