How we help
What we do for you
Seven things to buy, from a free check to monitoring set up in an account you own. Fixed prices, a named engineer on every document, and what each leaves out.
Updated 7 September 2026
Pick the one that matches where you are
We get ordinary products ready for the Cyber Resilience Act. We change how the product is built, then write the paperwork that falls out of it.
Every package has a fixed price, a named thing you receive at the end, and an engineer whose name is on it. You remain the manufacturer throughout: we do the engineering, you keep the responsibility the law gives you.
Almost all of it happens in writing, in a shared tracker, at the times that suit you. Calls are available in European working hours and are often useful, but no part of the work waits for one.
- Check whether the law covers youAutomated scope checkFree
- Know where you standScoping and classification memo€900
- Get ready to report nowReporting Ready€3,500
- See every gap, in orderEngineer-led gap review€4,900
- Be ready for the marketMarket Readyfrom €14,900
- Set up your own monitoringMonitoring set-up, in your own account€1,500
- Train your teamHalf-day training, in-house, up to 8 people€1,500
Check whether the law covers you
Automated scope check
Free
Five minutes on this site, an answer straight away, and nothing to sign.
You answer a short set of questions about your product and get back a plain reading: whether the law reaches it, which group it falls into, which dates apply to you and what to do first. It runs on published rules rather than on a model, so the same answers always produce the same result, and the reasoning is shown next to the answer.
Nobody calls you afterwards unless you ask. If it turns out the law does not reach your product, we say so, and you have spent five minutes.
Know where you stand
Scoping and classification memo
€900per unit
The same question answered properly, in writing, with an engineer's name on it.
You fill in one form in your own time and give us read access to your product documentation. You get back a signed scoping memorandum: whether the law covers each product and version and why, which group it falls into and who has to check your work as a result, the dates that apply to you, how long you should support the product, and the three things to do first. The manufacturer determines the support period so that it reflects the expected time in use; it must be at least five years unless the product is expected to be used for a shorter time.[Art. 13(8)]
If your product falls into one of the stricter groups, we say so and explain what that means for you. Conformity assessment uses the modules in Annex VIII: internal control (Module A) for default products; important class I products may use internal control only when applying harmonised standards, common specifications or a certification scheme; important class II products need a third party (Modules B and C, or H).[Art. 32; Annex VIII] We are honest about one thing here: the chapter that lets the independent bodies exist applies before the main duties do, and when this page was written no body had yet been listed for this law. The chapter on the notification of conformity assessment bodies applies from 11 June 2026, so that notified bodies can be in place before the main obligations apply.[Art. 71(2); Chapter IV] If you are going to need one, it is much better to know that now than in the last quarter before the deadline.
The fee comes off in full against anything you buy afterwards.
Get ready to report now
Reporting Ready
€3,500per unit
The reporting duty has already started, and this is the package that makes you able to meet it. Manufacturers' reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026.[Art. 71(2); Art. 14]
The first thing you receive is code, not a document. We open one change
against your own code that adds four things: a build step that produces
a signed list of every component in the product, a check that stops the
build when a dangerous component gets in, the small standard file
(security.txt) that tells outside researchers where to send a security
report, and a note saying how long the product is supported. Your
engineers review and merge it. That merged change is the first piece of
evidence in your paperwork.
The rest of it delivers:
- a published policy telling outsiders how to report a problem to you, and the person who answers; Manufacturers must put in place and enforce a coordinated vulnerability disclosure policy.[Annex I, Part II, point 5]
- a written plan for what happens when one arrives, keyed to the legal clocks and practised once with your team; For an actively exploited vulnerability: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available.[Art. 14(2)]
- a review of how updates reach your product, and of who inside your company would act on a warning about it;
- the paperwork folder in the structure the law requires, already holding the evidence produced so far;
- a draft declaration for you to complete and sign as the manufacturer.
We work with Python, Node, Java, .NET and Docker, on GitHub Actions and GitLab CI, on one product family in one repository. Anything else we quote separately rather than guess at.
