Ahead of the Curve: Pilot Your Path to CRA and EUCC Readiness
Ahead of the Curve: Pilot Your Path to CRA and EUCC Readiness
Join the TrustBoost pilot programme and gain practical experience with emerging European cybersecurity certification and compliance requirements.
The EU Cyber Resilience Act was proposed to provide harmonised rules when bringing to market digital products. This proposal aims to complement other EU laws on network and information security such as the NIS 2 directive and the Cybersecurity Act.
Under the Trustboost project, partners will conduct two pilot activities for ICT products, covering the CRA and EUCC. The CRA pilot will be a partial evaluation: as there is no official CRA certification scheme, it will focus on the applicable cybersecurity requirements in Annex I of the CRA and on the supporting evidence needed to demonstrate readiness. The EUCC pilot will follow the official EUCC scheme and is intended as a full evaluation and certification exercise. The consortium is looking to enrol organisations interested in participating in either scenario.

Participation offers vendors an opportunity to test their readiness in a practical setting and gain early experience with the evidence and interactions expected during evaluation and certification activities. The pilots can help participants identify gaps in technical documentation, security processes and product lifecycle practices, receive structured feedback, and reduce uncertainty and rework in future CRA compliance or EUCC certification activities. Participants will also have an opportunity to contribute practical industry experience to the Trustboost project while keeping vendor-specific information protected.
Participants are expected to have a sufficient level of maturity to make the pilot meaningful. This includes a working knowledge of the applicable legal and/or certification requirements, an established software development life cycle (SDLC) with cybersecurity activities integrated into development and maintenance, adequate technical and security documentation, and personnel available to provide evidence and engage with evaluators. Vendors should also be able to agree a realistic pilot plan and commit the necessary resources so that the relevant evaluation or certification is concluded by 31 May 2027 at the latest.
Interested organisations should submit a brief proposal describing the product/service, the preferred pilot scenario (CRA or EUCC), current compliance/certification maturity, availability against the above timeline, and reasons why they should be included in the pilot to Deploycyber@nsai.ie.
All information obtained through the application and pilot activities - including product/service information, documentation, evidence, test results, findings and other commercially or security-sensitive information - will be treated in strict confidence and will be subject to the applicable terms and conditions. Trustboost project deliverables will use only abstracted and generalised information. Any vendor-specific information that could identify a participant, product or individual finding will only be included subject to the relevant vendor's prior endorsement.
Further information regarding the EU certification schemes is available here.

