Skip to content

CRA for agencies and software service providers

Under the Cyber Resilience Act, the manufacturer is whoever places a product on the market under their own name or trademark, which for agency work is often the client. Agencies still need to deliver what clients need to comply: secure code, SBOMs, vulnerability handling and support over the support period.

Last updated:

Who is the manufacturer?

If you build an app or firmware that your client sells under its own brand, your client is usually the manufacturer and bears the CRA obligations. If you sell a product under your own name, you are the manufacturer. Pure SaaS projects are generally out of scope unless they are the remote data processing solution of a product with digital elements. See the CRA overview.

Topics for your contracts

  • Support period: who provides security updates for at least five years (or the expected use time), and at what cost.
  • Reporting: response times so the client can meet the 24h / 72h deadlines.
  • SBOM delivery: format, frequency and scope of the SBOM handed over with each release.
  • Vulnerability handling: who monitors, triages and fixes, and how evidence is documented.
  • Documentation: contributions to the technical documentation and risk assessment.

Per-repository pricing

Nuowei is priced per repository (Observe free for up to 4 repositories, Defend EUR 99 per month for up to 8 repositories plus EUR 5 per additional repository; Enterprise custom), so costs map to the client projects you run. See pricing.

CRA operations as a service

Many clients will not build CRA processes in-house. Agencies can offer ongoing monitoring, SBOM maintenance and vulnerability handling as a retained service, with Nuowei automating the recurring checks.

Nuowei is in beta and launches in November 2026. It does not certify products; legal responsibility remains with the manufacturer.

Join the waitlist

We launch in November. Be the first to get access.