Tools

Our methodology, productised: the tools we use with clients, several of them free to use.

Every tool here started as a method we applied by hand in an engagement, then productised so that a product team can use it without a security specialist in the room: find the CRA category of a product, evaluate a portfolio against the requirements, derive security requirements from a risk assessment, produce the RED documentation, write, analyse and score a vulnerability disclosure policy. Several are free. The others are the platforms we deploy with clients.

Pick a tool on the left. Each page explains what it does, who it is for and how to get it.

Cyber Resilience Act

Product security

RED cyber

CRAted for CRA compliance

CRA Toolkit for Evaluation and Decision. Map your product portfolio to CRA requirements, with no prerequisites.

Learn more

CRAted for CRA compliance

CRAscoping

Identify the category of your product under the EU Cyber Resilience Act with our free, specially trained AI.

Learn more

CRAscoping

FAST

The Friendly Assessment of Security and Threats. Your companion to secure-by-design products.

Learn more

FAST

Auto VDP

Generate your VDP in one click, or analyse the one you have.

A vulnerability disclosure policy is mandatory to comply with cyber security regulations such as the EU CRA or the UK PSTI.

Learn more

Auto VDP

VDP scoring

Evaluate your VDP score and see how well you do.

Learn more

VDP scoring

ProSecCo, the product security maturity model

With ProSecCo, evaluate your product security maturity, understand what you do well, highlight gaps and identify improvements.

Learn more

ProSecCo, the product security maturity model

RED scoping

Identify whether your products are in scope of RED cyber (art. 3.3 d/e/f).

Learn more

RED scoping

RED self-assessment

Evaluate whether a self-assessment (Module A) is possible for your product.

Learn more

RED self-assessment

Pre-compliance template

Evaluate your product compliance with EN 18031

Learn more

Pre-compliance template

REDact, compliance REDefined

The RED Assistant for Compliance Toolkit: free EN 18031 templates.

Learn more

REDact, compliance REDefined

ICS2IXIT

Optimise your compliance with EN 303 645 / TS 103 701 and RED cyber / EN 18031.

Learn more

ICS2IXIT

Next step

Need more than a tool?

Our tools are informative. For a formal assessment of your products and a compliance roadmap, our team works with yours.