services
Electronics development
Security & Safety
Digitalization
Embedded software
CRA
AI
Electronics manufacturing
Testing as a Service
Services
about usindustriescareer
de
en
contact

cra compliance

Regulation (EU) 2024/2847 makes cybersecurity mandatory for all products with digital elements on the EU market. The reporting requirements for vulnerabilities and incidents take effect on September 11, 2026, and full compliance is required as of December 11, 2027. We support you every step of the way—from risk assessment and secure development to the technical dossier. We also bring existing products up to the required standard.

get in touch

Integration is in our nature!

CRA Compliance

AS A SOLUTION AND SYSTEM PROVIDER, WE BRING YOUR IDEAS TO LIFE!

01

Risk Assessment & Threat Modeling

We deliver robust, reliable, and cost-effective hardware precisely tailored to your requirements.

learn more

02

Secure Development & SBOM

Our developers offer our clients more than just code. Because good software simplifies complex devices and systems.

learn more

03

Operations & Reporting Obligations

Firmware gives your hardware intelligence and brings it to life. We develop individual firmware solutions and program custom applications.

learn more

04

Updating legacy products

Our systems integrate seamlessly into your existing infrastructure and work together perfectly. This allows us to achieve maximum performance, efficiency, and reliability.

learn more

your path to market-ready electronics, with comprehensive support
CE-Reife

Through the perfect interplay of functional hardware, suitable firmware, and modular software, we transform complex challenges into simple solutions.
Wir wählen den kürzeren und gehen ihn mit Ihnen.
start inquiry
1

Risk Assessment & Threat Modeling

It starts with classification: Does your product fall within the scope of the CRA, and which class does it belong to under Annexes III and IV? This determines the conformity assessment path: self-assessment or involvement of a notified body.
The risk assessment according to Art. 13(2) is then prepared: threat scenarios are evaluated for each asset, and countermeasures are defined.
- Verification of scope and classification
- Determination of the conformity assessment path: self-assessment or notified body
- Cybersecurity risk assessment according to Art. 13(2)
- Threat modeling with specific attack scenarios
2

Secure Development & SBOM

The defined requirements are implemented during the development phase. In parallel, the machine-readable SBOM and the documentation for the technical file are generated.
- Secure by Design and Secure by Default
- Secure Boot, encrypted communication, and signed OTA updates
- Machine-readable SBOM, automated within the build process
- Alignment with relevant standards such as ISA/IEC 62443, ETSI EN 303 645, etc.
- Technical file according to Annex VII
‍
3

Operations & Reporting Obligations

Once a product is placed on the market, obligations begin that distinguish the CRA from a simple approval requirement:
- Security updates throughout the support period of at least five years
- Updated SBOM for each release, including CVE matching
- Continuous vulnerability monitoring
- Timely reporting to ENISA and the national CSIRT: early warning within 24 hours, notification within 72 hours, and a final report within 14 days
- CRA-compliant maintenance contracts
4

Update existing products

Products placed on the market after December 11, 2027, must comply with the requirements. This also applies to products developed prior to this date. For manufacturers with an existing portfolio, this often represents the greater challenge: the products function, but documentation, SBOMs, and update mechanisms are missing.
In our gap assessment, we evaluate the current status and provide a prioritized action plan with estimates for effort and timelines.
We handle the implementation through to CE readiness, even for software that was not developed by us.
- Gap assessment against CRA requirements
- Retroactive creation of SBOMs from existing code
- Prioritized action plan with effort and timeline estimates
- Implementation, testing, and validation through to CE readiness

case study

Pump Control: Cybersecurity under the CRA


‍Technologies: Microcontrollers, BLE, OTA updates, Secure Boot, encrypted communication, SBOM generation during build
‍
Challenge: A pump system controller, configurable via app over BLE and field-upgradable, falls under the scope of the Cyber Resilience Act. We determined the regulatory classification in collaboration with the client. Our task was the technical implementation: embedding the derived requirements into the firmware and development process.
‍
‍Solution: We assessed threat scenarios for the BLE channel, authentication, firmware integrity, and physical access, and derived technical measures accordingly. We implemented Secure Boot with signature verification prior to execution, encrypted communication without plaintext pairing, and encrypted OTA updates. The machine-readable SBOM is generated automatically during the build process and updated with every release, supplemented by cross-referencing the components used against known vulnerabilities.
‍
Result: Security requirements are firmly embedded in the product.

legal
imprintprivacy policyterms and conditions (agb)purchasing terms (aeb)
company
about uscareerscontact
contact
phone +49 (0) 8281 9997-0info@habemus.com
Burtenbacher Strasse 12 | 86505 Münsterhausen
Follow us
facebook
instagram
linkedin
© 2025 Habemus! electronic + transfer GmbH -