EU CYBER RESILIENCE ACT · FOR MAKERS OF CONNECTED PRODUCTS
Your product contains software. Since 11 September 2026, the EU gives you 24 hours.
The Cyber Resilience Act is a new EU law for every product that contains software and is sold in the EU. Swiss manufacturers included. Products you sold years ago included. No exemption for small companies. When a flaw in your product is being actively exploited, you have 24 hours to warn the authorities. We make sure you can.
What the law requires, once a flaw is actively exploited
24h
Early warning to the EU
72h
Full notification
14d
Final report, after the fix
Never heard of it? start here
The CRA in Three Sentences
It is a law, not a standard.
Regulation (EU) 2024/2847, the Cyber Resilience Act. It entered into force in December 2024. Its first duty, reporting, applies since 11 September 2026. The full set of requirements applies from 11 December 2027. There is no opt-in and no certificate to buy your way out.
It applies to you if three things are true.
Your product contains software. It can connect to something: a network, Bluetooth, USB, a phone app, a cloud. It is sold in the EU, directly or through a distributor. Where your company sits does not matter: a Swiss manufacturer is fully in scope.
It asks four things of you.
Know exactly what software is inside every version you have shipped. Watch for known flaws in it. Fix them and ship the fix. Report a flaw that is being actively exploited in your product within 24 hours. And keep all of this up for the whole support period of the product, at least five years. Products already in the field carry the reporting duty only; every unit you place on the market from 11 December 2027 carries all four.
Where the law stands today
What we offer
Three Steps, from “Where Do We Stand” to “We Are Covered”
Built for manufacturers whose firmware is made by a handful of engineers, not by a security department. The pressure rarely arrives as a regulator’s letter. It arrives as a customer’s purchase order asking for proof.
1 · Free · one hour · you do it
Check Yourself
Ten questions, scored honestly by you, nothing to send back and no obligation. You see where you stand today. We ran it on our own product first and scored 2 out of 10.
2 · Fixed price· TWO weeks · we do it
Let Us Measure
The readiness check. We measure your real build against the ten capabilities the law quietly assumes, with evidence, not with a questionnaire. You get a scored report, your registration on the EU reporting platform walked through, and a gap plan your own team can act on.
3 · Monthly · per product · we keep doing it
Stay Covered
The ongoing watch. We archive the software list of every release you ship and check it every night against the live vulnerability databases, with a separate watch for flaws under active attack. When something turns up, a named person on your side hears about it, with the notification already drafted.
Honest scope
Detection runs around the clock; expert analysis is business hours. You remain the manufacturer and the filing stays yours, with our draft in hand. The reporting duty lasts as long as your product is in use, and does not end with your support period; neither does the watch.
Why EDGEMTech
Why an Embedded Software Company, and not a Law Firm or a Scanning Tool
We build this kind of firmware every day.
Yocto Linux, real-time systems, Toradex and similar modules, chip-vendor Bluetooth stacks. The CRA is a question about what is inside your build. That is where we live.
Tools give findings. The law needs verdicts.
A scanner lists hundreds of matches and signs nothing. Someone has to say “this one does not affect us, because” and put their name under it. That judgment is the service.
The final report needs a fix that boots.
Within 14 days you must report what you did about it. A fix that runs on hardware sold five years ago is engineering work, not paperwork. We do that work.
The radio stack in your product comes from the chip vendor. The reporting duty stays with you, the manufacturer.
Frequently Asked Questions
Thirty minutes with an engineer, not a sales call.
Bring one product. We tell you which of the ten capabilities you already have, which you do not, and whether the readiness check is worth your money.
A summary of the regulation as we read it, not legal advice.
