The obligations below fall into two categories, and each usually has a different owner. We separate them clearly so product, engineering, security and compliance teams know what applies and who is responsible.
Product cybersecurity
Cybersecurity requirements for the hardware and software products you place on the EU market.
Cyber Resilience Act (CRA)
Regulation (EU) 2024/2847 sets mandatory cybersecurity requirements for products with digital elements placed on the EU market. It entered into force on 10 December 2024 and applies in full from 11 December 2027, with the Article 14 reporting obligations applying earlier, from 11 September 2026. Scope and product classification decide your conformity assessment route, which in turn decides what evidence must exist before the product is placed on the market.
We work through scope, classification, risk assessment against Annex I, vulnerability handling, reporting, SBOM, technical documentation and preparation for the applicable conformity assessment route.
CRA compliance services · Read the Cyber Resilience Act full text and practitioner notes
Organizational cybersecurity and regulatory compliance
Requirements for security governance, risk management and day-to-day operations.
NIS2 Directive
Directive (EU) 2022/2555 raises the level of cybersecurity expected of essential and important entities, widening the sectors covered and tightening risk management, incident reporting, supply chain security and management accountability. Being a Directive, it binds through each Member State's national transposition, so what applies to you depends on where you operate.
DORA
Regulation (EU) 2022/2554 sets digital operational resilience requirements for financial entities and the ICT providers that serve them: ICT risk management, incident classification and reporting, resilience testing, and oversight of third-party ICT arrangements.
GDPR
Regulation (EU) 2016/679 governs the processing of personal data. The part we work on is the security of processing and the technical and organizational measures behind it, together with breach detection, assessment and notification.
How we work
We organize engagements into four stages, with agreed deliverables and responsibilities.
Assess
We establish what actually applies to you before recommending anything: which regulations reach your products and your organization, and where you stand against them today. For CRA work this includes a scope and classification determination per product; for NIS2 it includes whether you are an essential or important entity under the relevant national transposition.
You receive: an applicability determination, a gap register with owners and effort estimates, and a prioritized roadmap.
Plan
We prioritize the gaps, assign responsibilities and set milestones around the applicable deadlines. We also prepare policies and define governance responsibilities.
You receive: a sequenced compliance plan with owners and milestones, and the policies the regulations require you to hold.
Implement
We work alongside your teams to implement technical controls: SBOM generation in the build pipeline, vulnerability handling and disclosure processes, reporting runbooks, logging and monitoring, access control, and technical documentation supporting conformity assessment.
You receive: implemented controls, documented processes and supporting evidence.
Maintain
We monitor regulatory developments, review their impact on your organization and help update your controls and documentation. We also support audits, market surveillance requests and incident reporting.
You receive: periodic reviews, regulatory change notifications, and support when an authority asks a question.
Where to start
Contact us to discuss applicable requirements, your current controls and implementation priorities. Initial assessments are free.
Email [email protected] or use the contact form.