EU Cyber Resilience Act

Your connected product needs to be CRA compliant by December 2027.

Penumbral Labs finds the security gaps between your product and its CE mark, and shows you exactly how to close them.

The deadline
11 Sep 2026
Vulnerability reporting duties began.
11 Dec 2027
Full compliance required. Miss it and the product loses its CE mark.
15M € / 2.5%
Maximum penalty, or 2.5 percent of global turnover, whichever is higher.

The EU Cyber Resilience Act makes cybersecurity a legal condition for selling any product with digital elements in the EU. Without compliance, a product loses its CE mark and cannot be sold.

What we do

All services →

We get manufacturers ready. A fixed-scope readiness assessment tells you where you stand. Hands-on testing proves what is actually exploitable. Ongoing support keeps you compliant through every release. All delivered by an offensive-security specialist, not a checklist.

01
Readiness assessment
A fixed-scope review tells you where you stand against the CRA essential requirements.
02
Hands-on testing
We attack the real product and prove what is actually exploitable, not just what a form says.
03
Ongoing support
We keep you compliant through every release, so it stays fixed after the first pass.

Why Penumbral Labs

Most compliance help is a questionnaire and a slide deck. We come at your product the way an attacker does, find the real weaknesses, and hand you a plan to fix them.

You get the rigour of an offensive security engagement without a large consultancy's price tag or timeline.

We test like an attacker, not a questionnaire.
Real vulnerability evidence, not a slide deck.
Offensive-security rigour without consultancy pricing or timelines.

The deadline is fixed. The sooner you know your gaps, the calmer the road to 2027.

Book a 20-minute scoping call.

Book a scoping call