Skip to content
The Berlaymont in Brussels, seat of the European Commission

Security & compliance

Get CRA compliant. Then stay that way.

The Cyber Resilience Act requires manufacturers of connected hardware and software products to meet specific cybersecurity obligations. Our three-phase service is designed for embedded systems running firmware or embedded Linux, IoT devices, industrial controllers, and hardware with connected software components.

Photo: almathias / Wikimedia Commons (CC0)

Three phases, in order.

  1. Readiness assessment

    Before anything can be fixed, we need to know where the problems are. A thorough review of three things: how your product is built, how secure it actually is, and whether the right processes and paperwork are in place. The result is a CRA Compliance Roadmap — a clear, prioritised action plan.

  2. Secure SDLC implementation

    Phase 1 gives you the roadmap. Phase 2 builds it: real, working security controls built together with your own engineering teams, one step at a time. A secure build pipeline, automated SBOM generation, a vulnerability handling process, the full documentation package, and a tested incident reporting procedure.

  3. Cable network

    Security platform maintenance

    Compliance is not a one-time check. New vulnerabilities surface every day in the open source software most embedded products run on. We list components after every build, scan against security databases, prioritise by how your product is actually used, agree the fix with you, then apply and test it.

CRA requirement met

What gets checked

Secure by design
Development process reviewed and scored
Security risk assessment
Product threats identified (STRIDE + EMB3D)
Attack surface reduction
Architecture weaknesses found
Vulnerability handling processes
Governance gaps identified
Technical documentationArt. 13
Documentation gaps identified

CRA requirement met

What gets built

No known exploitable vulnerabilities
Automated security checks in the build pipeline
Software Bill of MaterialsAnnex I Part II 1
SBOM generated and kept up to date
Address vulnerabilities without delay
Vulnerability fix process with response times
Coordinated Vulnerability Disclosure
Vulnerability disclosure policy published
Secure update distribution
Secure update delivery mechanism
Market conformityArt. 28
EU Declaration of Conformity signed
Incident reportingArt. 14
Incident reporting procedure tested

Ready to find out where you stand?

Talk with us about a CRA Readiness Assessment. Find out exactly what's between you and compliance, and what it'll take to close the gap.

Book an assessment