Skip to content

EU CYBER RESILIENCE ACT · FOR MAKERS OF CONNECTED PRODUCTS

Your product contains software. Since 11 September 2026, the EU gives you 24 hours.

The Cyber Resilience Act is a new EU law for products that contain software, exchange data with a device or network and are sold in the EU. Swiss manufacturers included. Products you sold years ago included. Once you become aware that a flaw in your product is being actively exploited, you have 24 hours to send an early warning to the national CSIRT. We make sure you can.

What the law requires once you become aware that a flaw in your product is actively exploited

24h

Early warning to the national CSIRT

72h

Vulnerability notification

14d

Final report, 14 days after a fix is available

Never heard of it? Start here

The CRA in Three Sentences

It is a law, not a standard.

Regulation (EU) 2024/2847, the Cyber Resilience Act. It entered into force in December 2024. Its first duty, reporting, applies since 11 September 2026. The full set of requirements applies from 11 December 2027. There is no opt-in and no certificate to buy your way out.

It applies to you if three things are true.

Your product contains software. It can exchange data with something, even indirectly: a network, Bluetooth, USB, a phone app, a cloud. It is sold in the EU, under your name. Where your company sits does not matter: a Swiss manufacturer is fully in scope.

It asks four things of you.

Know what software is inside every release you ship. Watch for known flaws in it. Fix them and ship the fix. Send an early warning within 24 hours of becoming aware that a flaw in your product is being actively exploited. Keep watching and fixing for the support period, normally at least five years; reporting continues after it. Products placed on the market before 11 December 2027 carry the reporting duty only; every unit placed from that date carries all four.

Where the law stands today

10 December 2024 Law enters into force 11 September 2026 Reporting duty applies, also for products already in the field 11 December 2027 Full requirements for every unit placed on the market from then on

Does it apply to me? Three questions, ten seconds

Does your product contain software?
Can it exchange data with anything, even indirectly? A network, Bluetooth, USB, a phone app, a cloud.
Is it sold in the EU, directly or through a distributor?
The CRA applies to you, since 11 September 2026.

The next question is whether you could answer an early warning within 24 hours. The free self-check tells you in an hour.

Probably out of scope.

Unsure about that “no”? Products get in through a companion app, a USB port or a cloud service more often than people expect. Ask us; the answer takes five minutes.

Ask an engineer

What we offer

Three Steps, from “Where Do We Stand” to “We Are Covered”

Built for manufacturers whose firmware is made by a handful of engineers, not by a security department. The pressure rarely arrives as a regulator’s letter. It arrives as a customer’s purchase order asking for proof.

1 · Free · one hour · you do it

Check Yourself

Ten questions, scored honestly by you, nothing to send back and no obligation. You see where you stand today. We ran it on our own product first and scored 2 out of 10.

2 · Fixed price· two weeks · we do it

Let Us Measure

The readiness check. We measure your real build against the ten capabilities the law quietly assumes, with evidence, not with a questionnaire. You get a scored report, the EU reporting platform walked through with your people, and a gap plan your own team can act on.

3 · Monthly · per product · we keep doing it

Stay Covered

The ongoing watch. We archive the software list of every release you ship and check it every night against the live vulnerability databases, with a separate watch for flaws under active attack. When something turns up, a named person on your side hears about it, with our verdict and, where it matters, the early warning already drafted.

Honest scope

Detection runs every night, unattended, weekends included; expert analysis is business hours. You remain the manufacturer and the filing stays yours, with our draft in hand. The reporting duty does not end with your support period, and the law sets no end date; neither does the watch.

Why EDGEMTech

Why an Embedded Software Company, and not a Law Firm or a Scanning Tool

We build this kind of firmware every day.

Yocto Linux, real-time systems, Toradex and similar modules, chip-vendor Bluetooth stacks. The CRA is a question about what is inside your build. That is where we live.

Tools give findings. Reporting needs judgment.

A scanner lists hundreds of matches and decides nothing. Someone has to say “this one does not affect us, because” and write down why. That judgment is the service.

The final report needs a fix that boots.

The final report is due no later than 14 days after a fix is available, and it has to describe that fix. A fix that runs on hardware sold five years ago is engineering work, not paperwork. We do that work.

The radio stack in your product comes from the chip vendor. The reporting duty stays with you, the manufacturer.

Frequently Asked Questions

Thirty minutes with an engineer, not a sales call.

Bring one product. We tell you which of the ten capabilities you already have, which you do not, and whether the readiness check is worth your money.

A summary of the regulation as we read it, not legal advice.