Reporting duty starts 11 Sept 2026 · Full enforcement Dec 2027

BitShepherd

Secure Products. Trusted Future.

CRA readiness assessments for embedded Linux and microcontroller products — engineering-driven gap analysis, risk-ranked remediation, and the hands-on support to close the gaps.

01 — Why we exist

Compliance that survives contact with real firmware.

We make CRA compliance achievable for small and mid-sized embedded companies: practical, engineering-driven cybersecurity that bridges the gap between regulation and real systems.

Compliance you can actually reach

We exist to make CRA compliance achievable for small and mid-sized embedded companies — bridging the gap between regulation and real embedded systems, not just policy.

Regulation, translated to engineering

We turn Cyber Resilience Act and ETSI EN 303 645 requirements into clear, actionable steps — structured evidence, risk prioritisation, and documentation aligned with regulatory expectations.

Security, not box-ticking

We enable secure product innovation, not just checkbox compliance — improving real-world security in embedded Linux and MCU systems while meeting the regulation.

A partner for the long run

Beyond a single assessment, we support teams as their products evolve — helping them stay compliant and secure through future iterations and regulatory change.

Fast, because deadlines don't wait

Our assessments are focused, decision-oriented and time-efficient — helping teams make progress in weeks, not months.

Senior expertise, lean pricing

By operating lean and focused, we deliver high-value embedded-security expertise at a fraction of the cost of large consulting firms.

02 — What is CRA?

The EU is making product security mandatory.

The Cyber Resilience Act (CRA) is an EU regulation introducing mandatory cybersecurity requirements for products with digital elements — embedded devices, IoT systems, industrial controllers, and the software shipped with them across the EU.

Who must comply? SCOPE

  • Embedded Linux devices — gateways, cameras, routers, industrial systems
  • Microcontroller-based IoT products — ESP32, STM32, NXP and similar
  • Consumer, industrial and B2B connected devices
  • Both EU and non-EU companies selling into the EU market
  • Importers and distributors — not only manufacturers — each carry their own obligations
  • Anyone reselling a product under their own brand, who is treated as its manufacturer

Key obligations DUTIES

  • Design and develop with security-by-design principles
  • Identify and mitigate cybersecurity risks
  • Provide secure update mechanisms (e.g. OTA updates)
  • Maintain a vulnerability handling and reporting process
  • Document security measures and keep compliance evidence
  • Report actively exploited vulnerabilities within defined timelines

Timeline

2024

CRA formally adopted and enters into force.

2026

Early obligations begin — vulnerability handling and reporting requirements (from Sept 2026).

2027

Full enforcement — only compliant products may be placed on the EU market (Dec 2027).

Don't worry — we're here for you.

03 — In force 11 September 2026

The first CRA duty lands this month.

Not in December 2027. Article 14 obligations begin on 11 September 2026, and they apply to products already on the market — no CE marking, no conformity assessment and no harmonised standard needed to be caught by them.

24 hours

to report an actively exploited vulnerability

CRA Reporting Readiness

From 11 September 2026 manufacturers must notify their CSIRT and ENISA within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident — with a fuller notification at 72 hours and a final report after that. Most embedded teams have no defined trigger, no filer, and no account on the platform they are supposed to file to.

In three days we put the process in place, end to end:

  • Awareness policy and triage criteria — when the clock starts, in writing
  • 24-hour, 72-hour and final notification templates, carrying your product identifiers
  • CSIRT routing determination and ENISA Single Reporting Platform registration
  • A tabletop exercise against your real templates, with a findings report
  • A one-page readiness statement you can send to customers asking for assurance

No prior assessment required. Independent of the Annex I work below — different clock, different question.

04 — Services & pricing

Fixed-scope assessments. No surprises.

Pick the depth that matches where your product is. Every engagement ends with a gap analysis and a risk-ranked remediation roadmap your team can act on. See what each tier includes →

3,500

Quick Scan

3–4 business days

A bounded triage of CRA readiness — architecture, documentation, network posture and published firmware. Deliberately limited: it tells you where you stand and what to worry about first, without deep technical testing.

Request a Quick Scan
from14,500

Extended Assessment

13–15 business days

Hardware teardown, off-chip firmware acquisition and demonstrated exploitation. Scoped to the product family; priced on the number of variants and how deep the physical work goes.

Request an Extended Assessment
Scoped per engagement

Engineering Support

Hands-on implementation to close what an assessment found — secure boot, signed updates, SBOM tooling in your CI, Linux hardening, key management — followed by re-test to prove each finding is actually closed. You get a scoped estimate up front, not an open meter.

Scope engineering support
from€490 per product / month

Vulnerability Monitoring

Continuous CVE watch against each product's SBOM, filtered to what actually affects you, with a first read on whether a signal starts the 24-hour clock. Priced per product and the size of its bill of materials. Cancellable; no long lock-in.

Set up monitoring

All prices exclude VAT · Valid through 30 June 2027

05 — Contact

Let's find your gaps before an auditor does.

Tell us about your product and timeline. We'll reply within two working days with a recommended starting point.

Send us a message

A short note about your product, target markets, and where you are with CRA is plenty to get started.