Shape

Service · Connected products

Cyber Resilience Act compliance for your connected products

From embedded software to the reporting process: getting your products and your organisation ready for CRA obligations.

Pricing
Fixed price, on quotation
Typical duration
3 to 6 weeks for the gap analysis
Who it is for
Manufacturers of connected machines and equipment · Makers of embedded products (sensors, gateways, controllers)

Who it is for

  • Manufacturers of connected machines and equipment
  • Makers of embedded products (sensors, gateways, controllers)
  • Software vendors whose code ships inside products

Why now

  1. Since 11 September 2026, actively exploited vulnerabilities and severe incidents must be reported (24h, then 72h).
  2. On 11 December 2027, all CRA essential requirements apply.
  3. The Machinery Regulation, applicable on 20 January 2027, adds requirements on protecting control systems.
  4. For radio equipment, the RED directive has required cybersecurity since August 2025 (EN 18031 standards).

Deliverables

What we deliver

  • Gap analysis against CRA essential requirements
  • Software inventory (SBOM) and dependency policy
  • Security architecture review: secure boot, OTA updates, secrets management
  • Vulnerability handling and reporting process (24h / 72h)
  • EN 18031 checklist for radio products
  • Compliance plan and input to the technical file

Method

How the engagement runs

  1. 1

    Qualification

    Classify the product under the CRA and identify applicable regulations.

  2. 2

    Product analysis

    Code and build-chain review, testing on target hardware.

  3. 3

    Gap analysis

    Comparison with essential requirements, prioritised gaps.

  4. 4

    Plan and tooling

    Compliance plan, SBOM, reporting process, implementation support.

Example

Sample deliverable

Typical table of contents of the CRA gap analysis

Example
  1. 01Product classification and applicable regulations
  2. 02Essential requirements: compliance status
  3. 03SBOM and exposure to known vulnerabilities
  4. 04Update and boot architecture
  5. 05Reporting and support process
  6. 06Compliance plan up to 11 December 2027

Typical structure of a deliverable, shown for illustration. Actual content is specific to each site or product.

FAQ

Frequently asked questions

What is an SBOM and why does the CRA require it?

An SBOM (Software Bill of Materials) is the inventory of a product’s software components. It shows quickly whether a product is affected by a published vulnerability. The CRA requires manufacturers to identify and document these components.

Our products are already on the market: are they affected?

Reporting obligations have applied since 11 September 2026 to products made available on the market. Essential requirements apply to products placed on the market from 11 December 2027. A gap analysis separates what is urgent from what can be planned.

Do you work on the embedded code itself?

Yes. We work on embedded software (embedded Linux, microcontrollers), the build chain and update mechanisms, with testing on target hardware.

A regulatory deadline is coming up?

Let’s talk about your site or product. One call is enough to know where to start.

Shape