Vulnir solutions

Engineering your EU Regulatory Compliance journey

Cyber Resilience Act (CRA)

Vulnerability Management

We architect internal and external vulnerability handling processes engineered precisely around prEN 40000-1-3 standards. We ensure your Product Security Incident Response Teams (PSIRT) are operationally mature and fully prepared to meet mandatory CRA reporting obligations.

Secure SDLC Transformation

We embed essential CRA technical security requirements directly into your active engineering pipelines. From automated Software Bill of Materials (SBOM) generation to continuous shift-left testing, we transform your development lifecycle into a self-sustaining compliance engine.

Regulatory Defensibility

We lead the structuring, compilation, and validation of your product’s technical files and testing of your product to ensure an accurate technical defensibility before Conformity Assessment Bodies (CABs) and market surveillance authorities.

WHY US?

Standardization Leadership

At Vulnir, we don't just interpret the rules, we help write them. As active leaders within the European standardization bodies, we directly shape the upcoming horizontal harmonized standards that will govern market access under the Cyber Resilience Act (CRA).
  • prEN 40000-1-4 : Generic Security Requirements
  • prEN 40000-1-3 : Vulnerability handling requirements

The Clock is Ticking: The Two-Phase Enforcement

Phase 1 - September 11, 2026

CRA Article 14 requires manufacturers to report actively exploited vulnerabilities within 24 hours and severe incidents within strict regulatory timelines. Vulnir delivers the expertise, processes, and operational support needed to meet these obligations, helping organizations reduce regulatory risk while protecting customers and business reputation. Vulnir supports manufacturers throughout the entire Article 14 process:

  • PSIRT establishment and maturity assessments
  • Active vulnerability and incident triage
  • CRA reporting readiness and procedures
  • 24h/72h/final report preparation
  • ENISA and CSIRT engagement support
  • Customer notification processes
  • Incident evidence and audit trail management
  • Post-incident improvement and lessons learned

Phase 2 - December 11, 2027

From December 2027, CRA compliance becomes mandatory for products with digital elements placed on the EU market. Manufacturers must demonstrate conformity with the Cyber Resilience Act, maintain the required technical documentation, perform conformity assessments, and affix the CE marking before placing products on the European Single Market. Vulnir supports manufacturers throughout the entire CRA compliance journey:

  • CRA strategy and compliance roadmaps
  • Product cybersecurity assessments
  • Essential requirements implementation
  • Technical file and compliance documentation development
  • SBOM and supply chain security programs
  • Conformity assessment preparation
  • CE marking readiness reviews
  • Ongoing compliance and governance support

As industry leaders, we are focused on driving innovation and solving problems every single day.

Strategic Service Offering

Gap Analysis & Strategy

We conduct a rigorous, architect-level evaluation of your current product ecosystem against the essential requirements of the Cyber Resilience Act (CRA) standards.

Trainings

We deliver tailored, technical training programs designed to upscale your engineering, product, and compliance teams. We prepare your organization to confidently navigate third-party conformity assessments and execute self-assessments.

Vulnerability Handling Strategy

We engineer the precise Technical and Organizational Measures (TOMs) required to meet the lifecycle vulnerability management and mandatory incident reporting rules.

Technical documentation

We lead the compiling, structuring, and final preparation of the comprehensive Technical Documentation dossier and the official EU Declaration of Conformity.

CRA Frequently Asked Questions

Reporting obligations start 11 September 2026. Full compliance is due 11 December 2027. Here's where you stand.

The CRA – Regulation (EU) 2024/2847, is EU product legislation that makes cybersecurity a condition of placing a product on the EU market. It is built on the New Legislative Framework, the same architecture as product safety law: essential requirements, conformity assessment, CE marking, market surveillance and fines. If your product has digital elements and its intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network, it is in scope.

Vulnir offers training for all levels and a certificate that demonstrates your proficiency based on the scope of the training itself. We are in the process of creating a formal training path for different roles. 

Almost certainly, if it has digital elements and can exchange data with a device or network. That covers hardware with embedded software, standalone hardware, standalone software, and combinations supplied separately but designed to work together. Pure cloud services sit under NIS2 instead, but if you also ship a local app or client, that’s in scope.

Note that scope is anchored in the capacity to exchange digitally encoded information – a product whose electrical signals merely trigger or power a function, without conveying encoded data, is outside the scope. Carve-outs exist for certain vehicles, medical devices, aviation and marine equipment.

Your reporting duties switch on, fifteen months before anything else. From that date, an actively exploited vulnerability or a severe incident must be notified to your national CSIRT and ENISA within 24 hours, with a fuller report at 72 hours.

The part most manufacturers miss: this applies to products already on the market, not just ones you launch after 2027. You can be legally obliged to report on a product that carries no CE mark.

Six things: build against the Annex I essential requirements; run and document a cybersecurity risk assessment; exercise due diligence on third-party components; establish vulnerability handling including a disclosure policy and an SBOM; declare and honour a support period; and compile the technical file, complete conformity assessment and affix the CE mark.

For high-level guidance for manufacturers, please have a look at Guidance for manufacturers.

Vulnir is supporting for all your compliance journey.

Default products can be self-assessed and are roughly 90% of the products on the market.

Important Class I products (VPNs, routers, password managers) can self-assess only if they fully apply relevant harmonised standards.

Class II (firewalls, IDS, operating systems) and critical products require a third party.

Which tier you’re in turns on your product’s core functionality, not its feature list. Containing a firewall doesn’t make you a firewall, and getting that call right is often the difference between a self-assessment and an audit.

Vulnir can establish your classification in writing and support with the right classification

Not yet, and until their references appear in the Official Journal, no presumption of conformity attaches. They’re being drafted in CEN/CENELEC JTC 13 as the EN 40000 series.

Vulnir’s founder holds a rapporteur role in CEN/CLC/JTC 13/WG 9, working on prEN 40000-1-3 and prEN 40000-1-4.

The plan for the majority of the standards is to be released between December 2026 and February 2027.

Up to €15 million or 2.5% of worldwide turnover, whichever is higher, for breaching the essential requirements (Article 13 & Article 14 violations).

For violations of other obligations (see Article 64), it is up  €10 million or 2% of worldwide turnover

Authorities can also order products withdrawn from the market — usually the more serious commercial outcome.

There’s no exemption, but the CRA does bend. Micro and small enterprises get simplified technical documentation, and cannot be fined for missing the 24-hour reporting deadline (see Article 64). Notified bodies are required to take company size into account, including in their fees.

In practice, smaller manufacturers often get there faster, scope is contained and decisions don’t cross four departments. The constraint is capacity, not complexity.

Vulnir supports any company and can help identify a reasonable level of proportionality, based on the team’s experience.

Because CRA compliance is a conformity problem, it requires a multifaceted perspective and is not limited to a testing problem. The founder has extensive experience in Testing, inspection, and Certification for regulated products, and a seat in the working group drafting the standards your product will be measured against.

External references

Our process

Insight into how it works when partnering with us

1

Reach out - get in touch with our team by phone, email, or live chat so we can start the discovery process.

2

We have an initial meeting so we can get a full understanding of what you are looking for and how we can work together.

3

We will create a comprehensive proposal based on our initial meeting, and present it to your team, either in person or virtually.

4

We collaborate with your company or organization to implement the appropriate plan and framework.

Secure your regulatory cybersecurity compliance in Europe