Sembra che tu preferisca leggere in italiano.

Passa all'italiano
CRA

"We're already ISO 9001": why it isn't enough for the CRA

29 July 2026·2 min read·Alberto Scarpa

Faced with a CRA that requires documented processes, nonconformity management, and internal audits, a certified manufacturer almost always reacts the same way: “we already have these things, we’re ISO 9001”. It’s half true. The quality management system is a concrete advantage, you already have the organisational backbone the CRA needs. But it’s also the source of the costliest illusion: thinking that “ISO 9001 compliant” means “almost CRA compliant”. It doesn’t. The difference lies in three processes the 9001 doesn’t provide, and if you don’t see them you end up exposed exactly where the CRA bites.

The full map — what you hook onto the quality system, what you build from scratch, and where the 9001 helps more than it seems — I’ve put in the guide CRA and ISO 9001: what to hook on and what to build. Here is the point that counts: the mistake I see recur.

Where reuse becomes dangerous

It’s not reusing the quality system too little, it’s reusing it badly, assuming that form equals substance. A nonconformity management process that measures time in weeks does not become an incident reporting process just because you write “cybersecurity” on top of it. The 24 hours of art. 14 don’t tolerate the rhythm of traditional quality. If you hook incident reporting onto the nonconformity cycle without redesigning timescales and responsibilities, you have a process that looks compliant on paper and collapses at the first real case.

The practical rule is simple: reuse the 9001 for the structure (documents, audits, review, suppliers, competences) and build new for the three processes that live in hours and look outside the company. Whoever confuses the two levels doesn’t save work: they find out too late, at the worst possible moment.

If you’re ISO 9001, you start with an advantage. But the advantage is the backbone, not the muscle, and the CRA’s muscle has to be built on purpose.


References: Regulation (EU) 2024/2847 (CRA), art. 14 and 16; ISO 9001:2015. The full CRA↔ISO 9001 map, with all the article and clause references, is in the linked guide.

Alberto Scarpa

AI · Cybersecurity · Regulation — I help industrial manufacturers integrate regulatory requirements into product decisions.

Not sure where to start?

45 free minutes to map your regulatory exposure — starting from what you've just read.

Book the Regulatory Spark