
The Cyber Resilience Act (CRA) sets cyber security requirements for every product with digital elements sold in the European Union: the product itself, the process that builds it, and the handling of vulnerabilities once it is on the market. This mix of governance and technical requirements covers the entire lifecycle of products in scope, and beyond (10 years).
The CRA applies since 11 September 2026 for reporting requirements. Full compliance is required from 11 December 2027. Non-compliance exposes manufacturers to fines of up to 15 M€ or 2.5% of worldwide turnover, and to products being withdrawn from the EU market.
Not sure which of your products are in scope, or in which category? Find out in seconds with our free tool.
What you get
We have secured connected products since 2017, and taken manufacturers through each regulation and standard as it arrived: EN 303 645, IEC 62443-4-1 and -4-2, RED cyber and EN 18031, and now the CRA. Working with us, you get:
A clear picture of where you stand
Security designed in, not bolted on
A vulnerability handling process that runs
Products on the market on time
Our founder, Dr Cédric LÉVY-BENCHETON, is a member of ENISA’s ad hoc working group on security architecture engineering and vulnerability management, the two areas where the CRA asks the most of manufacturers.
Our services
Most programmes start with the CRA portfolio assessment: three weeks, fixed scope, a roadmap and a budget your board can decide on. The services below take the roadmap through delivery. Each exists on its own. Together they cover every product category and every stage of the programme.
Risk assessment
The basis of everything else: the risk assessment determines which essential requirements apply to each product, and the evidence to produce.
We make risk assessment deterministic and repeatable, so your teams gain the independence to run it without a security specialist in the room. To accelerate its implementation, we can build a bespoke FAST methodology adapted to your products.
Gap analysis
Each product family assessed against the essential requirements of Annex I, product properties and vulnerability handling, with every gap rated by risk and by the effort to close it.
It is the core of the portfolio assessment, and the basis of every roadmap.
Compliance roadmap
The gaps sequenced by dependency and by launch date: what to do this quarter, what can wait, who does it and what it costs.
Written as engineering tasks and process changes, with a budget your executive committee can decide on.
Security-by-design
Security requirements, review gates and evidence inside your existing development process, so that every release meets the essential requirements without a late redesign.
Your teams keep the process once we leave.
Threat model for manufacturing
The CRA requires products to be produced securely, wherever they are built. We model the threats to provisioning, firmware flashing and the production line, and engineer the remediations with the teams on site.
Most products are not built in your own factories, and the obligation follows them: we work in the plants of your manufacturing partners and ODMs, and in their own suppliers’ sites where the risk sits, and we encourage it. The requirements then go into the contracts and the evidence comes back to you.
Done once per site, it protects every unit built there.
Post-market requirements
The policies and the process for your reporting obligations, and the SBOM to better support vulnerability management throughout the support period.
A process with owners and deadlines is what avoids crises and keeps customer trust.
How we work
From the CRA to compliant products
People, processes, tools and strategy: we work with your entire product team, so the capability stays in your company.
-
Scoping call
Thirty minutes to understand your products, your markets and your deadlines. We tell you honestly whether and how we can help. -
Assessment
We assess your products, processes and documentation against the CRA essential requirements, the harmonised standards, EN 303 645 and IEC 62443, together with your team. -
Roadmap
You receive prioritised actions, the evidence to produce for the technical documentation, and a realistic budget and timeline: the CRA turned into actionable tasks. -
Delivery with your teams
Documentation, tooling, training and reviews, alongside your developers, product owners and compliance managers, until the product ships and vulnerability handling runs.
Scope and price
Each service can be taken on its own, and every price is per product type unless it says otherwise.
Product scoping
1,000 €
discounted beyond five
Risk assessment
8,000 €
to 10,000 €, 2 to 3 weeks
Technical documentation
15,000 €
starting price
Threat model for manufacturing
30,000 €
per factory, travel extra
The threats and risks to provisioning, firmware flashing, and the production line at one factory until shipping, and the remediations with the relevant teams (industrialisation, product, security, etc.).
The factory can be your own, your manufacturing partner’s or your ODM’s, and their suppliers’ sites where the risk sits. We then turn what we find into requirements for the contract and evidence the manufacturer returns, so the sites we do not visit are covered too.
Prices exclude VAT. Travel for on-site work is extra.
The gap analysis against the essential requirements is the CRA portfolio assessment: 5,000 € per product, 20,000 € for a whole portfolio.
