Invisto
Invisto · your interface partner
Emailinfo@invisto.bePhone+32 477 42 11 14OfficeHangar K, Kortrijknlen
What we do

From CRA obligationsto continuous compliance.

The CRA applies to almost every machine with digital components. We make your product CRA compliant and keep it that way: from risk analysis to a file that grows automatically with every release.

Reporting obligationSeptember 11, 2026Report actively exploited vulnerabilities and severe security incidents: an early warning within 24 hours, a full notification within 72 hours.
Full CRA obligationsDecember 11, 2027From this date, the essential cybersecurity requirements, the risk assessment, the technical documentation, the EU declaration of conformity and the CE marking apply.

What is the CRA?

Who it applies to

The manufacturer that places the product on the EU market. We deliver the engineering and the evidence; the client remains the manufacturer.

The product and the process

Requirements for the properties of the product, and for how you handle vulnerabilities for as long as the support period runs. At least five years, and often much longer for industrial products.

Penalties

Fines of up to €15 million or 2.5% of worldwide annual turnover for failing to meet the cybersecurity or reporting requirements.

The chain, in one place.

We keep the CRA chain traceable for years, in one place. Risks, requirements, tests and evidence are connected, so you see right away what needs to be reassessed as soon as something changes.

Project overview showing the steps of the CRA chain for each product, from scope to report
  • 1

    An overview of all your products

    For each product, you see where it stands in the compliance chain and what is still open.

  • 2

    Evidence for every release

    Every release automatically comes with its test results, scans, SBOM and vulnerability status.

  • 3

    Vulnerabilities and reports

    New vulnerabilities are followed up and reports are prepared within the legal deadlines.

  • 4

    Connects to your existing tools

    Everything works with the engineering tools your team already uses. No extra workflow is added.

  • 5

    Documents in one click

    Technical documentation and the declaration of conformity are generated from the data that is already there.

One traceable chain,embedded in engineering.

  1. 1

    Understand first

    Product, engineering and processes mapped out: architecture, components, releases and responsibilities.

  2. 2

    Then automate

    Collect evidence where engineering happens, based on the tools your team already uses today.

  3. 3

    Continuously compliant

    The file grows with the product, with every release and every new vulnerability.

The same law, but every product needs its own approach.

The CRA takes more than compliance knowledge. It takes a partner at home in product development, firmware and embedded software, who understands the obligations deeply enough to connect both worlds. That is what we do every day.

Regulation (EU) 2024/2847

What the law actually requires.

Four product categories, each with its own route

  • Default

    Self-assessment by the manufacturer.

  • Important, class I

    Self-assessment with harmonized standards, otherwise a notified body.

  • Important, class II

    Always a notified body.

  • Critical

    European cybersecurity certification.

Let's look together at what the CRA means for your product.

In a first conversation, we determine the product category, the conformity route and what needs to be ready before December 11, 2027.

Schedule a CRA call