EU Regulation 2024/2847

Cybersecurity just became a CE-marking requirement.

The Cyber Resilience Act extends the CE mark — until now mainly a physical and electrical safety signal — to cover cybersecurity for connected products: technical documentation, conformity assessment, and statutory reporting clocks included. We help manufacturers get there, the same way we've helped them through ISO 26262, EN 50128/50129 and DO-178C.

The clock is already running

Not a future abstraction — a set of dates already in motion.

The reporting duty covers products already on the EU market, not just new launches — many manufacturers don't realize legacy product lines are already in scope. As of today, the reporting deadline is weeks away, and most have not operationalized it.

10–11 Dec 2024

Regulation (EU) 2024/2847 enters into force.

11 Jun 2026

Chapter IV applies — notified and conformity assessment bodies come online.

11 Sep 2026

Reporting obligations apply (Art. 14): actively exploited vulnerabilities and severe incidents, via ENISA'sENISA — the EU's cybersecurity agency, which runs the reporting platform manufacturers must use. Single Reporting Platform.

Next up
11 Dec 2027

Full application: Annex IAnnex I — the CRA's essential cybersecurity requirements for the product itself and for the manufacturer's processes. essential requirements, CE marking, technical documentation, EU Declaration of Conformity, coordinated vulnerability disclosure.

24hEarly warning to the national CSIRTCSIRT — Computer Security Incident Response Team, the national body that handles cybersecurity incidents. and ENISAENISA — the EU's cybersecurity agency. once a vulnerability or incident is identified.
72hFull notification with an initial assessment, severity and — where relevant — indicators of compromise.
14d / 1moFinal report: 14 days for exploited vulnerabilities, one month for severe incidents.
Is this you?

Self-qualification, not a sales pitch.

Run through it yourself — on the left as a checklist, on the right as a 30-second check.

  • You place hardware, embedded software, or connected devices on the EU market.
  • You act as a manufacturer, importer, or distributor — or steward an open-source component inside a commercial product.
  • Some of the affected products are already on the market — not just next year's launches.
  • Cybersecurity today lives in IT policy, not in your product development or safety lifecycle.
Some categories sit under a dedicated regime instead — medical devices, or vehicles under type-approval, for example. Which parts of your product fall under CRA versus an existing regime is itself a question worth answering first, especially in automotive and space/defense programs.
60-second check

Where does your product likely stand?

1. Does it connect to a network, exchange data, or run software?

2. Do you manufacture, import, or distribute it commercially in the EU?

3. Is it already covered by a dedicated regime (e.g. medical devices, vehicle type-approval)?

What we assess

One maturity model, five pillars, scored against the CRA's essential requirements.

Our gap and maturity assessment benchmarks current practice on a 1–5 scale across five domains — covering the essential cybersecurity requirements in Annex IAnnex I — the essential cybersecurity requirements for the product and for the manufacturer's processes., the user information and instructions in Annex IIAnnex II — the information and instructions that must ship with the product (contact points, support period, secure use, etc.)., and the technical documentation in Annex VIIAnnex VII — the technical documentation manufacturers must keep on file, e.g. design, risk assessment, and vulnerability handling. — so the roadmap that follows is prioritized rather than generic.

01

Governance & Documentation

Approved product security policies, clear ownership, and technical documentation that's actually kept current.

02

Risk Management & Security-by-Design/Default

Risk assessments that shape design decisions, and products shipped secure by default, not hardened after the fact.

03

Vulnerability & Patch Management

A disclosure process, an SBOMSBOM — Software Bill of Materials: a list of the components inside your software, so vulnerabilities in them can be tracked. you can trust, and update mechanisms that actually reach fielded products.

04

Product Lifecycle Management

Security carried through from concept to end-of-support, with defined support periods and retention.

05

Awareness, Competence & Skills

Engineering, product and quality teams who know what CRA asks of them — not just a policy on a shelf.

Where we bring this in

Four domains where we already build the rest of the product.

We're an engineering provider first — functional safety, software, AI and cybersecurity under one roof — which is why CRA lands as an extension of work already underway, not a bolt-on from a consultancy that has never touched your codebase or your safety case.

Automotive & Commercial Vehicles

Tier 1/2 suppliers already running ISO 26262 — we extend into ISO/SAE 21434 and CRA reporting without duplicating the existing safety process.

Railway & Signaling

Signal and control system suppliers already under EN 50128/50129 — CRA readiness folds into that same lifecycle, aligned with TS 50701, from secure boot and update mechanisms to security-by-design in ongoing development.

Space & Defense

Export-control and dual-use sensitivities mean scope isn't always obvious — and some products sit under separate regimes. That's a question we answer with you, not for you, working inside your existing classification and export-control handling rather than asking you to route sensitive data around it.

Industrial & Connected Products

Machinery, industrial IoT and smart building components from teams with functional-safety-adjacent culture but limited in-house cybersecurity capacity.

How we work with you

A phased engagement, integrated into your lifecycle — not bolted onto it.

01

Applicability & Scoping

Which products fall under CRA, at what risk class, and whether self-assessment or third-party conformity assessment applies — including the boundary against existing regimes such as vehicle type-approval.

Output: a documented applicability analysis with product type, risk class and recommended path.
02

Gap & Maturity Assessment

Current practice benchmarked against the CRA's essential requirements — Annex IAnnex I — the essential cybersecurity requirements for the product and for the manufacturer's processes., plus the documentation obligations in Annex IIAnnex II — user information and instructions that must ship with the product. and VIIAnnex VII — the technical documentation manufacturers must keep on file. — across the five pillars above: governance, risk management, vulnerability & patch management, lifecycle, and skills.

Output: a scored maturity baseline and a prioritized gap list.
03

Remediation Roadmap

Fixes folded into your existing safety and quality lifecycle: SBOMSBOM — Software Bill of Materials: an inventory of the components inside your software., secure-by-design and secure-by-default gates, and a CE marking pathway you can actually follow.

Output: a roadmap sized to your product, team and budget.
04

Ongoing Vulnerability Management & Reporting

A retainer that rehearses and runs the 24h / 72h / 14-day cascade through ENISA'sENISA — the EU's cybersecurity agency, which runs the reporting platform. Single Reporting Platform, plus continuous vulnerability tracking as products stay on the market.

Output: a reporting playbook your team can execute under pressure.
Why FEV

Cybersecurity from people who already build safety-critical products.

Broad engineering competence, in one place

Functional safety, software, AI and cybersecurity sit under one roof. Most firms cover one of these well; we cover all four for the same product, which is what CRA actually requires.

Built into the lifecycle you already run

CRA readiness lands inside your existing safety and quality process instead of running as a parallel program.

Delivery model built for regulated industries

An international engineering-services delivery model, with a track record across automotive, railway, space and defense — domains where "trust us" was never good enough.

An entry point that grows with you

CRA readiness naturally leads into further work as products stay on the market — vulnerability management, SBOMSBOM — Software Bill of Materials: an inventory of the components inside your software. tooling and secure boot among the common next steps, but rarely the only ones.

Start here

Start with a half-day, not a program.

The CRA Applicability & Maturity Workshop is the low-commitment first step: we scope which products are affected, baseline your maturity across the five pillars, and leave you with a prioritized roadmap sketch — before anyone talks about a larger engagement.

Book a workshop
Half or full dayon-site or remote
No commitmentto a larger program required
Cross-domainautomotive, railway, space & defense, industrial
You'll be working with
[Name placeholder]
CRA Lead, Cybersecurity
[Name placeholder]
Functional Safety & Compliance Lead
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.