BOOK ONLINE DEMO!
Skip to main content

Cyber Resilience Act and configurators: Why CRA-compliant software is now becoming a competitive advantage

How Resolto provides CONFIGON in CRA-compliant form and supports companies in making their own product processes fit for the future
 

Cyber security is becoming a core part of product responsibility for companies. With the Cyber Resilience Act (CRA), the European Union is creating a binding framework for products with digital elements. For manufacturers, integrators, distributors and operators, this means that digital products will in future need to be not only high-performing and user-friendly, but also securely developed, documented, updated and supported throughout their life cycle.

For companies with complex products, this raises two questions: how can they ensure that the digital tools they use themselves meet the new requirements? And how can these tools help make their own product, variant and documentation processes CRA-ready?

This is precisely where Resolto comes in with CONFIGON. CONFIGON is the configurator solution for complex products, variants and applications. As a software solution, CONFIGON is provided with the relevant requirements of the Cyber Resilience Act in mind and is being continuously developed. At the same time, CONFIGON supports companies in making product data, variant logic, technical dependencies and documentation processes more transparent, consistent and traceable.

In short: CONFIGON is not only a tool that helps companies manage CRA-related complexity. CONFIGON is itself part of a modern approach to cyber-resilient software responsibility.
 

What is the Cyber Resilience Act?
 

The Cyber Resilience Act is an EU regulation for products with digital elements. This includes hardware and software products that are directly or indirectly connected to devices or networks and exchange data. The aim of the CRA is to make cyber security more binding across the entire product life cycle – from development and placing on the market to updates, vulnerability management and support.

The CRA’s key obligations apply from December 2027. Certain requirements, particularly reporting obligations for actively exploited vulnerabilities and severe security incidents, take effect earlier. Companies should therefore not wait until shortly before the deadlines to begin preparing. Product data, development processes, technical documentation, update mechanisms and responsibilities cannot be adapted overnight.

The CRA therefore changes not only technical security requirements. It also changes the way companies develop, market, document and support digital products.
 

Why the CRA is also relevant for configurators
 

A product configurator today is much more than a digital sales tool. In many companies, it is a key interface between product management, sales, engineering, procurement, manufacturing and the customer experience. It guides users through variants, checks technical rules, processes product data, generates quotations, bills of materials or technical documents, and connects to systems such as PIM, ERP, CRM or webshops.

This makes a configurator relevant to the CRA in two ways.

First, the configurator is itself software. When a configurator solution is provided as a digital product, it must be securely developed, documented, maintained and updated in line with the applicable requirements. This includes professional handling of vulnerabilities, traceable update and support processes, secure interfaces and transparent technical documentation.

Second, a configurator helps companies make their own product processes more CRA-ready. This is because the CRA requires not only secure products, but also clear information, traceable decisions and robust processes. To achieve this, companies need structured data, consistent rules and a reliable link between product knowledge and operational implementation.
 

Outlook: CONFIGON as a CRA-compliant configurator solution
 

Resolto will provide CONFIGON as a secure and future-proof configurator solution, consistently aligning development, deployment and support with the relevant requirements of the Cyber Resilience Act. In doing so, we take responsibility for the security of our own software – and create a reliable foundation on which our customers can further develop their digital product and sales processes.

For CONFIGON, this includes, among other things:

  • secure development and deployment processes,
  • controlled handling of vulnerabilities and security updates,
  • transparent support and life-cycle structures,
  • technical documentation for the software solution,
  • secure and traceable interfaces,
  • clear roles and processes for operation, maintenance and ongoing development.

Resolto is therefore taking an important step beyond the pure functionality of a configurator. CONFIGON is seen not only as a powerful product configuration solution, but as a software product that meets the rising demands placed on cyber resilience and digital product responsibility.

This is particularly important for customers: anyone using a configurator as part of central sales, engineering or manufacturing processes must be able to rely on the security and future viability of that solution. A CRA-oriented, CRA-compliant configurator solution reduces risks, builds trust and helps companies better achieve their own compliance and security goals.
 

What does this mean in practical terms for our customers?
 

For Resolto customers, the CRA primarily means that product data, configuration rules and technical documentation will become strategically more important. In future, companies will need to be even better able to understand which product variants are being offered, which components may be combined, which technical dependencies exist and which information is passed on to customers, internal systems or downstream processes.

CONFIGON supports precisely this. The solution digitally maps complex products, variants and rules. Users are guided through the configuration, invalid combinations can be excluded and suitable options can be suggested in a targeted way. The result is configurations that are not only customer-friendly, but also technically plausible and process-reliable.

In the context of the CRA, this is particularly valuable because companies gain a better basis for transparency, documentation and life-cycle processes. CONFIGON helps ensure that product knowledge is not maintained in isolation in individual departments or files, but made usable in an end-to-end digital process.

Customers benefit in several concrete areas.
 

1. Greater security through reliable software
 

The first benefit lies in the configurator solution itself. Resolto provides CONFIGON as software designed for cyber resilience, maintainability and secure ongoing development. Companies receive a solution that is not only functionally compelling, but also prepared for the increasing regulatory requirements placed on digital products.

