CRA consulting vs CVD Portal
Expert-led CRA readiness delivered as an engagement rather than as a system. How does CRA consulting compare to CVD Portal for an EU manufacturer subject to the Cyber Resilience Act?
- Provider
- Independent firms, EU-wide
- Category
- Advisory engagement
- Pricing model
- Day rates or fixed-scope project fees, quoted per engagement and quoted again for each additional product.
How they compare on CRA-critical features
Five places where an engagement and a system behave differently under Regulation (EU) 2024/2847. This is about the delivery model, not about competence.
Where CRA consulting is strong
- +Judgement on the calls that are genuinely arguable. Classification edge cases, risk acceptance criteria and how far state of the art reaches are reasoned positions, not lookups.
- +Sector experience. An adviser who has taken comparable products through conformity knows what an assessment body pushes back on.
- +Coverage beyond the CRA, including the Machinery Regulation, RED and medical device rules, and how they interact on one product.
- +Capacity. Someone else does the work, which matters most in a company that has nobody to assign it to.
Where the engagement model strains
- !The deliverable is accurate on the day it is handed over. The obligation is continuous, and Article 31(2) expects the technical documentation to stay up to date at least through the support period.
- !Cost scales with repetition. Each additional product, each substantial modification under Article 3(30) and each re-assessment is another engagement.
- !Article 14's clock is operational rather than advisory. A 24-hour early warning cannot wait for an adviser to have availability.
- !State ends up spread across the adviser's templates, a shared drive and email, so there is no single place where current status can be shown to an authority or a notified body.
- !The reasoning behind a decision leaves with the engagement unless something on the manufacturer's side records why a requirement was marked not applicable.
The CRA gap
A consultancy closes the knowledge gap and produces the file. What it cannot do is hold the file true afterwards. The CRA's duties run for the whole support period. Technical documentation has to stay current under Article 31(2), vulnerability handling under Annex I Part II continues for as long as the product is supported, and Article 14 reporting starts inside 24 hours of learning that a vulnerability in the product is being actively exploited. Those are operating obligations, and an engagement ends.
Why teams pick CVD Portal for CRA
Five reasons EU manufacturers put a system underneath the advice. Most keep both.
- 1
The file stays live. Classification, Annex I applicability, evidence and the technical documentation are one record with review cycles rather than a document set that ages quietly.
- 2
Article 14 runs on in-product timers, so the 24-hour early warning does not depend on anyone's availability.
- 3
Every additional product is included rather than re-quoted, which is where consulting cost concentrates for a multi-product manufacturer.
- 4
Justifications are captured where the decision is made, so the reasoning behind a not-applicable marking survives staff turnover and the end of an engagement.
- 5
The two combine cleanly. Advisers use the platform as the system of record for their clients, and the partner programme exists for exactly that.
Frequently asked
Should we hire a consultant or buy a platform?
We already paid for a CRA readiness assessment. Was that wasted?
Our consultant would rather we did not use a platform.
Can a platform make the judgement calls a consultant makes?
What happens when a notified body is required?
Keep what the engagement produced, and keep it current
Import the existing file, then hold it against the clock. Article 31(2) expects the technical documentation to stay accurate through the support period, and this is where it lives between engagements.