Understand your product
Review its architecture, components, and how it is used. Identify questions for your regulatory advisers.
CYBER RESILIENCE ACT
Product security starts well before the next release reaches the market.
Discuss my productSTUDIO BODs / CYBER RESILIENCE ACT
The CRA’s main requirements apply from 11 December 2027 to products within scope placed on the EU market. Certain reporting obligations have applied since 11 September 2026. Now is the time to examine your products, software, and release process.
Which components does your software use? How do you fix a vulnerability and deliver an update? We work through these questions with your team and identify the changes your product needs.
OUR APPROACH
Review its architecture, components, and how it is used. Identify questions for your regulatory advisers.
Review software security, dependencies, and how you detect, fix, and report vulnerabilities.
Set priorities, improve the software, and document the changes and checks carried out.
IN PRACTICE
We review your software and explain the work ahead. Our specialists can then help your team carry it out, from component inventories and code security to executable signing and updates.
YOUR QUESTIONS
Products intended for the EU market can be within scope even when the manufacturer is based elsewhere. Your role, the product, and how it is placed on the market need to be assessed.
The engagement provides a technical assessment and action plan. Regulatory classification and the appropriate conformity assessment procedure must be determined for your product with the relevant advisers or bodies.
Yes. We examine what can be retained, what needs to change, and what is missing to maintain and update the product.
STUDIO BODs / CYBER RESILIENCE ACT
Understanding your software, addressing weaknesses, and preparing updates takes time. Let’s discuss your product and deadlines now.
Discuss my product