Digital product security

Cyber Resilience Act (CRA)

Adaptation of products with digital elements to the European Cyber Resilience Regulation.

What it involves

What we do

The CRA requires manufacturers, importers and distributors of products with digital elements to meet essential security requirements, manage vulnerabilities and report incidents. We determine how your products are classified and the path to CE marking.

What's included

  • Applicability analysis and product classification
  • Gap assessment against the Annex I essential requirements
  • Vulnerability management and reporting processes
  • Technical documentation, SBOM and declaration of conformity
  • Preparation for the conformity assessment
  • Integration with ISO 27001, IEC 62443 and product security

Who it's for

  • Software and hardware manufacturers with digital elements
  • Importers and distributors in the EU
  • Connected product and IoT companies

Deliverables

  • Applicability report
  • CRA gap assessment
  • Adaptation plan and technical documentation

Reference frameworks and standards

CRA (EU Reg. 2024/2847)IEC 62443ETSI EN 303 645ISO/IEC 27034

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does Cyber Resilience Act (CRA) fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.