CRA compliance cost: what small manufacturers actually pay
An honest breakdown of CRA compliance cost for a small manufacturer — consultants and notified bodies vs a DIY open-source stack vs dedicated software — plus the real cost of non-compliance.
Not sure if you’re in scope?
Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.
Check if the CRA applies to youIn short
There is no single CRA compliance cost — it depends on the route you take. A consultant or notified-body route runs from low thousands to tens of thousands of euro, project-based, and suits complex or higher-class products. A DIY open-source stack has no licence fee but costs real engineering time to build and maintain. Dedicated software like Nordchecks is free during early access, then €99/month (Starter) or €249/month (Pro). Weigh all three against the cost of non-compliance: fines up to €15 million or 2.5% of turnover, plus market withdrawal.
“How much does CRA compliance cost?” is the question every small manufacturer asks, and the honest answer is that it depends entirely on how you get there. The same default-class product can cost you fifteen thousand euro or a few hundred, depending on whether you hire a consultant, build your own tooling, or use a dedicated tool. This guide breaks down the three realistic routes, what each actually costs in money and time, and who each one suits — then sets that against the cost of getting it wrong.
The figures below are indicative ranges, not quotes. Consultancy and notified-body fees vary widely by country, product complexity and scope, so treat them as an order of magnitude to plan around, not a price list.
Not sure the CRA applies to your product? Run the free 3-minute scope check first — it tells you your risk class, which drives most of the cost.
The three routes at a glance
| Route | Typical cost | Effort from you | Who it suits |
|---|---|---|---|
| Consultant / legal / notified body | Low thousands to tens of thousands of euro, project-based | Low — you supply information, they do the work | Complex products, Important/Critical classes, notified-body assessment, teams with budget but no time |
| DIY open-source stack | No licence fee — but real engineering hours to build and maintain | High — ongoing, falls on your developers | Teams with DevOps capacity and time, and appetite to own the tooling |
| Dedicated software (Nordchecks) | Free during early access; then €99/month (Starter) or €249/month (Pro) | Low to moderate — upload once, review monthly | Default-class small manufacturers who want it handled without hiring |
The rest of this guide unpacks each row honestly — including where the cheap-looking options hide their real cost.
Route 1: consultant, legal advice or notified body
This is the highest-cost route and, for the right product, the correct one. It splits into two kinds of spend.
Advisory work — a compliance consultant or law firm that assesses your product, determines scope and class, drafts your technical documentation and vulnerability-handling process, and guides you through the Declaration of Conformity. For a small manufacturer this is typically a project engagement running into the low-to-mid thousands of euro, more if your product is complex or you need ongoing retainer support. Day rates for specialist CRA consultants are not cheap, and a full documentation package is measured in days of their time.
Notified-body assessment — unavoidable for Important Class II and, in the form of European certification, for Critical products (hypervisors, hardware security modules, smartcards, smart meter gateways). This is a formal conformity assessment by an accredited body, and it is the most expensive line item on the CRA — comfortably into the tens of thousands of euro for a full assessment, plus surveillance over time. Default-class products (roughly 90% of all products) self-assess and need none of this.
Who it suits: genuinely complex products, anything in the higher risk classes, and teams that have budget but no engineering time to spare. If you build a firewall, a VPN or an HSM, this route is not optional — and paying for expertise is cheaper than getting a Class II assessment wrong. See our product classes guide to check which class you are in before you budget for this.
Route 2: the DIY open-source stack
On paper this route is free. Every core CRA task has a capable open-source tool behind it: Syft or cdxgen generate a CycloneDX or SPDX SBOM from your lockfiles; OSV and the NVD are free vulnerability databases you can query; a document template can hold your Annex VII technical file. No licence fee, no vendor.
The cost is real but hidden, and it is measured in engineering hours, not euro. Someone on your team has to:
- Wire the SBOM generation into each release so it never goes stale
- Run and update the vulnerability scanner, and — the genuinely hard part — filter the noise so you act on real critical and high findings instead of a wall of low-severity entries
- Record a triage decision for every finding so it becomes a compliance record, not a to-do list
- Keep the technical documentation and Declaration of Conformity mapped to the right release
- Build and rehearse the 24-hour reporting process by hand
Budget this honestly. The initial build is a few days of developer time; the maintenance is a few hours every month, forever, plus a scramble whenever a serious CVE lands. With the Black Duck (formerly Synopsys) OSSRA report finding an average of 581 vulnerabilities per commercial codebase (a figure that varies by year and report), the triage load alone is not trivial. At a loaded developer cost, that maintenance quietly adds up to more than a software subscription within the first year — which is exactly the trap: the free route is free in cash and expensive in the scarcest thing a small team has, engineering time. We cover this trade-off in depth in how to automate CRA compliance.
Who it suits: teams with real DevOps capacity, time to spare, and a genuine preference to own their tooling.
The free open-source route has no licence fee, but the SBOM wiring, scanner de-noising, triage records and document mapping fall on your developers every month, forever.
Nordchecks runs that whole chain for a fixed monthly price — SBOM per release, daily vulnerability matching, triage records and generated documents — so the hidden engineering cost disappears.
Try Nordchecks freeRoute 3: dedicated CRA compliance software
The middle route on cost and the lowest on effort is a purpose-built tool that does the four core jobs — SBOM, monitoring, reporting readiness and documentation — in one place and keeps them current automatically. This is what CRA compliance software is for: it turns the DIY stack’s recurring engineering work into a fixed, predictable line item.
Nordchecks is free during early access. After that, pricing is €99/month on the Starter plan (a single product) and €249/month on Pro (a product range). That is the whole cost — no per-assessment fee, no consultant day rate, no hidden maintenance hours. For a default-class small manufacturer, it replaces both the spreadsheet and the DIY scripts, and it is a fraction of a consultant engagement. If you are weighing it against tracking everything by hand, our Nordchecks vs spreadsheets comparison lays out the difference directly.
Who it suits: default-class small manufacturers — the ~90% who can self-assess — who want compliance handled continuously without hiring or building. It does not replace a notified body where your class requires one; nothing does.
The cost you cannot skip: non-compliance
Every budget conversation has to include the alternative. The CRA’s penalty ceiling is up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher, for breaching essential requirements. That is the ceiling, not the likely outcome for a good-faith small manufacturer — but the more probable costs are real and nearer to hand: a market-withdrawal or recall order that pulls your product from the EU market, and lost sales when a distributor or enterprise customer refuses to buy because you cannot produce a Declaration of Conformity or an SBOM. That last one is already happening in 2026, ahead of the deadlines. Our fines and enforcement guide explains how this plays out in practice.
Set against tens of thousands in withdrawal costs and lost contracts, every one of the three compliance routes above is cheap insurance. The real decision is not whether to spend, but which route fits your product’s class and your team’s time.
So what should you actually budget?
- Default-class product, small team, limited engineering time: dedicated software. Free now, then €99–249/month. Lowest total cost of ownership for most readers of this guide.
- Default-class product, strong DevOps team that wants to own tooling: the DIY stack — but budget the monthly maintenance hours honestly, because they are the real cost.
- Important Class II or Critical product, or genuine complexity: consultant plus notified body. Not optional, and worth every euro against the risk of a failed assessment.
Most small manufacturers reading this are default class, and for them the honest answer is that CRA compliance costs far less than the headlines suggest — provided you pick the route that matches your product instead of defaulting to the most expensive one.
Nordchecks keeps the SBOM, monitoring, reporting readiness and documentation current for a fixed monthly price, free during early access. See how it works →
Start with the free step: check your product’s scope and risk class in 3 minutes — it decides which route you actually need.