This builds trust – particularly when CONFIGON is integrated into critical business processes, such as sales, product management, manufacturing or quotation processes.
 

2. Greater transparency in product and variant processes
 

Complex products often consist of numerous options, dependencies, technical parameters and customer-specific requirements. Without digital support, disconnected systems, manual alignment and incorrect combinations can quickly arise.

CONFIGON makes this complexity manageable. Product rules, variant logic and technical dependencies are represented in the configurator. This enables companies to control more transparently which product combinations are possible, sensible or permissible.

This transparency is an important prerequisite for properly supporting CRA-relevant processes.
 

3. Consistent data instead of manual interim steps
 

CRA readiness depends heavily on how consistently and up to date product information is maintained. If data is entered multiple times, transferred manually or interpreted differently in different systems, risks arise.

CONFIGON can be connected to existing systems such as PIM, ERP, CRM or webshops. This makes it easier to link product information, prices, technical features, documents and follow-on processes. Configurations are not considered in isolation, but become part of an end-to-end digital data flow.

This reduces errors, accelerates processes and improves data quality.
 

4. A better basis for documentation
 

The CRA increases the importance of technical documentation. Companies must be able to understand how products are structured, which components they contain, which properties apply and which information is relevant for customers or internal processes.

CONFIGON helps companies automatically generate relevant documents and data from configurations – for example quotations, bills of materials, technical descriptions, drawings or other documents. Which documents are generated in each case depends on the specific project and system integration.

It is important to note that the configurator does not replace a legal or technical CRA conformity assessment for the customer’s products. However, it can create a significantly better basis for consistent, traceable and up-to-date product information.
 

5. Support for sales, engineering and manufacturing
 

In many companies, errors do not occur because specialist knowledge is lacking, but because that knowledge is not available everywhere at the right time. Sales, engineering and manufacturing often work with different systems, data statuses or documents.

CONFIGON brings this knowledge into a guided digital process. Sales staff and customers can configure products more easily. Technical dependencies are taken into account in the background. Downstream processes receive more structured data. Engineering and manufacturing benefit from fewer queries and more plausible starting data.

In this way, the configurator becomes a bridge between customer experience, technical feasibility and operational implementation.
 

What CONFIGON does not promise
 

A clear distinction is important: CONFIGON does not automatically make our customers’ products CRA-compliant. Responsibility for product design, risk assessment, technical documentation, vulnerability management, updates and conformity assessment remains with the respective manufacturer or the responsible party.

However, CONFIGON is an important building block for better preparing and operationally supporting these tasks. The solution helps digitally map product complexity, make configurations traceable, pass on data consistently and improve documentation processes.

In this way, CONFIGON supports companies on the path towards CRA-ready product and sales processes – without replacing the company’s individual assessment and responsibility.
 

Why companies should act now
 

The CRA will become binding for many companies in the coming years. Those who only begin shortly before the central obligations come into force risk time pressure, unclear responsibilities and high costs for rework.

It is therefore advisable to review the following at an early stage:

  • Which products, software solutions or digital components could potentially fall within the scope of the CRA?
  • What role does your own company play – manufacturer, integrator, distributor, importer or operator?
  • Which product data, variant rules and technical documents are already available in structured form today?
  • Where do process breaks occur between sales, product management, engineering and manufacturing?
  • Which digital tools must themselves be provided in a CRA-compliant form?
  • How can a configurator help manage product and process complexity more effectively?

These questions concern not only IT or security teams. They affect product management, sales, development, service, procurement and management alike.
 

Resolto as a partner for secure, future-proof configuration processes
 

Resolto combines technological expertise with a deep understanding of complex product and variant logic. With CONFIGON, Resolto offers a configurator solution that helps companies represent complex products in a comprehensible, rule-based and digitally integrated way.

In the context of the Cyber Resilience Act, this means two things:

First, Resolto will provide CONFIGON as a secure software solution aligned with CRA compliance. Our customers will therefore receive a configurator that takes account of the rising demands for cyber resilience, maintainability and digital product responsibility.

Second, CONFIGON supports companies in making their own product and variant processes more CRA-ready. Product data, rules, technical dependencies and documents are brought together in a consistent digital process. This creates a robust basis for transparency, traceability and efficient downstream processing.
 

Conclusion: using CRA-compliant software and creating CRA-ready processes
 

The Cyber Resilience Act makes one thing clear: cyber security is no longer an optional extra, but part of modern product responsibility. Companies must securely develop, provide, document and support digital products throughout their life cycle.

For configurator solutions, this means that they themselves must be provided securely and in CRA-compliant form. At the same time, they can help companies align their own product and variant processes more closely with the requirements of the CRA.

CONFIGON fulfils precisely this dual role. Resolto will provide CONFIGON as a secure, future-proof and CRA-oriented configurator solution and will support customers in making product complexity, variant logic and documentation digitally manageable.

This turns a product configurator into more than a sales tool: it becomes a building block for cyber-resilient, transparent and future-proof business processes.

 

Back