At full delivery capacity until the end of 2026.
Build it secure. Sell it that way.
Security is becoming a purchasing criterion for products with software in them. We build resilience into the product and produce the evidence that turns it into something you can put in front of a buyer.
Whether the Cyber Resilience Act Cyber Resilience Act EU regulation for products with digital elements. Anyone placing hardware or software on the EU market must build security in, handle vulnerabilities for the product's support period, and prove both. reaches you, the role you hold in law, and your product class are answered free in the Discovery Calculator - including whether you can self-assess or need a notified body Notified body An independent organisation designated by an EU member state to assess whether a product meets the regulation's requirements. Only products in the higher CRA classes need one; most products can self-assess. . We never charge for scope.
Where This Fits
Who this is for
This is you
Your company
- You place hardware or software on the EU market
- Your product ships with firmware, a companion app, or a backend it cannot work without
- You sell a supplier's product under your own name
- You have engineers, but nobody owns product security
What is pushing you
- A customer questionnaire has started asking for an SBOM
- A distributor wants your Declaration of Conformity
- Procurement asks how long you will ship security updates
- A vulnerability report arrived and nobody owned it
How we do it
-
Instead of starting with a control framework and a big documentation project, we start from the product: how it is built, how it updates, what its real attack surface is.
-
Instead of charging you to work out whether the regulation applies, we answer scope, role, and product class free in the Discovery Calculator.
-
Instead of treating the CRA as paperwork, we treat the essential requirements as engineering: secure design, vulnerability handling, updates, testing.
The Problem
“We make machines, not software.”
Most companies in scope do not know they are in scope. They think of themselves as manufacturers, not as software companies.
- Your device has firmware. That is software placed on the EU market.
- You white-label a supplier's hardware under your own name. That makes you the manufacturer in law.
- Your product talks to a cloud backend it cannot work without. That backend is in scope too.
- Nobody has written a Software Bill of Materials, and the customer questionnaires have started asking for one.
The CRA is not NIS2. NIS2 secures your organisation. The CRA secures the thing you sell.
The Requirements
What the CRA actually requires
Your product must
- Ship with no known exploitable vulnerabilities
- Be secure by default, and resettable to that state
- Control access: authentication and identity management
- Protect the confidentiality and integrity of data
- Collect only the data it needs
- Limit attack surface and mitigate exploitation
Your process must
- Maintain an SBOM SBOM A Software Bill of Materials: a structured inventory of the components inside your software. The CRA requires one in a commonly used, machine-readable format covering at least top-level dependencies. in a commonly used, machine-readable format covering at least top-level dependencies
- Include regular security testing of the product
- Fix vulnerabilities without delay, and ship security updates separately from feature updates
- Run a coordinated vulnerability disclosure policy with a published reporting contact
- Keep this up for the whole support period, which reflects the expected product lifetime and is at least five years unless the product is expected to be in use for less
And you must prove it
- A technical file (Annex VII), drawn up before the product goes to market
- An EU Declaration of Conformity Declaration of Conformity A signed statement that your product meets the regulation's requirements. It backs the CE marking and you are legally accountable for what it claims. and CE marking
- Everything retained for 10 years, or the support period if that is longer
The Roadmap
Five phases
Map the product
What actually ships: firmware, applications, libraries, the backend the product needs. Your role in law and your product class are settled here.
Close the product gaps
Secure by default and resettable to it, no known exploitable vulnerabilities at release, access controlled, data protected and minimised, attack surface reduced.
Make vulnerability handling real
A published reporting contact, a disclosure policy people actually follow, triage with a named owner, and security updates that ship separately from features.
Build the evidence
SBOM, secure development records, test results, the support period you declare, the technical file, and the Declaration of Conformity behind your CE marking.
Keep it true
Obligations run for the whole support period. The retainer keeps the SBOM, disclosure process, testing, and technical file current as the product changes.
Start Here
How to start
The same four steps for every engagement here. You can stop after step two and owe nothing.
- 1
Run the Discovery Calculator
FreeAbout four minutes, no sign-up. It runs in your browser and nothing is sent anywhere unless you choose to send it.
- 2
Send me the result
FreeI reply with a recommendation for your situation - including when the honest answer is that you do not need me yet.
- 3
Starter Assessment (€1,900) or Starter Month (€2,900)
Fixed price, one-offThe paid entry, and the only one. It ends with a roadmap of the major milestones and a recommended retainer tier.
- 4
Continue on a retainer
From €950 a monthIf the roadmap makes sense to both of us, implementation runs inside the retained engagement. Part of what you paid for the starter door is credited against it.
How this becomes a retainer
CRA obligations do not close at a launch date: vulnerability handling, updates, testing and the technical file run for the whole support period. The starter door produces the roadmap; the retained engagement is where it gets built. One senior practitioner, a fixed monthly hour cap, and a tier set after the starter door rather than guessed before it.
What is not included
We do not sell CRA certification, and you should be careful with anyone who does: ask which harmonised standard they certify against. No legal advice, no notified body role. We do the engineering and the evidence; the Declaration of Conformity is signed by you.
What you get is not a certificate. It is a product that holds up in the field, and the evidence to say so.
Not sure the regulation reaches you at all? The calculator will say so, and you will have spent nothing. Longer answers live in the FAQ.