Services

Four services, designed to be taken in order.

Most clients start with a readiness assessment and grow from there. Each one stands on its own.

01

CRA Readiness Assessment

The starting point. A fixed-scope review of one product against the CRA essential requirements and its vulnerability-handling and reporting duties. You get a gap report with every requirement rated, real vulnerability evidence from automated discovery, a prioritised remediation roadmap with a timeline to December 2027, and an executive summary your management can read in five minutes.

Delivered in about ten business days. Fixed scope, fixed price, quoted per product.
02

Source Code and Dependency Review

A deep look at what is actually inside your product. We scan your repositories and their dependencies for vulnerabilities, triage what matters, and produce the software bill of materials the CRA expects. This is where our tooling does the heavy lifting, so you get more coverage than a manual review at the same cost.

03

Product Penetration Test

Hands-on attack testing of the product, its firmware, its APIs, and the systems it talks to. This is the "prove it by breaking it" step. It produces the security evidence the CRA expects and validates that your fixes actually hold.

Backed by recognised offensive-security certifications.
04

CRA Compliance Partner

Monthly retainer

Compliance is not one and done. We monitor for new vulnerabilities in your product and its components, re-test when you ship, run your vulnerability-disclosure inbox, and keep your documentation audit-ready. Your outsourced product-security function.

Not sure which one you need?

That is what the scoping call is for. Every engagement is fixed-scope and fixed-price, quoted per product on the call.

Book a call