You're accountable for the CRA. You don't have a compliance department.
Most small manufacturers can self-assess under the CRA — no notified body, no auditor in the room. But "self-assess" doesn't mean "assert." You still have to stand behind every call you make. ProvenVEX lets a thin team do that on evidence instead of headcount.
Big-company compliance advice assumes a team you don't have.
The CRA lands the same obligations on a ten-person company as on a thousand-person one. Three of them fall hardest when the team is small.
The accountability is yours
As the founder or CTO, you're the one personally on the hook for the product's compliance. There's no compliance director to hand it to.
No dedicated headcount
Your engineers already ship the product. Nobody's full-time job is triage, VEX, and reporting — and the CRA needs all three, continuously.
The deadline is already here
Reporting applies from September 2026 to products you've already shipped. The 24-hour clock doesn't care how many people you have.
You can almost certainly self-assess.
Most products with digital elements fall in the CRA's default class, which means Module A — internal control. You assess conformity yourself; no notified body is required.
But self-assessment is not self-assertion.
Removing the notified body removes the third party, not the requirements. You still compile the full technical file, sign the Declaration of Conformity, and keep both for ten years — and a market-surveillance authority can still ask you to justify any decision. The bar for evidence is the same as for a company ten times your size. That's the trap: a small team is tempted to assert its way through, and an asserted not_affected is exactly what doesn't hold up.
Four jobs, collapsed into a workflow.
The CRA's recurring work breaks into four jobs. On a thin team, each one has to be near-automatic or it doesn't get done.
Know what you ship
SBOMs generated from your build, not maintained by hand. If you already produce one, we take it as input — see the CRA guide.
Know what actually matters
Which component CVEs are genuinely exploitable in your product — decided with evidence, so one engineer isn't hand-judging a wall of findings.
Be ready for the clock
Active-exploitation monitoring wired to a timer, and reports drafted in advance, so a 24-hour deadline isn't a fire drill. See 24 / 72 / 14 reporting.
Be ready for a question
An immutable, retained evidence trail per product and version — the technical file assembles itself instead of becoming a quarterly scramble.
Evidence instead of headcount.
The reason CRA compliance looks like a hiring problem is that the assessment has always been manual. Make it evidence-backed and the maths changes.
A programme that needs a team
- An engineer reads each advisory and forms a judgement.
- Every
not_affectedis an assertion nobody can reconstruct later. - The evidence trail is a folder of documents someone maintains.
- Scales only by adding people.
A programme a small team can run
- The engine decides reachability and exploitability, with the proof attached.
- Every decision is defensible to an authority, years later.
- The evidence trail is produced automatically, not maintained.
- Scales by adding products, not people.
There's an EU tailwind here too. The regulation builds in proportionality for micro and small enterprises — simplified technical documentation among it — and ENISA and the national CSIRTs offer guidance and priority support aimed squarely at smaller manufacturers. The support exists. What it can't do is make the assessment for you, which is the piece that decides whether a small team can actually keep up.
The honest answers.
Do small businesses have to comply with the CRA?
Yes. The CRA applies to products with digital elements, not to company size — there is no blanket SME exemption from the core obligations. The regulation does build in proportionality for smaller manufacturers, such as simplified technical documentation for micro and small enterprises, and open-source software stewards get a lighter regime, but a small company placing a product on the EU market is in scope.
Can an SME self-assess under the CRA?
For most products, yes. Products in the default class self-assess under Module A internal control, with no notified body involved. You still compile the full technical file and sign the Declaration of Conformity, and you keep them for ten years — but the assessment is yours to run.
Do I need to hire a compliance team for the CRA?
Not necessarily. The heaviest recurring work — deciding which component vulnerabilities actually affect your product and being able to justify it — is what usually drives headcount. If that assessment is backed by machine-generated evidence rather than manual review, one engineer can run a defensible programme that would otherwise need a team.
Does self-assessment mean less rigour?
No. Self-assessment removes the notified body, not the requirements. You meet the same essential requirements and hold the same technical documentation; you simply attest to it yourself. The evidence bar an authority can hold you to is the same as for any manufacturer.
One product. One engineer. A defensible programme.
Bring a single product and we'll show you what a small-team CRA programme looks like on your own code — evidence-backed VEX and a reportability shortlist, no team required.
Limited design-partner slots · EU-hosted · priced per product, not per developer