For SMEs & founders

You're accountable for the CRA. You don't have a compliance department.

Most small manufacturers can self-assess under the CRA — no notified body, no auditor in the room. But "self-assess" doesn't mean "assert." You still have to stand behind every call you make. ProvenVEX lets a thin team do that on evidence instead of headcount.

Self-assessment readyEU-hostedNo scanner to rip out
The reality for a small team

Big-company compliance advice assumes a team you don't have.

The CRA lands the same obligations on a ten-person company as on a thousand-person one. Three of them fall hardest when the team is small.

Personal

The accountability is yours

As the founder or CTO, you're the one personally on the hook for the product's compliance. There's no compliance director to hand it to.

Capacity

No dedicated headcount

Your engineers already ship the product. Nobody's full-time job is triage, VEX, and reporting — and the CRA needs all three, continuously.

Clock

The deadline is already here

Reporting applies from September 2026 to products you've already shipped. The 24-hour clock doesn't care how many people you have.

The good news

You can almost certainly self-assess.

Most products with digital elements fall in the CRA's default class, which means Module A — internal control. You assess conformity yourself; no notified body is required.

But self-assessment is not self-assertion.

Removing the notified body removes the third party, not the requirements. You still compile the full technical file, sign the Declaration of Conformity, and keep both for ten years — and a market-surveillance authority can still ask you to justify any decision. The bar for evidence is the same as for a company ten times your size. That's the trap: a small team is tempted to assert its way through, and an asserted not_affected is exactly what doesn't hold up.

What a small team needs

Four jobs, collapsed into a workflow.

The CRA's recurring work breaks into four jobs. On a thin team, each one has to be near-automatic or it doesn't get done.

Job 1 · inventory

Know what you ship

SBOMs generated from your build, not maintained by hand. If you already produce one, we take it as input — see the CRA guide.

Job 2 · assessment

Know what actually matters

Which component CVEs are genuinely exploitable in your product — decided with evidence, so one engineer isn't hand-judging a wall of findings.

Job 3 · reporting

Be ready for the clock

Active-exploitation monitoring wired to a timer, and reports drafted in advance, so a 24-hour deadline isn't a fire drill. See 24 / 72 / 14 reporting.

Job 4 · evidence

Be ready for a question

An immutable, retained evidence trail per product and version — the technical file assembles itself instead of becoming a quarterly scramble.

The shift

Evidence instead of headcount.

The reason CRA compliance looks like a hiring problem is that the assessment has always been manual. Make it evidence-backed and the maths changes.

The manual way

A programme that needs a team

  • An engineer reads each advisory and forms a judgement.
  • Every not_affected is an assertion nobody can reconstruct later.
  • The evidence trail is a folder of documents someone maintains.
  • Scales only by adding people.
With evidence-backed VEX

A programme a small team can run

  • The engine decides reachability and exploitability, with the proof attached.
  • Every decision is defensible to an authority, years later.
  • The evidence trail is produced automatically, not maintained.
  • Scales by adding products, not people.

There's an EU tailwind here too. The regulation builds in proportionality for micro and small enterprises — simplified technical documentation among it — and ENISA and the national CSIRTs offer guidance and priority support aimed squarely at smaller manufacturers. The support exists. What it can't do is make the assessment for you, which is the piece that decides whether a small team can actually keep up.

Questions small teams ask

The honest answers.

Do small businesses have to comply with the CRA?

Yes. The CRA applies to products with digital elements, not to company size — there is no blanket SME exemption from the core obligations. The regulation does build in proportionality for smaller manufacturers, such as simplified technical documentation for micro and small enterprises, and open-source software stewards get a lighter regime, but a small company placing a product on the EU market is in scope.

Can an SME self-assess under the CRA?

For most products, yes. Products in the default class self-assess under Module A internal control, with no notified body involved. You still compile the full technical file and sign the Declaration of Conformity, and you keep them for ten years — but the assessment is yours to run.

Do I need to hire a compliance team for the CRA?

Not necessarily. The heaviest recurring work — deciding which component vulnerabilities actually affect your product and being able to justify it — is what usually drives headcount. If that assessment is backed by machine-generated evidence rather than manual review, one engineer can run a defensible programme that would otherwise need a team.

Does self-assessment mean less rigour?

No. Self-assessment removes the notified body, not the requirements. You meet the same essential requirements and hold the same technical documentation; you simply attest to it yourself. The evidence bar an authority can hold you to is the same as for any manufacturer.

Design partners

One product. One engineer. A defensible programme.

Bring a single product and we'll show you what a small-team CRA programme looks like on your own code — evidence-backed VEX and a reportability shortlist, no team required.

Limited design-partner slots · EU-hosted · priced per product, not per developer