If your connected device sells into Europe, the EU Cyber Resilience Act applies to you. Full enforcement lands in December 2027, with reporting duties starting as early as September 2026. We help connected-device and IoT makers reach conformity with gap assessments, continuous SBOM monitoring, and the reporting the CRA expects.
The EU Cyber Resilience Act sets mandatory cybersecurity rules for any product with digital elements sold in the EU, from telematics units and IoT gateways to smart devices and beyond. The bar isn't “best effort.” It's documented security by design, a real vulnerability-handling process, and proven conformity.
Full enforcement lands in December 2027, and getting it wrong can mean fines up to €15 million or 2.5% of global annual turnover, whichever is higher, plus the risk of being pulled from the EU market. The work behind compliance, from SBOMs to vulnerability processes to conformity evidence, takes months. The deadline is closer than it looks.
We map your product against the CRA's requirements and work out which risk class it falls into.
Explore EU CRAContinuous component monitoring through vulnerability.core, with an alert the moment a new vulnerability appears.
We help you stand up the identify-fix-disclose process the CRA requires, and keep it running.
Explore the processPenetration and fuzz testing of your device firmware, interfaces and APIs.
Explore testingThe evidence pack for self-assessment or third-party conformity, and your CE marking.
Explore complianceA practical plan for security updates across the support period you commit to.
Explore updatesA documented risk assessment, and a product that's secure straight out of the box.
A maintained list of every component in your product, so vulnerabilities can be tracked and disclosed.
A working process that runs for the life of the product, including duties to report serious issues.
Proof that your product conforms, self-assessed or checked by a third party depending on risk class, so you can CE-mark it.
Updates provided across the support period you've defined for the product.
We do automotive and connected-device/EU CRA work, a combination very few security vendors can offer.
vulnerability.core keeps watching your SBOM long after the assessment is signed off, not just on day one.
Reporting built for EU CRA conformity, not a generic scan dump you have to translate yourself.
vulnerability.core's SBOM monitoring to your products.Start an EU CRA assessment, and we'll map your device against the regulation, set up continuous SBOM monitoring, and build the conformity evidence that keeps you selling in the European market.