Cybersecurity just became a CE-marking requirement.
The Cyber Resilience Act extends the CE mark — until now mainly a physical and electrical safety signal — to cover cybersecurity for connected products: technical documentation, conformity assessment, and statutory reporting clocks included. We help manufacturers get there, the same way we've helped them through ISO 26262, EN 50128/50129 and DO-178C.
Not a future abstraction — a set of dates already in motion.
The reporting duty covers products already on the EU market, not just new launches — many manufacturers don't realize legacy product lines are already in scope. As of today, the reporting deadline is weeks away, and most have not operationalized it.
Regulation (EU) 2024/2847 enters into force.
Chapter IV applies — notified and conformity assessment bodies come online.
Reporting obligations apply (Art. 14): actively exploited vulnerabilities and severe incidents, via ENISA'sENISA — the EU's cybersecurity agency, which runs the reporting platform manufacturers must use. Single Reporting Platform.
Next upFull application: Annex IAnnex I — the CRA's essential cybersecurity requirements for the product itself and for the manufacturer's processes. essential requirements, CE marking, technical documentation, EU Declaration of Conformity, coordinated vulnerability disclosure.
Self-qualification, not a sales pitch.
Run through it yourself — on the left as a checklist, on the right as a 30-second check.
- You place hardware, embedded software, or connected devices on the EU market.
- You act as a manufacturer, importer, or distributor — or steward an open-source component inside a commercial product.
- Some of the affected products are already on the market — not just next year's launches.
- Cybersecurity today lives in IT policy, not in your product development or safety lifecycle.
Where does your product likely stand?
1. Does it connect to a network, exchange data, or run software?
2. Do you manufacture, import, or distribute it commercially in the EU?
3. Is it already covered by a dedicated regime (e.g. medical devices, vehicle type-approval)?
One maturity model, five pillars, scored against the CRA's essential requirements.
Our gap and maturity assessment benchmarks current practice on a 1–5 scale across five domains — covering the essential cybersecurity requirements in Annex IAnnex I — the essential cybersecurity requirements for the product and for the manufacturer's processes., the user information and instructions in Annex IIAnnex II — the information and instructions that must ship with the product (contact points, support period, secure use, etc.)., and the technical documentation in Annex VIIAnnex VII — the technical documentation manufacturers must keep on file, e.g. design, risk assessment, and vulnerability handling. — so the roadmap that follows is prioritized rather than generic.
Governance & Documentation
Approved product security policies, clear ownership, and technical documentation that's actually kept current.
Risk Management & Security-by-Design/Default
Risk assessments that shape design decisions, and products shipped secure by default, not hardened after the fact.
Vulnerability & Patch Management
A disclosure process, an SBOMSBOM — Software Bill of Materials: a list of the components inside your software, so vulnerabilities in them can be tracked. you can trust, and update mechanisms that actually reach fielded products.
Product Lifecycle Management
Security carried through from concept to end-of-support, with defined support periods and retention.
Awareness, Competence & Skills
Engineering, product and quality teams who know what CRA asks of them — not just a policy on a shelf.
Four domains where we already build the rest of the product.
We're an engineering provider first — functional safety, software, AI and cybersecurity under one roof — which is why CRA lands as an extension of work already underway, not a bolt-on from a consultancy that has never touched your codebase or your safety case.
Automotive & Commercial Vehicles
Tier 1/2 suppliers already running ISO 26262 — we extend into ISO/SAE 21434 and CRA reporting without duplicating the existing safety process.
Railway & Signaling
Signal and control system suppliers already under EN 50128/50129 — CRA readiness folds into that same lifecycle, aligned with TS 50701, from secure boot and update mechanisms to security-by-design in ongoing development.
Space & Defense
Export-control and dual-use sensitivities mean scope isn't always obvious — and some products sit under separate regimes. That's a question we answer with you, not for you, working inside your existing classification and export-control handling rather than asking you to route sensitive data around it.
Industrial & Connected Products
Machinery, industrial IoT and smart building components from teams with functional-safety-adjacent culture but limited in-house cybersecurity capacity.
A phased engagement, integrated into your lifecycle — not bolted onto it.
Applicability & Scoping
Which products fall under CRA, at what risk class, and whether self-assessment or third-party conformity assessment applies — including the boundary against existing regimes such as vehicle type-approval.
Output: a documented applicability analysis with product type, risk class and recommended path.Gap & Maturity Assessment
Current practice benchmarked against the CRA's essential requirements — Annex IAnnex I — the essential cybersecurity requirements for the product and for the manufacturer's processes., plus the documentation obligations in Annex IIAnnex II — user information and instructions that must ship with the product. and VIIAnnex VII — the technical documentation manufacturers must keep on file. — across the five pillars above: governance, risk management, vulnerability & patch management, lifecycle, and skills.
Output: a scored maturity baseline and a prioritized gap list.Remediation Roadmap
Fixes folded into your existing safety and quality lifecycle: SBOMSBOM — Software Bill of Materials: an inventory of the components inside your software., secure-by-design and secure-by-default gates, and a CE marking pathway you can actually follow.
Output: a roadmap sized to your product, team and budget.Ongoing Vulnerability Management & Reporting
A retainer that rehearses and runs the 24h / 72h / 14-day cascade through ENISA'sENISA — the EU's cybersecurity agency, which runs the reporting platform. Single Reporting Platform, plus continuous vulnerability tracking as products stay on the market.
Output: a reporting playbook your team can execute under pressure.Cybersecurity from people who already build safety-critical products.
Broad engineering competence, in one place
Functional safety, software, AI and cybersecurity sit under one roof. Most firms cover one of these well; we cover all four for the same product, which is what CRA actually requires.
Built into the lifecycle you already run
CRA readiness lands inside your existing safety and quality process instead of running as a parallel program.
Delivery model built for regulated industries
An international engineering-services delivery model, with a track record across automotive, railway, space and defense — domains where "trust us" was never good enough.
An entry point that grows with you
CRA readiness naturally leads into further work as products stay on the market — vulnerability management, SBOMSBOM — Software Bill of Materials: an inventory of the components inside your software. tooling and secure boot among the common next steps, but rarely the only ones.
Start with a half-day, not a program.
The CRA Applicability & Maturity Workshop is the low-commitment first step: we scope which products are affected, baseline your maturity across the five pillars, and leave you with a prioritized roadmap sketch — before anyone talks about a larger engagement.
Book a workshop