Get CRA ready

From the essential requirements to products that ship on time: assessment, roadmap and delivery with your teams, for every product category.

The Cyber Resilience Act (CRA) sets cyber security requirements for every product with digital elements sold in the European Union: the product itself, the process that builds it, and the handling of vulnerabilities once it is on the market. This mix of governance and technical requirements covers the entire lifecycle of products in scope, and beyond (10 years).

The CRA applies since 11 September 2026 for reporting requirements. Full compliance is required from 11 December 2027. Non-compliance exposes manufacturers to fines of up to 15 M€ or 2.5% of worldwide turnover, and to products being withdrawn from the EU market.

Not sure which of your products are in scope, or in which category? Find out in seconds with our free tool.

CRAscoping

What you get

We have secured connected products since 2017, and taken manufacturers through each regulation and standard as it arrived: EN 303 645, IEC 62443-4-1 and -4-2, RED cyber and EN 18031, and now the CRA. Working with us, you get:

A clear picture of where you stand

Every product’s category and conformity route, the gaps against the essential requirements, and what to fix first.

Security designed in, not bolted on

Security built into the development process you already have: the essential requirements met before the first line of code, with no friction for your teams.

A vulnerability handling process that runs

Intake, triage, remediation and reporting, with the SBOM to better support vulnerability management, ready for the obligations that already apply.

Products on the market on time

Documentation and evidence that pass the assessment, self-assessed or with a notified body, without a redesign at the last minute.

Our founder, Dr Cédric LÉVY-BENCHETON, is a member of ENISA’s ad hoc working group on security architecture engineering and vulnerability management, the two areas where the CRA asks the most of manufacturers.

Our services

Most programmes start with the CRA portfolio assessment: three weeks, fixed scope, a roadmap and a budget your board can decide on. The services below take the roadmap through delivery. Each exists on its own. Together they cover every product category and every stage of the programme.

Risk assessment

The basis of everything else: the risk assessment determines which essential requirements apply to each product, and the evidence to produce.

We make risk assessment deterministic and repeatable, so your teams gain the independence to run it without a security specialist in the room. To accelerate its implementation, we can build a bespoke FAST methodology adapted to your products.

Gap analysis

Each product family assessed against the essential requirements of Annex I, product properties and vulnerability handling, with every gap rated by risk and by the effort to close it.

It is the core of the portfolio assessment, and the basis of every roadmap.

Compliance roadmap

The gaps sequenced by dependency and by launch date: what to do this quarter, what can wait, who does it and what it costs.

Written as engineering tasks and process changes, with a budget your executive committee can decide on.

Security-by-design

Security requirements, review gates and evidence inside your existing development process, so that every release meets the essential requirements without a late redesign.

Your teams keep the process once we leave.

Threat model for manufacturing

The CRA requires products to be produced securely, wherever they are built. We model the threats to provisioning, firmware flashing and the production line, and engineer the remediations with the teams on site.

Most products are not built in your own factories, and the obligation follows them: we work in the plants of your manufacturing partners and ODMs, and in their own suppliers’ sites where the risk sits, and we encourage it. The requirements then go into the contracts and the evidence comes back to you.

Done once per site, it protects every unit built there.

Post-market requirements

The policies and the process for your reporting obligations, and the SBOM to better support vulnerability management throughout the support period.

A process with owners and deadlines is what avoids crises and keeps customer trust.

How we work

From the CRA to compliant products

People, processes, tools and strategy: we work with your entire product team, so the capability stays in your company.

  1. Scoping call

    Thirty minutes to understand your products, your markets and your deadlines. We tell you honestly whether and how we can help.
  2. Assessment

    We assess your products, processes and documentation against the CRA essential requirements, the harmonised standards, EN 303 645 and IEC 62443, together with your team.
  3. Roadmap

    You receive prioritised actions, the evidence to produce for the technical documentation, and a realistic budget and timeline: the CRA turned into actionable tasks.
  4. Delivery with your teams

    Documentation, tooling, training and reviews, alongside your developers, product owners and compliance managers, until the product ships and vulnerability handling runs.

Scope and price

Each service can be taken on its own, and every price is per product type unless it says otherwise.

Product scoping

1,000 €

discounted beyond five

Each product type placed in its CRA category, with the conformity route that follows from it.

Risk assessment

8,000 €

to 10,000 €, 2 to 3 weeks

The risk assessment that decides which essential requirements apply, ready for the technical documentation. The price depends on the product’s complexity.

Technical documentation

15,000 €

starting price

The technical documentation of a simple product and its remote data processing, such as its mobile app and its cloud. A complex product starts at 30,000 €.

Threat model for manufacturing

30,000 €

per factory, travel extra

The threats and risks to provisioning, firmware flashing, and the production line at one factory until shipping, and the remediations with the relevant teams (industrialisation, product, security, etc.).

The factory can be your own, your manufacturing partner’s or your ODM’s, and their suppliers’ sites where the risk sits. We then turn what we find into requirements for the contract and evidence the manufacturer returns, so the sites we do not visit are covered too.

Prices exclude VAT. Travel for on-site work is extra.

The gap analysis against the essential requirements is the CRA portfolio assessment: 5,000 € per product, 20,000 € for a whole portfolio.

Next step

Let's talk about your CRA programme

A first call takes thirty minutes and costs nothing: tell us about your product, your market and your timeline, and we will tell you honestly how we can help.