At full delivery capacity until the end of 2026.
Discovery Calculator
18 questions. A clear direction.
Compliance language is noisy. This short self-assessment cuts through it: answer honestly and get a recommended starting path - CIS Critical Controls for practical basics, NIS2 supplier readiness when the directive reaches you through your customers' contracts, or ISO 27001 when you want certification - plus the EU regulations worth checking.
If you place a product on the EU market, the same run answers your Cyber Resilience Act position: whether you are in scope, the role you hold in law, the product class that decides self-assessment against a notified body, and the practices you still need. That answer is free here - it is not something you should be paying a consultant to work out.
- About 4 minutes, no sign-up, no sales call required
- A framework recommendation with the reasoning behind it
- A free CRA scope, role, and product-class verdict if you sell a product
- Send your answers straight to Petr to start a focused first call
The Calculator
Find your starting path
Ready to start?
18 questions across 4 phases (plus five short follow-ups if you place a product on the EU market) - about 4 minutes. You get a framework recommendation and can send your answers directly to Petr before the call.
Your Security Path
NIS2 worth checking. Your sector, size, or supply-chain role may bring NIS2 into play - worth confirming whether you are directly in scope or pulled in through your customers' requirements.
What you still need
Your deadlines: vulnerability reporting obligations are already in force, including for products you have shipped. From 11 December 2027 a product that does not meet the requirements cannot be placed on the EU market. What CRA readiness involves →
Additional regulations to check
A note on budget. The retainer starts at about €11,400/year, so your figure sits below a continuous engagement. A one-off Starter Assessment (€1,900) is the right first step - but lasting security is a programme that runs, not a snapshot. One-time projects like a single pentest cost more and protect less. The strongest position is for management to allocate an annual security budget before we engage.
This is a starting point, not a contract. Real-world context - your stack, your customers, your risk appetite - shapes the actual path. The calculator gives you a direction to bring to the call. We agree the specifics together.