Secure Products. Trusted Future.
CRA readiness assessments for embedded Linux and microcontroller products — engineering-driven gap analysis, risk-ranked remediation, and the hands-on support to close the gaps.
01 — Why we exist
We make CRA compliance achievable for small and mid-sized embedded companies: practical, engineering-driven cybersecurity that bridges the gap between regulation and real systems.
We exist to make CRA compliance achievable for small and mid-sized embedded companies — bridging the gap between regulation and real embedded systems, not just policy.
We turn Cyber Resilience Act and ETSI EN 303 645 requirements into clear, actionable steps — structured evidence, risk prioritisation, and documentation aligned with regulatory expectations.
We enable secure product innovation, not just checkbox compliance — improving real-world security in embedded Linux and MCU systems while meeting the regulation.
Beyond a single assessment, we support teams as their products evolve — helping them stay compliant and secure through future iterations and regulatory change.
Our assessments are focused, decision-oriented and time-efficient — helping teams make progress in weeks, not months.
By operating lean and focused, we deliver high-value embedded-security expertise at a fraction of the cost of large consulting firms.
02 — What is CRA?
The Cyber Resilience Act (CRA) is an EU regulation introducing mandatory cybersecurity requirements for products with digital elements — embedded devices, IoT systems, industrial controllers, and the software shipped with them across the EU.
CRA formally adopted and enters into force.
Early obligations begin — vulnerability handling and reporting requirements (from Sept 2026).
Full enforcement — only compliant products may be placed on the EU market (Dec 2027).
Don't worry — we're here for you.
03 — In force 11 September 2026
Not in December 2027. Article 14 obligations begin on 11 September 2026, and they apply to products already on the market — no CE marking, no conformity assessment and no harmonised standard needed to be caught by them.
to report an actively exploited vulnerability
From 11 September 2026 manufacturers must notify their CSIRT and ENISA within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident — with a fuller notification at 72 hours and a final report after that. Most embedded teams have no defined trigger, no filer, and no account on the platform they are supposed to file to.
In three days we put the process in place, end to end:
No prior assessment required. Independent of the Annex I work below — different clock, different question.
04 — Services & pricing
Pick the depth that matches where your product is. Every engagement ends with a gap analysis and a risk-ranked remediation roadmap your team can act on. See what each tier includes →
A bounded triage of CRA readiness — architecture, documentation, network posture and published firmware. Deliberately limited: it tells you where you stand and what to worry about first, without deep technical testing.
Request a Quick ScanThe right depth for most single products. Documentation review plus active interception and firmware reverse-engineering — findings backed by evidence from the device itself, not inferred from the outside.
Request a Standard AssessmentHardware teardown, off-chip firmware acquisition and demonstrated exploitation. Scoped to the product family; priced on the number of variants and how deep the physical work goes.
Request an Extended AssessmentHands-on implementation to close what an assessment found — secure boot, signed updates, SBOM tooling in your CI, Linux hardening, key management — followed by re-test to prove each finding is actually closed. You get a scoped estimate up front, not an open meter.
Continuous CVE watch against each product's SBOM, filtered to what actually affects you, with a first read on whether a signal starts the 24-hour clock. Priced per product and the size of its bill of materials. Cancellable; no long lock-in.
All prices exclude VAT · Valid through 30 June 2027
05 — Contact
Tell us about your product and timeline. We'll reply within two working days with a recommended starting point.
A short note about your product, target markets, and where you are with CRA is plenty to get started.
Occasional, practical notes on CRA, ETSI EN 303 645 and embedded security. No noise.