Most product teams treat the Cyber Resilience Act as a 2027 problem because that is when the main obligations bite. The reporting duties do not wait: from 11 September 2026 you need a working intake channel, a triage process, named owners and a rehearsed 24-hour path to the ENISA reporting platform. A clock you cannot meet is worse than one you have not read.
Why teams choose us.
No Accreditation Needed
Default-category products self-assess. There is no notified body to satisfy and no certificate to buy, which means the entire obligation is engineering work — and engineering is what we do.
No Personal Data In Scope
SBOMs, vulnerability processes and CI gates touch no personal data, so this engagement carries none of the EU transfer machinery that constrains our other services here.
Legacy Products Included
The reporting duty covers products already shipped, not just new releases. We inventory what is in the field and what you can actually patch.
A Rehearsed Clock
We do not hand you a policy document. We run the 24-hour path end to end with your team before you need it.
The full menu.
SBOM In The Pipeline
- Generated automatically on every build
- CycloneDX or SPDX, machine-readable
- Retained and versioned per release
- Covers direct and transitive dependencies
Vulnerability Handling Process
- Documented intake, triage and severity model
- Named owners and escalation path
- Remediation and disclosure timelines
- Evidence trail for each handled report
Coordinated Disclosure
- Public policy and security.txt
- Monitored intake channel
- Researcher acknowledgement process
- Advisory template and publication path
The Reporting Runbook
- 24h / 72h / 14-day sequence with owners
- ENISA Single Reporting Platform path
- Decision criteria for 'actively exploited'
- Rehearsed once with your team before sign-off
Update Delivery & Support Period
- Security update mechanism reviewed
- Support-period position documented
- Patch pipeline for products in the field
- CI/CD security gates and dependency policy
Our process.
Product Inventory
Every product with digital elements sold into the EU, including what is already in the field, with its dependency surface and current patch route.
Build The Artefacts
SBOM generation in CI, vulnerability handling process, coordinated disclosure policy, security update mechanism. Real artefacts, wired into your pipeline.
Wire The Clock
Owners named, criteria written, escalation path agreed, ENISA submission route confirmed. Then we run it once, as a drill.
Hand Over
You own the runbook and the pipeline. We document what remains for the December 2027 main obligations so it is a plan, not a surprise.
What we build with.
Choose this if...
Honest about who this is for.
This will be a fit.
- You are an English-speaking product company — Ireland, the Nordics, or selling into the EU from elsewhere
- You want SBOMs and a working process, not a compliance PDF
- You would rather drill the 24-hour path than discover it during an incident
- You accept that the main CRA obligations land in December 2027 and this is the reporting layer
Honestly — not our zone.
- —Your product is in an important or critical category needing a notified body — that is a conformity assessment and we do not perform them
- —You want a CRA certificate or a declaration of conformity signed by us. The declaration is yours to sign; we build the evidence behind it
- —You want us to operate the reporting clock for you. We build and drill it; you own it, because the legal duty is the manufacturer's
- —You need the work delivered in German, French, Italian, Dutch or Spanish. We deliver in English only