"Ready to report in ten working days" is the target for the core of that list, and the ten days are ours: they do not stop while we wait for a meeting, because there are no meetings in them. We track it day by day and you see the tracker. The contract commits our effort to the target, not a guaranteed result.
Choosing and configuring the tool that watches your components is a separate job with its own price — see set up your own monitoring below.
See every gap, in order
Engineer-led gap review
€4,900per unit
For a firm with more than one product, a bigger team, or somebody internal who already owns security and wants the evidence before the work.
We take a read-only copy of your code, run our scanners over it and compare what we find against the law's requirements, one by one. Products must be designed, developed and produced to meet the product cybersecurity requirements in Annex I Part I, and manufacturers must meet the vulnerability handling requirements in Annex I Part II.[Art. 13(1); Annex I] You get a plain report of what is missing, with the evidence from your own code beside each item, and a plan in priority order that separates what you need now from what you need before the second date. The raw findings and the component list come with it, so your team can start without us.
It is credited in full against getting ready for the market, so in a job that goes ahead it costs nothing. If you are a smaller firm with one product, you do not need this: the package above already tells you where the gaps are.
Be ready for the market
Market Ready
from €14,900per unit
The bigger job, for the date when the rest of the law lands.
The main obligations of the Cyber Resilience Act (essential requirements, technical documentation, conformity assessment, CE marking, importer and distributor duties) apply from 11 December 2027.[Art. 71(2)]Every essential requirement checked against your product and closed or planned; how you build and how you ship updates written down and running; the risk assessment done; the technical file assembled in the structure the law asks for; and the declaration drafted for you to complete and sign. The manufacturer draws up the technical documentation with the content set out in Annex VII before placing the product on the market and keeps it up to date during the support period.[Art. 31; Annex VII]
- Everything you have already paid us comes off the price, in full.
- You can take it as two invoices in two budget periods if one signature is easier to get than another. It is the same total either way.
- It is priced per unit, and a unit is one product family sharing a codebase and a release train — see what one price is for.
Set up your own monitoring
Monitoring set-up, in your own account
€1,500per unit
New weaknesses turn up in other people's code every week and some of them will be in yours, so somebody has to keep looking. Under this law that somebody is the manufacturer, which is you. This is the piece of work that makes it easy.
We compare the monitoring tools that suit your stack and your size and write down which one we would choose and why. We set that tool up in an account you own and pay for, against your own component list, and route the alerts to the people in your company who would actually act on one. We give you a one-off picture of what is vulnerable in your product today, so you know what you are starting from, and one page saying what to do when an alert arrives: who is told, what they check, what the first message says, who sends it, what goes in the log. Then a short recorded walkthrough for your team, the keys, and we step back.
You own the tool and the account from that moment, and from then on you watch your own product on something that keeps working whether or not you ever hear from us again. That is the main reason to do it this way round.
What it is not. We do not watch your product. We are not sent your alerts, we owe you no response time, we run no rota and nobody here is on call, at any hour of any day. We are not a security operations centre and not an incident response service. The tool's own subscription is yours and is not included in our fee. We hold your credentials only while we are setting the tool up and give them back at hand-over. The public sources any tool reads are other people's and can be late or incomplete. You decide whether a weakness is really being exploited, you decide what to report, and you send it.
An actively exploited vulnerability is one for which there is reliable evidence that malicious code was executed by an actor on a system without the permission of the system owner; a severe incident is one that has an impact on the security of the product.[Art. 3 (definitions); Art. 14(3)]If we recommend a particular tool, we take nothing from the company behind it. No referral fee, no commission, no partner status. We put that in writing at the same moment, and the choice is recorded in your decision log as a decision you took on our advice. What we suggest is what fits your product and your team, and there is no other reason for it to be on the list.
It is one fee, once, per unit, and the second and later units cost less, because by then it is the same tool and the same routes with a different component list.
