Skip to content

EU CYBER RESILIENCE ACT · FOR MAKERS OF CONNECTED PRODUCTS

Your product contains software. Since 11 September 2026, the EU gives you 24 hours.

The Cyber Resilience Act is a new EU law for every product that contains software and is sold in the EU. Swiss manufacturers included. Products you sold years ago included. No exemption for small companies. When a flaw in your product is being actively exploited, you have 24 hours to warn the authorities. We make sure you can.

What the law requires, once a flaw is actively exploited

24h

Early warning to the EU

72h

Full notification

14d

Final report, after the fix

Never heard of it? start here

The CRA in Three Sentences

It is a law, not a standard.

Regulation (EU) 2024/2847, the Cyber Resilience Act. It entered into force in December 2024. Its first duty, reporting, applies since 11 September 2026. The full set of requirements applies from 11 December 2027. There is no opt-in and no certificate to buy your way out.

It applies to you if three things are true.

Your product contains software. It can connect to something: a network, Bluetooth, USB, a phone app, a cloud. It is sold in the EU, directly or through a distributor. Where your company sits does not matter: a Swiss manufacturer is fully in scope.

It asks four things of you.

Know exactly what software is inside every version you have shipped. Watch for known flaws in it. Fix them and ship the fix. Report a flaw that is being actively exploited in your product within 24 hours. And keep all of this up for the whole support period of the product, at least five years. Products already in the field carry the reporting duty only; every unit you place on the market from 11 December 2027 carries all four.

Where the law stands today

10 December 2024 Law enters into force 11 September 2026 Reporting duty applies, also for products already in the field 11 December 2027 Full requirements for every unit placed on the market from then on

Does it apply to me? Three questions, ten seconds

Does your product contain software?
Can it connect to anything? A network, Bluetooth, USB, a phone app, a cloud.
Is it sold in the EU, directly or through a distributor?
The CRA applies to you, since 11 September 2026.

The next question is whether you could answer an early warning within 24 hours. The free self-check tells you in an hour.

Probably out of scope.

Unsure about that “no”? Products get in through a companion app, a USB port or a cloud service more often than people expect. Ask us; the answer takes five minutes.

Ask an engineer

What we offer

Three Steps, from “Where Do We Stand” to “We Are Covered”

Built for manufacturers whose firmware is made by a handful of engineers, not by a security department. The pressure rarely arrives as a regulator’s letter. It arrives as a customer’s purchase order asking for proof.

1 · Free · one hour · you do it

Check Yourself

Ten questions, scored honestly by you, nothing to send back and no obligation. You see where you stand today. We ran it on our own product first and scored 2 out of 10.

2 · Fixed price· TWO weeks · we do it

Let Us Measure

The readiness check. We measure your real build against the ten capabilities the law quietly assumes, with evidence, not with a questionnaire. You get a scored report, your registration on the EU reporting platform walked through, and a gap plan your own team can act on.

3 · Monthly · per product · we keep doing it

Stay Covered

The ongoing watch. We archive the software list of every release you ship and check it every night against the live vulnerability databases, with a separate watch for flaws under active attack. When something turns up, a named person on your side hears about it, with the notification already drafted.

Honest scope

Detection runs around the clock; expert analysis is business hours. You remain the manufacturer and the filing stays yours, with our draft in hand. The reporting duty lasts as long as your product is in use, and does not end with your support period; neither does the watch.

Why EDGEMTech

Why an Embedded Software Company, and not a Law Firm or a Scanning Tool

We build this kind of firmware every day.

Yocto Linux, real-time systems, Toradex and similar modules, chip-vendor Bluetooth stacks. The CRA is a question about what is inside your build. That is where we live.

Tools give findings. The law needs verdicts.

A scanner lists hundreds of matches and signs nothing. Someone has to say “this one does not affect us, because” and put their name under it. That judgment is the service.

The final report needs a fix that boots.

Within 14 days you must report what you did about it. A fix that runs on hardware sold five years ago is engineering work, not paperwork. We do that work.

The radio stack in your product comes from the chip vendor. The reporting duty stays with you, the manufacturer.

Frequently Asked Questions

Thirty minutes with an engineer, not a sales call.

Bring one product. We tell you which of the ten capabilities you already have, which you do not, and whether the readiness check is worth your money.

A summary of the regulation as we read it, not legal advice.