If your connected product sells into Europe, the EU Cyber Resilience Act applies to you. Full enforcement lands in December 2027, with the first reporting duties from September 2026. We help you reach conformity before it gates your access to the market.
The EU Cyber Resilience Act sets mandatory cybersecurity rules for any product with digital elements sold in the EU, from vehicles and ECUs to telematics units and IoT gateways. Full enforcement begins in December 2027, with vulnerability and incident reporting duties starting earlier, in September 2026.
Getting it wrong is expensive. It can mean market restrictions, plus fines up to €15 million or 2.5% of global annual turnover, whichever is higher. And the work to comply, from SBOMs to a vulnerability-handling process to conformity evidence, takes months. So the deadline is closer than it looks.
Your product has to be secure out of the box, backed by a documented risk assessment.
A maintained list of every component, so vulnerabilities can be tracked and disclosed.
A working process to find, fix and disclose vulnerabilities across the product's whole life.
Proof of conformity, self-assessed or third-party depending on your product's risk class, so you can CE-mark it.
Security updates across the support period you commit to.
We start with an EU CRA gap assessment against your product, then help you close the gaps: continuous SBOM/HBOM scanning through vulnerability.core, a working vulnerability-handling process, and the conformity documentation you need to CE-mark your product and stay in the market.
An EU CRA gap report · an SBOM maintained in vulnerability.core · a vulnerability-handling process · a conformity evidence pack.
December 2027 is a deadline, not a suggestion, and the September 2026 reporting duties arrive sooner still. A gap assessment tells you exactly what the EU CRA requires of your product, and how to get there in time.