Technical Assurance & Offensive Security
Cyber Resilience Act Readiness
If you ship a product with digital elements into the EU, the clock is already running.
The situation
What the client receives
Schedule of deliverables
- Product scope and risk classification (default / important / critical)
- Annex I essential requirements gap assessment
- Vulnerability handling process and coordinated disclosure policy
- Article 14 reporting procedure for actively exploited vulnerabilities
- SBOM and secure-update capability design
- Technical documentation and conformity assessment route planning
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- Regulation (EU) 2024/2847 (CRA)
- Harmonised standards as published
- NIST SSDF
- ISO/IEC 29147 / 30111
Related services
Discuss this engagement
Tell us about the product with digital elements and the market you place it on and we will set out the scope, the method and the reporting format.