cra compliance
Regulation (EU) 2024/2847 makes cybersecurity mandatory for all products with digital elements on the EU market. The reporting requirements for vulnerabilities and incidents take effect on September 11, 2026, and full compliance is required as of December 11, 2027. We support you every step of the way—from risk assessment and secure development to the technical dossier. We also bring existing products up to the required standard.

AS A SOLUTION AND SYSTEM PROVIDER, WE BRING YOUR IDEAS TO LIFE!
01
Risk Assessment & Threat Modeling
We deliver robust, reliable, and cost-effective hardware precisely tailored to your requirements.
learn more02
Secure Development & SBOM
Our developers offer our clients more than just code. Because good software simplifies complex devices and systems.
learn more03
Operations & Reporting Obligations
Firmware gives your hardware intelligence and brings it to life. We develop individual firmware solutions and program custom applications.
learn more04
Updating legacy products
Our systems integrate seamlessly into your existing infrastructure and work together perfectly. This allows us to achieve maximum performance, efficiency, and reliability.
learn moreyour path to market-ready electronics, with comprehensive support
CE-Reife
Wir wählen den kürzeren und gehen ihn mit Ihnen.
Risk Assessment & Threat Modeling
The risk assessment according to Art. 13(2) is then prepared: threat scenarios are evaluated for each asset, and countermeasures are defined.
- Verification of scope and classification
- Determination of the conformity assessment path: self-assessment or notified body
- Cybersecurity risk assessment according to Art. 13(2)
- Threat modeling with specific attack scenarios
Secure Development & SBOM
- Secure by Design and Secure by Default
- Secure Boot, encrypted communication, and signed OTA updates
- Machine-readable SBOM, automated within the build process
- Alignment with relevant standards such as ISA/IEC 62443, ETSI EN 303 645, etc.
- Technical file according to Annex VII
Operations & Reporting Obligations
- Security updates throughout the support period of at least five years
- Updated SBOM for each release, including CVE matching
- Continuous vulnerability monitoring
- Timely reporting to ENISA and the national CSIRT: early warning within 24 hours, notification within 72 hours, and a final report within 14 days
- CRA-compliant maintenance contracts
Update existing products
In our gap assessment, we evaluate the current status and provide a prioritized action plan with estimates for effort and timelines.
We handle the implementation through to CE readiness, even for software that was not developed by us.
- Gap assessment against CRA requirements
- Retroactive creation of SBOMs from existing code
- Prioritized action plan with effort and timeline estimates
- Implementation, testing, and validation through to CE readiness

.avif)