Assessment and implementation at firmware level, from a single source.
From 11 September 2026, the CRA reporting obligations apply to actively exploited vulnerabilities and severe security incidents. The initial early warning is generally due within 24 hours.
From 11 December 2027, the essential requirements of the Cyber Resilience Act apply to products in scope, including conformity assessment and CE marking.
Request a free intro callThe Cyber Resilience Act is EU regulation and applies across all member states. What I advise on is the concrete implementation for the German market: the German authorities and notified bodies, the documentation practice expected here, and — where legal questions arise — our German partner law firm. I work with you in English, but the regulatory context I know inside out is the German one.
One day of analysis plus a written report: which product class, which obligations, which deadlines. Fixed price, credited against a follow-up engagement.
Your products checked against the essential requirements of the CRA, at firmware level rather than on documents alone.
A working process for the 24-hour early warning, the subsequent 72-hour notification and the final report: roles, procedures, templates. Tested, not just described.
SBOM pipeline, secure boot, signed updates, vulnerability handling. This is the part you cannot read up on.
For clarity: I advise and prepare things technically, the legal advice is provided exclusively in cooperation with our partner law firm. The declaration of conformity, CE marking and liability remain with the manufacturer. For most products an internal conformity assessment is possible. Certain important products may require a notified body; for critical products third-party assessment is generally mandatory.
For torcbrain I developed large parts of the software of an IoT cordless high-torque screwdriver: embedded Linux, a secure bootloader with TrustZone-protected M4 firmware IP protection, secure OTA updates, remote management and device administration via the cloud. The system has been in the field for over two years, and idastroem runs the cloud operations to this day. More in the blog.
Dipl.-Inf., Managing Director of idastroem GmbH
25 years of software development for electronics and industrial automation. I have shipped secure boot, encrypted firmware and secure OTA updates in series products long before the CRA made them mandatory.
30 minutes are enough for a first assessment. Free of charge, no obligation. If I cannot help, I will tell you during the call.
Arrange a call now30 minutes: products, connectivity, deadlines. Afterwards you know whether you need to act.
One day of analysis plus a written report with product class, obligations and priorities. Fixed price, credited against a follow-up engagement.
Gap analysis, reporting process, SBOM pipeline or firmware hardening, depending on what the check turns up. With clear milestones.