Train your team
Half-day training, in-house, up to 8 people
€1,500per session
Half a day, in your own building or on a call, for a group rather than a seat: what the law asks of engineers, how the component list and the build checks work, and how the plan runs when something happens. It ends in a short practice run.
What we do not do
This is the part of the page we would want to read first, so it is not in the small print. Knowing where we stop is what lets the price be a fixed number, and it is how you can tell what you still have to arrange somewhere else.
Unless the contract says otherwise, we do not do and are not responsible for:
- breaking into your systems to test them, certifying anything, or attesting that a product is secure;
- changing your product, your firmware, your infrastructure or your suppliers, or fixing what the scanners find (we add build configuration and policy files; your engineers review and merge them);
- monitoring your product, receiving your alerts, triaging them, answering within any period, or being on call — at any hour, on any day, on any package;
- sending anything to an authority, in any circumstances, or speaking for you in front of one;
- legal advice, or deciding what your legal obligations are;
- hardware, radio, safety or any other regulatory regime;
- the subscription to any tool we help you choose or set up;
- any promise that a product is free of weaknesses, or that every weakness, attack or incident will be found;
- the duties of your importers, distributors or customers;
- work on products, versions or components the contract does not name.
None of that is us being careful with you. Every one of those lines is somebody else's job, and telling you which ones early is more use than finding out late.
We use scanners and AI-assisted tools for parts of the work. Whether the law covers you, which group your product is in, how serious a finding is and which deadline applies are worked out by published rules, never by a model. Every document is released by a named engineer, and your code is never used to train or test a model. The detail is on the how we use AI page.
How it runs
The free check
Five minutes on this site, no account and no call. Most people know after it whether they need us at all.
One form, in your own time
About half an hour, saved as you go. It asks what the product is, what is in it and how it is built — the questions we would otherwise spend a morning asking you.
Read-only access to one repository
A link and a token, ten minutes of an engineer's day. Nothing leaves the EU.
The proposal and the contract
A statement of work listing products, deliverables and fees, signed electronically.
The work, on a tracker you can see
What is done, what is next, what we need from you and by when. Written updates, not meetings.
Approvals in writing
Everything we hand over gets a page with a plain summary, the file itself, and a button to accept it or to tell us it is wrong. You have ten business days and you can use them at nine in the evening.
The practice run, on your own afternoon
We send the exercise and the script; your team runs it when it suits them and sends us the notes; we read them and write back what to change.
Hand-over, and it ends
A short recorded walkthrough you can watch when it suits you, the folder with everything in it, and — if you took the monitoring set-up — the keys to your own tool account. The statement of work finishes there. Nothing carries on afterwards and nothing renews by itself.
Written questions get an answer within one working day. Where writing is the wrong tool — deciding something, or a bad day — a call is the right one: ask for it and we book a slot in European working hours, usually within a couple of days. What we will not do is make the work depend on one. We are two engineers rather than a service desk: nobody here is on call, and we would rather say so than promise a phone that is always answered.
Every package is a one-off fee. Larger ones are invoiced half on signature and half on delivery, smaller ones once in full, with the threshold written into your statement of work. Every decision you take on our advice goes into a log that becomes part of your evidence.
The fix-it warranty
If a deliverable does not match the statement of work, tell us in writing inside the ten-business-day acceptance period: we correct it and deliver it again at no charge, and the corrected version gets a fresh acceptance period. For twelve months after delivery we extend the same free correction and re-delivery to a deliverable that falls short of the reasonable skill and care we owe — including one your own customer or a distributor turns down for a reason inside the agreed scope. That is Article 7.4 of the services agreement you sign.
We give no warranty about the position a market surveillance authority may take on scope, classification or conformity: nobody can, and Article 13.4 of the same agreement says so. The warranty does not cover reasons outside the agreed scope, changes in the law or the standards after delivery, or decisions you took against our advice. Where a correction would need access to a tool account we have already handed back to you, we tell you what to change and you make the change.
Talk to an engineer
Describe the product and we will say which package fits, or that none does.