Reporting duties apply
24-hour early warning and 72-hour notification for actively exploited vulnerabilities and severe incidents — including products already on the market.
For manufacturers of products with digital elements. IEC 62443-4-1 proves how you build; the CRA governs what you must show the market. We map the two, name the gap, and hand you the evidence — before the clock runs out.
If your product has digital elements and carries a CE mark, the Cyber Resilience Act now applies to you. The obligations are not a policy PDF — they are demonstrated, evidenced, audited processes. IEC 62443-4-1 proves how you build; the CRA governs what you must show the market. Most teams discover the gap between the two too late.
24-hour early warning and 72-hour notification for actively exploited vulnerabilities and severe incidents — including products already on the market.
CE marking will require demonstrated cybersecurity: technical documentation, conformity assessment, and an EU declaration of conformity.
And your customers are asking earlier than the law does.
The standard audits your secure-development lifecycle — the process, the gates, the evidence. The CRA adds market-facing obligations the standard never covers: incident and vulnerability reporting, a coordinated-disclosure policy, a defensible support period, SBOM and third-party component duties, and the technical-documentation-to-CE conformity route. That seam between the standard and the regulation is where the audit finding lands — and no single framework governs both sides of it. Naming that gap, and closing it with evidence, is the work.
The standard audits how you build. The regulation audits what you place on the market. No single framework governs the seam between them — that seam is where the finding lands, and closing it with evidence is the work.
Security Management
Security Requirements
Secure by Design
Secure Implementation
Verification & Validation
Defect Management
Secure Update Management
Security Guidelines
Procedures, templates, and evidence registers behind every one.
Who does what inside the 24-hour and 72-hour windows — for products already placed on the market, not just new ones.
A public vulnerability-disclosure policy and the internal process that stands behind it.
A defensible end-of-support definition and the security-update commitment that follows from it.
Component inventory (CycloneDX/SPDX), known-vulnerability handling, and supplier obligations — the supply-chain surface the CRA makes yours.
The conformity route mapped: technical documentation, conformity assessment, declaration of conformity, CE marking.
90 minutes and a written memo: where your product stands against the Sept 2026 reporting duties and the Dec 2027 conformity deadline, and the three gaps that carry the most exposure.
Your product assessed across its full threat surface and mapped requirement-by-requirement to IEC 62443-4-1 and the CRA. Deliverable: the gap between standard and regulation named, a prioritised remediation plan, and the evidence you'll be asked for.
The audit-ready document set — the SDLC standard, one procedure per 62443-4-1 practice, the CRA pack (reporting, PSIRT, support policy, SBOM, CE route), templates, and traceability registers — tailored to your products and roles. You adopt and run it instead of writing it. Weeks, not a year.
A standing capability through the compliance window: reporting-duty readiness, vulnerability-handling on call, and a rolling assessment as the harmonised standards land.
Click one — we'll route you. None fit? Describe it below.