productcybersecurity
Connected-product compliance

Product Cybersecurity Experts

Product cybersecurity protects software, firmware, connected devices, and AI-enabled products throughout their lifecycle. We help teams prepare for the EU CRA, the EU AI Act, UN R155/R156, and ISO/SAE 21434.

Frameworks
CRA · AI ACT
Domains
AUTO · AI · IOT
Capabilities
06
Status
OPERATIONAL
01Regulations

Start with the deadline that gates your market.

Four regulatory regimes drive connected-product security programs across firmware, software, vehicles, and AI-enabled systems. Identify yours, then map the technical work beneath it.

EU CRA01/04

EU Cyber Resilience Act

Cybersecurity by design, vulnerability handling, and technical documentation for products with digital elements placed on the EU market.

Binds
Manufacturers, importers & distributors
Deadline
Obligations phase in through Dec 2027
Run scope check
UN R155/R15602/04

Automotive Homologation

Cyber Security Management System (CSMS) and Software Update Management System (SUMS) for vehicle type approval.

Binds
Vehicle manufacturers & Tier-1 suppliers
Deadline
Mandatory for new vehicle types
Discuss homologation
EU AI ACT03/04

EU Artificial Intelligence Act

Risk-based obligations for AI systems and certain general-purpose AI, including transparency, governance, and added controls for high-risk AI.

Binds
Providers, deployers, importers & distributors
Deadline
Phased obligations started in 2025
Plan AI Act readiness
ISO/SAE 2143404/04

Road Vehicle Cybersecurity

Engineering process for cybersecurity risk management across the automotive component and system lifecycle.

Binds
Automotive engineering organizations
Deadline
Referenced by UN R155 type approval
Assess process
02CRA Scope Check

Am I in scope — and which category?

A quick determination with the article and annex citations behind every step. Preview it here, then open the full four-question tool.

Scope & Classification00/04
  1. 01

    Does the product have digital elements?

    Hardware or software placed on the EU market whose intended use includes a direct or indirect data connection to a device or network.

    CRA Art. 3(1) — definition of ‘product with digital elements’

  2. 02

    Is it made available on the EU market in the course of a commercial activity?

    Free and open-source software developed or supplied outside a commercial activity is out of scope.

    CRA Art. 2 & Recital 18 — scope and FOSS exclusion

Open full CRA check
Decision Trail

Answer the questions to preview your determination. The full tool covers Annex III/IV classification.

02Definitions

Clear answers for product cybersecurity, the EU CRA, and the EU AI Act.

These are the core terms buyers, regulators, and engineering teams search for when they need connected-product security guidance.

01

What is Product Cybersecurity?

Product cybersecurity is the practice of designing, testing, documenting, and maintaining secure software, firmware, and connected devices across the full product lifecycle. It covers secure design, vulnerability handling, updates, and evidence that supports market access and customer trust.

Discuss your product
02

What is the EU CRA?

The EU Cyber Resilience Act applies to products with digital elements placed on the EU market. It requires cybersecurity by design, vulnerability handling, and technical documentation that supports conformity assessment and post-market obligations.

Check CRA scope
03

What is the EU AI Act?

The EU AI Act is a risk-based regulation for AI systems and certain general-purpose AI models used in or placed on the EU market. Depending on the use case, obligations can include prohibited-use restrictions, transparency duties, governance controls, and added requirements for high-risk AI.

Plan AI Act readiness
03Capabilities

The technical work beneath the regulations.

Six services that produce the evidence, findings, and hardening each compliance program depends on.

01

Firmware Analysis

Comprehensive binary analysis of embedded firmware to identify security weaknesses, hardcoded credentials, and vulnerable components.

  • Binary reverse engineering
  • SBOM generation
  • Cryptographic assessment
02

Vulnerability Assessment

Systematic identification and classification of security vulnerabilities in IoT devices and their firmware.

  • CVE identification
  • Zero-day research
  • Risk prioritization
03

Compliance Services

Navigate complex regulatory requirements with expert guidance on product cybersecurity standards and certification preparation.

  • EU Cyber Resilience Act
  • EU AI Act
  • UN R155 & ISO 21434
04

Penetration Testing

Simulated attacks on your IoT ecosystem to validate security controls and identify real-world attack vectors.

  • Network penetration
  • Physical testing
  • Red team exercises
05

Architecture Review

Security-focused evaluation of your product architecture, communication protocols, and cloud integration points.

  • Threat modeling
  • Protocol analysis
  • Secure design review
06

Security Training

Customized training programs for engineering teams on secure firmware development and IoT security best practices.

  • Secure SDLC
  • Code review skills
  • Incident response
04Our Approach

Engineering Meets Legal Compliance

We bridge the gap between abstract legal requirements and the binary reality of your firmware.

  1. 01

    Regulatory Classification

    We analyze your product against the legal text (EU CRA, UN R155) to determine your exact category — Critical, Important, or Default — ensuring you don't over-engineer compliance.

  2. 02

    Gap Analysis

    A dual-layer assessment: scanning firmware against technical standards (IEC 62443, EN 303 645) while mapping findings directly to legal Essential Requirements.

  3. 03

    Defensible Documentation

    We deliver the evidence required for your Declaration of Conformity. You receive a technical risk assessment and a legal roadmap prepared for Notified Body reviews.

  4. 04

    Remediation & Lifecycle

    Compliance doesn't end at launch. We help implement fixes and establish the Vulnerability Handling processes required to keep your product on the market.

Engage

Secure Your Connected Products

Get expert guidance on product cybersecurity, EU Cyber Resilience Act essential requirements, EU AI Act readiness, UN R155 homologation, and ISO/SAE 21434 automotive standards.