EU CRA: vulnerability-reporting obligations apply from 11 September 2026 — full compliance required by 11 December 2027.

Get a readiness assessment

What We Do

One partner across the cybersecurity lifecycle.

From first gap assessment to a fully operating product security organization — GRC, consulting, testing, and leadership under one roof.

Service lines

  • 01

    GRC Programs & Operating Model

    Governance · Risk · Compliance — AI-Accelerated

    • Gap assessment against IEC 62443, EU CRA, NIS2 and ISO 27001 in one pass
    • MDS² and IEC 81001-5-1 questionnaire answers, written once and reused
    • Audit evidence packs assembled from records your team already keeps
    • A written operating model: owners, decision points, review cadence
    • Supplier reviews scoped to what each one actually touches
  • 02

    Consulting & Auditing

    Gap Analysis · Compliance · Architecture

    • Architecture and risk review of the system as built, not as documented
    • Product security gap analysis ranked by what blocks a sale
    • Audit readiness: findings closed before the assessor arrives
    • Policy, procedure and record templates you can adopt as they are
  • 03

    Penetration Testing

    OT · Embedded · Connected Products

    • OT, embedded and connected-product testing against the real deployment
    • Threat modeling across the attack surface the product actually has
    • Findings written with the fix, the component, and the order to do them
    • One test, two reports: technical detail and board-level posture
  • 04

    Regulatory Readiness

    EU CRA · NIS2 · IEC 62443

    • EU CRA and NIS2 obligations mapped to your product, deadlines marked
    • Market-by-market assessment of what applies — and what does not
    • Gap analysis of shipping product against IEC 62443 and the EU CRA
    • Technical file and conformity documentation, built as the work happens

Insights

What we are writing about

Notes on the standards and regulations our clients are working through, written for the people who have to implement them.

All insights

Not sure which of these you need?