EU CYBER RESILIENCE ACT · FOR MAKERS OF CONNECTED PRODUCTS
Your product contains software. Since 11 September 2026, the EU gives you 24 hours.
The Cyber Resilience Act is a new EU law for products that contain software, exchange data with a device or network and are sold in the EU. Swiss manufacturers included. Products you sold years ago included. Once you become aware that a flaw in your product is being actively exploited, you have 24 hours to send an early warning to the national CSIRT. We make sure you can.
What the law requires once you become aware that a flaw in your product is actively exploited
24h
Early warning to the national CSIRT
72h
Vulnerability notification
14d
Final report, 14 days after a fix is available
Never heard of it? Start here
The CRA in Three Sentences
It is a law, not a standard.
Regulation (EU) 2024/2847, the Cyber Resilience Act. It entered into force in December 2024. Its first duty, reporting, applies since 11 September 2026. The full set of requirements applies from 11 December 2027. There is no opt-in and no certificate to buy your way out.
It applies to you if three things are true.
Your product contains software. It can exchange data with something, even indirectly: a network, Bluetooth, USB, a phone app, a cloud. It is sold in the EU, under your name. Where your company sits does not matter: a Swiss manufacturer is fully in scope.
It asks four things of you.
Know what software is inside every release you ship. Watch for known flaws in it. Fix them and ship the fix. Send an early warning within 24 hours of becoming aware that a flaw in your product is being actively exploited. Keep watching and fixing for the support period, normally at least five years; reporting continues after it. Products placed on the market before 11 December 2027 carry the reporting duty only; every unit placed from that date carries all four.
Where the law stands today
What we offer
Three Steps, from “Where Do We Stand” to “We Are Covered”
Built for manufacturers whose firmware is made by a handful of engineers, not by a security department. The pressure rarely arrives as a regulator’s letter. It arrives as a customer’s purchase order asking for proof.
1 · Free · one hour · you do it
Check Yourself
Ten questions, scored honestly by you, nothing to send back and no obligation. You see where you stand today. We ran it on our own product first and scored 2 out of 10.
2 · Fixed price· two weeks · we do it
Let Us Measure
The readiness check. We measure your real build against the ten capabilities the law quietly assumes, with evidence, not with a questionnaire. You get a scored report, the EU reporting platform walked through with your people, and a gap plan your own team can act on.
3 · Monthly · per product · we keep doing it
Stay Covered
The ongoing watch. We archive the software list of every release you ship and check it every night against the live vulnerability databases, with a separate watch for flaws under active attack. When something turns up, a named person on your side hears about it, with our verdict and, where it matters, the early warning already drafted.
Honest scope
Detection runs every night, unattended, weekends included; expert analysis is business hours. You remain the manufacturer and the filing stays yours, with our draft in hand. The reporting duty does not end with your support period, and the law sets no end date; neither does the watch.
Why EDGEMTech
Why an Embedded Software Company, and not a Law Firm or a Scanning Tool
We build this kind of firmware every day.
Yocto Linux, real-time systems, Toradex and similar modules, chip-vendor Bluetooth stacks. The CRA is a question about what is inside your build. That is where we live.
Tools give findings. Reporting needs judgment.
A scanner lists hundreds of matches and decides nothing. Someone has to say “this one does not affect us, because” and write down why. That judgment is the service.
The final report needs a fix that boots.
The final report is due no later than 14 days after a fix is available, and it has to describe that fix. A fix that runs on hardware sold five years ago is engineering work, not paperwork. We do that work.
The radio stack in your product comes from the chip vendor. The reporting duty stays with you, the manufacturer.
Frequently Asked Questions
Thirty minutes with an engineer, not a sales call.
Bring one product. We tell you which of the ten capabilities you already have, which you do not, and whether the readiness check is worth your money.
A summary of the regulation as we read it, not legal advice.
