Cyber Resilience Act (CRA) Compliance Lawyer in Spain

24 hours to report an exploited vulnerability. Who does it in your company?

If you manufacture connected products or sell them under your own brand, the Cyber Resilience Act has required you since 11 September 2026 to send an early warning within 24 hours of becoming aware of an actively exploited vulnerability. We help you classify your products, set up the reporting process and adjust your contracts with suppliers, so that your new products reach December 2027 ready for CE marking.

Request a free initial assessment. We will tell you whether your products fall within the regulation, in which category and what you need to do now.

No commitment · We reply the same day

    YEARS OF EXPERIENCE

    + 0

    CLIENTS ADVISED

    + 0

    PROJECTS COMPLETED

    + 0

    PRACTICE AREAS

    + 0

    WHAT SETS US APART

    The CRA Is Met in the Code and Decided in the Contract

    We reply the same day

    CYBER RESILIENCE ACT LEGAL SERVICES

    What Does Your Company Need to Comply with the CRA?

    Legal advice on product cyber resilience, the supply chain and regulatory compliance for companies that manufacture or sell technology in the European Union.

    We determine whether each product falls within the regulation or one of its exclusions, and in which category: default, important class I or II under Annex III, or critical under Annex IV. The classification, together with the harmonised standards you apply, decides whether self-assessment is enough or a notified body is needed.

    We design the internal process to meet the Article 14 deadlines: early warning within 24 hours, notification within 72 hours and a final report, through ENISA’s single reporting platform, with INCIBE as Spain’s coordinating CSIRT. It includes the coordinated vulnerability disclosure policy.

    We prepare and review the technical documentation, the EU declaration of conformity and the file that supports the CE marking, and we assist you in dealing with the notified body where the product’s category requires one.

    We review contracts with manufacturers, component suppliers and distributors: who is liable as manufacturer, how vulnerabilities are shared, what support period is taken on and what assurances are requested on the third-party software built into the product.

    We analyse your current catalogue. Products placed on the market before 11 December 2027 are outside the essential requirements unless they are substantially modified, but the reporting obligation already covers all of them, however old they are.

    SECTORS AND COMPANIES

    Do You Manufacture or Sell Products with Digital Elements?

    We advise companies with these profiles on the Cyber Resilience Act.

    IoT and Smart Home

    Cameras, locks and connected devices

    Software and Apps

    Programs and applications placed on the market

    Importers and Own Brands

    Products made elsewhere and sold under your brand

    Consumer Electronics

    Hardware distribution in the EU

    Hardware Start-ups

    Connected products from the first prototype

    PROCESS AND TIMELINES

    How We Work

    From first contact to compliance, in 4 steps

    1 –

    Scope diagnosis

    We review your catalogue and tell you which products fall within the regulation, which are excluded and whether in any case you are liable as manufacturer without being one. No cost and no commitment.

    2 –

    Classification and map of obligations

    We classify each product, set the conformity assessment route and give you the timeline of what you need to have ready and by when.

    3 –

    Compliance plan

    Reporting protocol, vulnerability disclosure policy, technical documentation, support period and clauses with suppliers and distributors.

    4 –

    Support until December 2027

    We follow the implementing acts, the harmonised standards and the designation of authorities in Spain, and we assist you whenever a vulnerability or an incident has to be reported.

    REVIEWS AND RATINGS

    What Our Clients Say

    cybersecurity and product cyber resilience services
    Dimas Pérez
    1 Reseña
    Marta combines impeccable professionalism with a remarkable ability to explain complex legal concepts in simple terms...
    Roberto Fernandez
    3 Reseñas
    Impeccable personal attention, availability and human touch. Broad knowledge and experience in the sector. Outstanding at solving problems. 100% recommended...
    Alina
    1 Reseña
    I have no words to express my sincere gratitude. Marta is a very dedicated and empathetic professional. She also works fast...
    Gregorio Gigorro
    1 Reseña
    Thank you so much, Marta, for your invaluable advice. Without your knowledge of NFT technology in the art market, a new and promising field but one exposed to a lot of fraud, I would have got myself into serious trouble. Marta …

    REGULATORY FRAMEWORK

    The Cyber Resilience Act in Spain and the EU

    Regulation (EU) 2024/2847, known as the Cyber Resilience Act, has been in force since 10 December 2024 and applies in phases. The rules on notified bodies have applied since 11 June 2026; the obligation to report actively exploited vulnerabilities and severe incidents since 11 September 2026; and full application arrives on 11 December 2027, with the essential requirements of Annex I and CE marking. We explain it in detail in our guide to what the Cyber Resilience Act is and which companies it covers and in our guide to vulnerability reporting.

    It is a regulation, so it applies directly in Spain with no need for a transposing law. What is still pending is the formal designation of the national authorities and of the penalty procedure: the draft royal decree assigns market surveillance to the Secretary of State for Telecommunications and Digital Infrastructure and the role of notifying authority to the National Cryptologic Centre (CCN). For reporting, by contrast, there is already a channel: INCIBE appears on ENISA’s list as Spain’s coordinating CSIRT.

    Fines can reach 15 million euros or 2.5 % of total worldwide annual turnover, whichever is higher, for breaching the essential requirements or the obligations in Articles 13 and 14. These are maximum amounts set by the regulation; the fact that the designation of authorities is still pending does not suspend any obligation. The CRA coexists with the NIS2 Directive: NIS2 governs essential and important entities in critical sectors, while the CRA governs the products placed on the market.

    FAQ

    Frequently Asked Questions on the Cyber Resilience Act

    Any product with digital elements, hardware or software, that is made available in the EU and whose intended purpose or reasonably foreseeable use includes a direct or indirect, logical or physical data connection to a device or network falls within it. Products already governed by another specific EU law are excluded, such as medical devices and in vitro diagnostic devices, motor vehicles subject to type-approval, certified aviation products and marine equipment, as well as identical spare parts and products developed exclusively for national security or defence. If the product falls within it, its category depends on its core functionality.

    Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products, with an early warning within 24 hours and a notification within 72. This obligation also covers products that were already on the market. The remaining requirements, including CE marking, apply from 11 December 2027.

    In general, no: pure SaaS is outside it and falls under NIS2 where applicable. The exception is remote data processing that forms part of a product: processing that the manufacturer designs and develops, or has designed under its responsibility, and without which an application or device could not perform one of its functions. That component is assessed together with the product.

    Four things: who acts as manufacturer for the purposes of the regulation, especially if you sell under your brand a product made by someone else or substantially modify it; how and how quickly the supplier informs you of vulnerabilities in its components, because your 24-hour clock starts when you become aware of them; what support period it takes on; and who is liable if a third-party component causes an incident.

    Three tiers, and in each one the higher figure applies: up to 15 million or 2.5 % of total worldwide annual turnover for breaching the essential requirements and the obligations in Articles 13 and 14; up to 10 million or 2 % for breaching the other obligations, including those of importers and distributors; and up to 5 million or 1 % for supplying incorrect, incomplete or misleading information to notified bodies or authorities. Microenterprises and small enterprises cannot be fined for missing the 24-hour early warning deadline, but they can be fined for not reporting.

    Products placed on the market before 11 December 2027 do not have to meet the essential requirements of Annex I, unless they are substantially modified after that date. The obligation to report actively exploited vulnerabilities and severe incidents, by contrast, has applied to all of them since 11 September 2026, regardless of when they were sold.

    REQUEST YOUR ASSESSMENT

    Request a free initial assessment and receive a diagnosis of how your products fit within the Cyber Resilience Act, their classification and the steps you need to take before December 2027.