
Security & compliance
Get CRA compliant. Then stay that way.
The Cyber Resilience Act requires manufacturers of connected hardware and software products to meet specific cybersecurity obligations. Our three-phase service is designed for embedded systems running firmware or embedded Linux, IoT devices, industrial controllers, and hardware with connected software components.
Photo: almathias / Wikimedia Commons (CC0)
Three phases, in order.
Readiness assessment
Before anything can be fixed, we need to know where the problems are. A thorough review of three things: how your product is built, how secure it actually is, and whether the right processes and paperwork are in place. The result is a CRA Compliance Roadmap — a clear, prioritised action plan.
Secure SDLC implementation
Phase 1 gives you the roadmap. Phase 2 builds it: real, working security controls built together with your own engineering teams, one step at a time. A secure build pipeline, automated SBOM generation, a vulnerability handling process, the full documentation package, and a tested incident reporting procedure.

Security platform maintenance
Compliance is not a one-time check. New vulnerabilities surface every day in the open source software most embedded products run on. We list components after every build, scan against security databases, prioritise by how your product is actually used, agree the fix with you, then apply and test it.
CRA requirement met
What gets checked
- Secure by design
- Development process reviewed and scored
- Security risk assessment
- Product threats identified (STRIDE + EMB3D)
- Attack surface reduction
- Architecture weaknesses found
- Vulnerability handling processes
- Governance gaps identified
- Technical documentationArt. 13
- Documentation gaps identified
CRA requirement met
What gets built
- No known exploitable vulnerabilities
- Automated security checks in the build pipeline
- Software Bill of MaterialsAnnex I Part II 1
- SBOM generated and kept up to date
- Address vulnerabilities without delay
- Vulnerability fix process with response times
- Coordinated Vulnerability Disclosure
- Vulnerability disclosure policy published
- Secure update distribution
- Secure update delivery mechanism
- Market conformityArt. 28
- EU Declaration of Conformity signed
- Incident reportingArt. 14
- Incident reporting procedure tested
Ready to find out where you stand?
Talk with us about a CRA Readiness Assessment. Find out exactly what's between you and compliance, and what it'll take to close the gap.
Book an assessment