F.A.S. EST. 2026 FIRST ARTICLE SECURITY matt@firstarticle.ca Book the 20-min check
CRA reporting readiness — for CE-marked suppliers
First Article Security · Controlled document
Doc No.
FAS-WEB-001
Rev
B
Effective
2026-08-02

Your first 24-hour report shouldn’t be your first attempt.

If you hold a CE mark for the EU, the Cyber Resilience Act adds a new duty on top of it, and the reporting part starts first. We build it into the quality system you already certify against, and run each case through the corrective action process your team already knows.

Reporting duty begins · Art. 14
 
11 September 2026 · no grandfathering
What it covers
Products already in the field. No grandfathering (Art. 69(3))
How we do it
Inside your ISO 9001 system, as a corrective action
24 h
Early warning to the SRP
72 h
Vulnerability notification
14 d
Final report
Grandfathering for reporting
None — Art. 69(3)
Notified bodies designated today
0
CE marking under the CRA
Dec 2027 — reporting comes first

Verified 24 Jul 2026 · Regulations change; we re-verify before every engagement.

01

The offers: fixed prices, decision dates tied to 11 Sep

Tier 0 · Free · 20 min

Article 14 exposure check

$0

Twenty minutes on your product line and what you ship into the EU. You get a one-page memo within 48 hours telling you where you stand. We do not pitch you on the call.

Tier 1 · 3 to 5 days

SRP Readiness Sprint

$2,500 $3,500 Founding rate

Founding rate for the first three clients, in exchange for a named reference.

  • We work out which national contact point your report goes to, and prove the route works
  • A named reporter and a deputy, so someone is always on the hook
  • The 24 h / 72 h / 14 d runbook, with the forms already filled in
  • One dry run around a table before it counts
  • Evidence log opened
Tier 2 · 2 weeks

PSIRT-in-QMS Sprint

$14k–$18k

The whole thing built into your QMS: charter, intake, triage, disclosure policy, advisory templates, and the evidence pack an auditor will ask for. Mapped to IEC 62443-4-1 Practices 6 and 7.

After a sprint, most clients keep the process running on a part-time retainer. That conversation happens inside the sprint, not before.

02

An Article 14 report, run as a corrective action

One process, two audiences. Shown as an 8D because that is the corrective action method most quality departments already use. If yours runs 5-why, DMAIC, or your own CAPA form, the clocks and the evidence land the same way. Clause references point to our process map; they are not reproductions of the standard.

8D step (corrective action) CRA obligation Clock 62443-4-1 What gets produced
D0 Plan & intakeYou learn a vulnerability is being exploited. The reporting duty starts (Art. 14(1))24 hP6 · DM-1Intake record; early-warning submission to the SRP; clock log opened
D1 TeamA named reporter and deputy who can act inside the windowstandingP6 · DM-1RACI, on-call rota, escalation path
D2 DescribeVulnerability notification: nature, severity, affected products (Art. 14(2)(b))72 hP6 · DM-2/3Characterized defect: what, where, since when, exploitation status
D3 ContainInterim measures users can apply now; users informedASAPP6 · DM-4Mitigation advisory: workaround, configuration change, or restriction
D4 Root causeWhy it got in, and why nothing caught itn/aP6 · DM-3Systemic root-cause record, twice over
D5 Corrective actionA security update that addresses the verified causen/aP7 · SUMThe fix, qualified for the fielded fleet
D6 ValidateEvidence the fix closes the path it claims to closen/aP7 · SUMRegression run plus targeted re-test of the patched path
D7 Prevent recurrenceThe process fix behind the product fixn/aP6 · DM-5/6Updated coding standard, new CI detection, amended threat model
D8 Close & recognizeFinal report: description, severity, measures taken (Art. 14(2)(c))14 dP6 · DM-5Final report filed; reporter credited; the 8D record archived as audit evidence
03

Straight answers

We already hold a CE mark. Doesn’t that cover us?

Not for this. The CRA brings its own CE requirement in Dec 2027, but the reporting duty lands more than a year earlier, on 11 Sep 2026. That one has no grandfathering.

We’re ISO 9001 certified. Where does this actually live?

In the corrective action process you already have. Article 14 gives you a new trigger and three deadlines. The containment, root cause, and verification work is the same work your team does on any customer complaint. We are not asking you to stand up a second system beside your QMS.

Are you a notified body?

No. We are advisory only. You stay the manufacturer of record. We get you ready for whoever assesses you.

We’re a component supplier. Isn’t our customer the manufacturer?

If you put it on the EU market under your own brand, you are the manufacturer for that product. And your customers will push the requirement down to you either way.

Our products shipped years ago.

Product requirements are grandfathered to Dec 2027. Article 14 is not (Art. 69(3)).

Why fixed prices?

Because scoping surprises are a process failure.

04

Who runs this

Portrait — Matthew Macri
Fig. 1 — Principal
Principal

Matthew Macri

Matthew Macri built a CRA and IEC 62443 programme inside a BC industrial manufacturer, from nothing to a signed charter: intake, triage, disclosure, and the evidence trail behind them. He runs the process he sells. Based in British Columbia, works in client time zones.

ISA/IEC 62443 certification · in progress
05

Book the 20-minute exposure check

Twenty minutes, a straight read on where you stand, and a one-page memo within 48 hours. We do not pitch you on the call.

Prefer email

matt@firstarticle.ca — include your product line and where it ships; you’ll get times within one business day.

Booking

The calendar loads when you scroll here. If it does not, email works just as well.

Email instead