From 11 December 2027, every product with digital elements placed on the EU market must meet the Cyber Resilience Act. For an established life-science OEM, the exposure is rarely a single product. It is a portfolio built up over decades: instruments, analyzers, detection and sample-handling systems, and the embedded and companion software that runs them, much of it written long before “secure by design” was a phrase. TotalLab modernizes that software across your portfolio, so you keep your hardware, keep your compliance, and keep selling into Europe.
The CRA clock is already running
11 June 2026 — Notified bodies and member-state provisions come into effect, so the assessment infrastructure starts standing up.
11 September 2026 — Mandatory vulnerability and incident reporting begins. Actively exploited vulnerabilities must be reported within 24 hours, and this applies to your existing fleet, not just new products.
11 December 2027 — Full enforcement. Essential requirements, conformity assessment and CE marking apply to everything you place on the EU market. Penalties reach up to €15 million or 2.5% of global annual turnover.
Guidance only, not legal advice. Verify obligations against Regulation (EU) 2024/2847.
If you carry a legacy portfolio, the CRA applies right across it
If you manufacture life-science equipment or software of any kind, and any product carries a digital element placed on the EU market, the CRA is now your regulation to meet. For a large OEM that can mean dozens or hundreds of product lines, many of them long-lived, revenue-generating systems still shipping today.
The risk almost always sits in the software, and the warning signs repeat across an estate. Products run on outdated, unsupported frameworks. There is no Software Bill of Materials, so nobody has a complete view of the open-source and third-party components inside each product. There is no documented vulnerability handling process, and no secure mechanism to push updates to units already installed in the field. That worked for years. It will not clear the CRA.
Keep your hardware. Modernize the software around it.
Your equipment is mechanically sound and commercially valuable, and the CRA does not require you to scrap it. It requires the software wrapped around it to meet modern cybersecurity requirements. That turns a daunting, portfolio-wide regulation into a series of practical, product-by-product decisions:
- Remediate the existing software where the codebase is sound enough to bring up to standard.
- Redevelop the software, and keep the hardware, where the legacy code cannot get there.
- Retire or replace a product where neither option makes commercial sense.
We help you make that call honestly for each product, then we do the work.
Built for portfolios, not just single products
Bringing one product into compliance is a project. Bringing a portfolio into compliance is a program, and that is what we are set up for. We inventory and classify your entire estate, prioritize it by regulatory risk and commercial value, and work through it product by product against a single roadmap to December 2027, with the capacity to run multiple work streams in parallel. You get one partner accountable for the whole program, not a compliance problem multiplied across every SKU you sell.
What we do
Free CRA gap analysis and readiness audit. A structured review of your in-scope portfolio, a classification of each product (Default, Important or Critical), and a prioritized roadmap to December 2027. No commitment, no sales hand off, just clarity.
SBOM generation. Machine-readable Software Bills of Materials for each product, giving you and the regulator a complete, maintained view of every component you ship.
Legacy software remediation and modernization. Where code can be remediated, we remediate it. We close security gaps, replace unsupported dependencies and bring the software up to the CRA’s essential requirements without disrupting the workflows your customers rely on.
Secure-by-design redevelopment. Where a legacy codebase cannot get there, we rebuild the software around your existing hardware, engineered secure by design and secure by default from the start.
Compliance documentation and CE marking. The technical file, cybersecurity risk assessment and EU Declaration of Conformity, prepared and ready for CE marking under the CRA.
Ongoing vulnerability management. Coordinated disclosure, security updates across the support period, and 24 and 72-hour incident reporting workflows, so you meet your obligations after launch, not just at it.
CRA compliance is custom software development, done by specialists
Meeting the CRA is not a checkbox exercise or a bolt-on. It is custom software engineering on real, shipping products, and it is exactly the work TotalLab has done for the world’s largest life-science OEMs for over two decades. You may well have used our software before without ever knowing it was ours, because everything we build for OEM partners ships white-label under your brand.
