Cyber Resilience Act
Does the new EU cyber law apply to your product?
If your company sells anything with software inside it in Europe, it probably does — wherever in the world your company sits. Six questions tell you for certain.
Two minutes, no sign-up, answer on screen. Leave an email only if you want it as a PDF.
What you make
Question 1 of 6
What we do, and what stays yours
We are engineers, and we promise two things. The first is the whole job, not a slice of it: the scoping, the changes to your build, the policies, the plans, the paperwork, and the monitoring set up in an account you own. The second is the price. A fifteen-person manufacturer can afford all of it, because software does the expensive parts and we charge for the judgement rather than for the typing.
What we do not do is take the duty off your hands, because the law does not let anyone do that. Here is the line, before you read anything else.
What we do
We work out where you stand and write it down. We look at your code with our tools and tell you what is missing. We propose the build changes, write the policies, plans and paperwork with you, and set up the monitoring you will run afterwards, in your own account. A named engineer reads and signs every document you get.
What stays yours
You remain the manufacturer. You decide what to change and when, your engineers merge the changes into your own code, you sign your declaration, you put the CE mark on the product, and you decide whether an event has to be reported and send the report. You watch your own product too: the tool is in your account, the alerts go to your people, and the clock is yours. When a component you ship turns up on a public list of weaknesses under attack, that is a signal, not a verdict.
What we are not
We are not a law firm, a certification body, or your authorised representative in the EU. We do not give legal advice, sign your declaration, put the CE mark on anything, issue a certificate, or promise that every weakness in your product will be found. We do not watch your product, we are not sent your alerts, and nobody here is on call. Nobody can tell you in advance what view an authority will take, and we do not pretend to. If you need a representative in the EU, we introduce one.
A manufacturer may appoint an authorised representative in the Union by written mandate; the Regulation does not oblige non-EU manufacturers to appoint one.[Art. 18]Two dates, and they follow the product
Since 11 September 2026, if someone is attacking a weakness in your product, you have to tell the authorities, and fast. For an actively exploited vulnerability: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available.[Art. 14(2)]
From 11 December 2027, the rest applies: how the product is built, the paperwork behind it and the CE mark. A product that does not meet the rules cannot be sold in the EU.
The duty follows the product into the EU market, not your postcode. A maker in Manchester, Boston or Taipei that sells into Europe carries the same duties as one in Lyon, and the rules follow what your company does rather than how big it is.
The Regulation applies to products with digital elements made available on the Union market in the course of a commercial activity, whatever the size or place of establishment of the manufacturer.[Art. 2(1); Art. 3]Fines reach €15,000,000 or 2.5% of worldwide annual turnover, whichever is bigger. But the first pressure usually comes from a customer or a tender asking you for evidence.
What you get from us
You find out where you stand
Whether the law covers each product and version, which group it falls into, which dates apply to you and what to do first. In writing, signed by a named engineer.
You get it set up, not written up
We propose the build changes as a change your own engineers review and merge, and we write the policies, the plan and the paperwork around them. A slide deck is not a deliverable here.
You end up watching it, and owning the tool
We help you choose a monitoring tool, set it up in an account you own against your own component list, send the alerts to your own people and hand you one page saying what to do when one arrives. Then we give you the keys. You watch your own product from that day on, on a tool that keeps working whether or not you ever hear from us again.
How the work actually happens
Almost all of it is in writing. You do your part when it suits your week; we do ours and hand it back. Nothing sits waiting for a slot in a shared diary.
You answer, in your own time. We send one short brief: read access to your repository, who owns what, and a handful of questions. Most teams finish it in about an hour, spread over a few days.
We work in ours. The scanning, the drafting and the paperwork happen on our side, outside your working day. Each piece comes back in writing with a plain summary and one question: is this right?
You approve in writing. Every deliverable arrives with a decision to take and ten working days to take it. Saying yes needs no meeting.
You rehearse it once, yourselves. We send the exercise and the script; your team runs it on an afternoon that suits you and sends us the notes. We read them and write back what to change.
Where a call earns its place
We book calls in daytime Paris hours for the things writing does badly: the first conversation, a judgement call, a bad day. They are not how the work gets done, and that is deliberate — it is what keeps your engineers out of meetings and the price where it is. Written questions get an answer within one working day. We are two engineers, not a service desk: nobody here is on call, and we would rather say so than promise a phone that is always answered.
What you can run yourself afterwards
You should not need us in a year. Everything we set up — the monitoring included — runs on tools you own, is written in the words your team uses, and needs no compliance department to operate.
One page to follow when something happens
Who is told, what they check, what the first message says, who sends it. It fits on a page because someone has to be able to use it at eight in the morning.
A release that produces its own evidence
Every time your team makes a new release, the list of what is inside your product comes out of that same process, automatically, and the release stops if it does not. Nobody has to remember.
A folder that stays where you left it
Your paperwork sits in your own systems, in the structure the law asks for, with the evidence already filed against each part. Keeping it up to date is a filing job, not a project.
What it costs
Five things. Two of them are the two dates, one leaves you watching your own product, and two are ways to start without committing to anything.
- To find out whether the law reaches you at allAutomated scope checkFree
- To know where you stand, in writingScoping and classification memo€900per unit
- To be able to report, from now onReporting Ready€3,500per unit
- To be ready for the market laterMarket Readyfrom €14,900per unit
- To watch your own product, on your own toolMonitoring set-up, in your own account€1,500per unit
Whatever you pay on the way in comes off the bigger job, in full — not a percentage and not a voucher. Every price is published before you talk to us, and it is one euro price wherever your company is. Nothing on that list is monthly and nothing renews by itself. What each one includes, and what it leaves out, is on the pricing and services pages.
Why a small company can afford all of this
Because software does most of the work. Your component list, your reporting policy, your handling procedure and your build changes are produced from your own repository by tools we wrote. An engineer then reads every line and puts their name on it. The machine does the volume; a person does the judgement; you are paying for the judgement. That is what lets a fifteen-person manufacturer buy the whole advisory instead of the slice it can afford, and it is the point of the exercise: getting the barrier to compliance down far enough to step over.
It is also why we do not sell you a watch. Anything a consultancy watches for you is people's time on a retainer, so it always ends up expensive. A monitoring tool in your own account costs a fraction of that, it does the same watching, and it does not stop the day you stop paying us. Setting it up once and showing your team how to run it is both the cheaper arrangement and the honest one — you are the manufacturer, so the watching was always going to be yours.
We are two engineers. We have shipped software in five Horizon Europe projects — VOXReality, UTTER, CORTEX2, ResilMesh and PoliRuralPlus — and we put our own product through this work before selling it to anyone. The result is public on the proof page. [LOGO PERMISSION STATUS TO CONFIRM]
Being two is also why the work is written down rather than talked through: a process a small firm can actually operate has to survive everybody being busy, on your side and on ours.
We work in English, in every country the law reaches. Your code stays in Europe and is never used to train anything.
If something we deliver is not right
Tell us inside the ten-business-day acceptance period that a deliverable does not match what we agreed, and we correct it and deliver it again at no charge. For twelve months after delivery, the same free correction covers a deliverable that falls short of the care and skill we owe you — including one your own customer or a distributor turns down for a reason inside the agreed scope.
Nobody can promise the view a market surveillance authority will take of your file, and we do not. The full wording is on the services page.
Not sure where you stand?
Thirty minutes, or a written answer within one working day if you would rather not book anything. You describe the product, we tell you where it stands and what it would take. No slides.