Most product teams treat the Cyber Resilience Act as a 2027 problem because that is when the main obligations bite. The reporting duties do not wait: from 11 September 2026 you need a working intake channel, a triage process, named owners and a rehearsed 24-hour path to the ENISA reporting platform. A clock you cannot meet is worse than one you have not read.
Why teams choose us.
No Accreditation Needed
Default-category products self-assess. There is no notified body to satisfy and no certificate to buy, which means the entire obligation is engineering work — and engineering is what we do.
No Personal Data In Scope
SBOMs, vulnerability processes and CI gates touch no personal data, so this engagement carries none of the EU transfer machinery that constrains our other services here.
Legacy Products Included
The reporting duty covers products already shipped, not just new releases. We inventory what is in the field and what you can actually patch.
A Rehearsed Clock
We do not hand you a policy document. We run the 24-hour path end to end with your team before you need it.
The full menu.
SBOM In The Pipeline
- Generated automatically on every build
- CycloneDX or SPDX, machine-readable
- Retained and versioned per release
- Covers direct and transitive dependencies
Vulnerability Handling Process
- Documented intake, triage and severity model
- Named owners and escalation path
- Remediation and disclosure timelines
- Evidence trail for each handled report
Coordinated Disclosure
- Public policy and security.txt
- Monitored intake channel
- Researcher acknowledgement process
- Advisory template and publication path
The Reporting Runbook
- 24h / 72h / 14-day sequence with owners
- ENISA Single Reporting Platform path
- Decision criteria for 'actively exploited'
- Rehearsed once with your team before sign-off
Update Delivery & Support Period
- Security update mechanism reviewed
- Support-period position documented
- Patch pipeline for products in the field
- CI/CD security gates and dependency policy
Our process.
Product Inventory
Every product with digital elements sold into the EU, including what is already in the field, with its dependency surface and current patch route.
Build The Artefacts
SBOM generation in CI, vulnerability handling process, coordinated disclosure policy, security update mechanism. Real artefacts, wired into your pipeline.
Wire The Clock
Owners named, criteria written, escalation path agreed, ENISA submission route confirmed. Then we run it once, as a drill.
Hand Over
You own the runbook and the pipeline. We document what remains for the December 2027 main obligations so it is a plan, not a surprise.
What we build with.
Choose this if...
Honest about who this is for.
This will be a fit.
- You are an English-speaking product company — Ireland, the Nordics, or selling into the EU from elsewhere
- You want SBOMs and a working process, not a compliance PDF
- You want the 24-hour path drilled before you need it
- You accept that the main CRA obligations land in December 2027 and this is the reporting layer
Honestly — not our zone.
- —Your product is in an important or critical category needing a notified body — that is a conformity assessment and we do not perform them
- —You want a CRA certificate or a declaration of conformity signed by us. The declaration is yours to sign; we build the evidence behind it
- —You want us to operate the reporting clock for you. We build and drill it; you own it, because the legal duty is the manufacturer's
- —You need the work delivered in German, French, Italian, Dutch or Spanish. We deliver in English only
Common questions, straight answers.
One contract covers any of these.
Everything below runs on the same agreement, the same invoice and the same account team as EU Cyber Resilience Act Readiness.
Compliance Readiness Assessment
A fixed-fee assessment of where you actually stand against SOC 2 or ISO 27001:2022, ending in a costed, sequenced remediation plan and a warm introduction to an auditor. We are not your auditor and legally cannot be — which is exactly why we can do this work.
Compliance Remediation Pod
Your platform lists eighty failing controls and your auditor is legally not allowed to close any of them. We put a security pod on the backlog — IAM, logging, encryption, cloud configuration, CI/CD hardening — and hand your auditor working evidence in the format they ask for.
Agentic AI Development
Custom AI agents, LLM integrations, RAG pipelines, and intelligent automation built into your product. On the Secure Build tier, every agent ships with a threat model, tool-permission scoping, guardrails, and an adversarial eval suite running in your CI.
Direct Hire
We source, vet, and shortlist senior engineers from a 100,000+ pool. You interview, offer, and own the employment.
Managed Growth
The whole digital operation for a business people physically visit — website built and maintained, SEO, AEO, GEO, Google Ads, email, campaigns, lead gen, and the automations behind them. One team, one fee, and ad spend passed through to the platforms at cost.
Graphic & Design Services
Brand systems, marketing collateral, and design-on-demand for product, social, and sales.