That heritage matters here. We have spent more than 24 years building software that meets and exceeds 21 CFR Part 11, GMP and Annex 11 requirements, so regulated, audited, documented development is our normal. CRA readiness draws on the same discipline, the same secure-development practice, and in many cases the same foundations as our AuditSafe platform, which already maps onto much of what the CRA now asks for. In short: this is our core custom development work, pointed at your CRA problem, at portfolio scale.
How an engagement works
- Free CRA readiness audit. We review your in-scope products and tell you where you stand.
- Roadmap and scoping. A prioritized, dated plan per product, and a clear remediate-or-redevelop decision.
- SBOM and reporting readiness. We build your Software Bills of Materials and stand up your reporting workflows.
- Secure development and validation. We remediate or rebuild the software, engineered and tested to the essential requirements.
- Documentation and conformity assessment. We prepare the technical file and conformity evidence, ready for CE marking.
- Ongoing support and maintenance. Security updates and incident reporting across the product’s support period.
Why life science OEMs choose TotalLab
Life science specialists, not generalists. Our team pairs deep life-science domain knowledge with regulated software engineering, so we understand both your equipment and your customers’ workflows, whatever the modality.
24+ years of regulated software. We have delivered compliant software for the world’s largest life-science OEMs and pharma companies for over two decades, in the most heavily regulated corners of the industry.
Portfolio-scale capacity. We are built to take on whole estates, running parallel workstreams so a large portfolio still hits the deadline.
An AuditSafe head start. Our existing 21 CFR Part 11 and GMP platform maps directly onto CRA requirements, so most OEMs start from further along than they expect.
White-label, always. Everything we build ships under your brand. We stay invisible; your customers see your product.
You almost certainly have less time than you think
A typical CRA modernization program runs nine to eighteen months. The OEMs starting conversations now will comfortably hit the December 2027 deadline. The ones who wait will quietly stop being able to ship into Europe. Twelve months feels like a lot. With classification, SBOMs, remediation and conformity all to do, it isn’t.
Frequently asked questions
Does the CRA really apply to our products? If a product has any digital element and you place it on the EU market, almost certainly yes. Instrument firmware, embedded software and companion applications are all in scope, across your whole portfolio. The free readiness audit confirms exactly which of your products are affected and how each is classified.
We have a huge legacy portfolio. Can you handle that scale? Yes. We are set up to take on whole estates: we inventory and classify every product, prioritize by risk and commercial value, and run multiple remediation workstreams in parallel against one roadmap. One partner, accountable for the whole program.
What happens if we do nothing? From September 2026 you carry reporting obligations on products already in the field, and from December 2027 non-compliant products cannot legally be placed on the EU market. Penalties reach up to €15 million or 2.5% of global annual turnover. In practice, the commercial risk is simple: products drop out of Europe.
Do we have to rebuild everything from scratch? No. Wherever the existing code can be brought up to standard, we remediate rather than rebuild, so you protect your investment. We only redevelop where the legacy software genuinely cannot meet the requirements, and even then we keep your hardware.
How long does it take? A single product typically runs nine to eighteen months; a large portfolio runs as a phased program. That is why starting the readiness audit now matters.
Will our customers know TotalLab was involved? No. Everything we deliver is white-label under your brand. We stay invisible by design.
How does this relate to 21 CFR Part 11 and Annex 11? Closely. The secure-development, documentation and audit discipline the CRA expects is the same discipline we have applied to 21 CFR Part 11, GMP and Annex 11 work for years. If your products already meet those standards, you have a head start, and we know exactly how to build on it.
We are not an EU company. Are we still affected? Yes. The CRA applies to any product placed on the EU market, wherever the manufacturer is based. If you sell into Europe, it applies to you.
Ready to find out where you stand?
A free audit. No commitment. Just clarity. In one discovery call you will leave with a view of which products across your portfolio are in scope, how each is classified, whether to remediate or redevelop, a prioritized roadmap to December 2027, and an honest estimate of the work involved.