From CRA obligationsto continuous compliance.
The CRA applies to almost every machine with digital components. We make your product CRA compliant and keep it that way: from risk analysis to a file that grows automatically with every release.
What is the CRA?
Who it applies to
The manufacturer that places the product on the EU market. We deliver the engineering and the evidence; the client remains the manufacturer.
The product and the process
Requirements for the properties of the product, and for how you handle vulnerabilities for as long as the support period runs. At least five years, and often much longer for industrial products.
Penalties
Fines of up to €15 million or 2.5% of worldwide annual turnover for failing to meet the cybersecurity or reporting requirements.
The chain, in one place.
We keep the CRA chain traceable for years, in one place. Risks, requirements, tests and evidence are connected, so you see right away what needs to be reassessed as soon as something changes.

- 1
An overview of all your products
For each product, you see where it stands in the compliance chain and what is still open.
- 2
Evidence for every release
Every release automatically comes with its test results, scans, SBOM and vulnerability status.
- 3
Vulnerabilities and reports
New vulnerabilities are followed up and reports are prepared within the legal deadlines.
- 4
Connects to your existing tools
Everything works with the engineering tools your team already uses. No extra workflow is added.
- 5
Documents in one click
Technical documentation and the declaration of conformity are generated from the data that is already there.
One traceable chain,embedded in engineering.
- 1
Understand first
Product, engineering and processes mapped out: architecture, components, releases and responsibilities.
- 2
Then automate
Collect evidence where engineering happens, based on the tools your team already uses today.
- 3
Continuously compliant
The file grows with the product, with every release and every new vulnerability.
The same law, but every product needs its own approach.
The CRA takes more than compliance knowledge. It takes a partner at home in product development, firmware and embedded software, who understands the obligations deeply enough to connect both worlds. That is what we do every day.
What the law actually requires.
Four product categories, each with its own route
Default
Self-assessment by the manufacturer.
Important, class I
Self-assessment with harmonized standards, otherwise a notified body.
Important, class II
Always a notified body.
Critical
European cybersecurity certification.
Let's look together at what the CRA means for your product.
In a first conversation, we determine the product category, the conformity route and what needs to be ready before December 11, 2027.
