Niteo
EU Cyber Resilience Act

24 hours to report an exploited vulnerability.Most industrial teams have no process for hour one.

From 11 September 2026, every manufacturer selling connected products in the EU must report actively exploited vulnerabilities within 24 hours — including products already in the field. We audit the layer that makes that possible: firmware, companion app, update chain.

30 min · No pitch · You'll leave knowing where you stand

Built by the team behind Hager Charge — iF Design Award Gold 2025

Hager Group
EIA Tech
Celad
0h
To report an actively exploited vulnerability
0M
Or 2.5% of global turnover — maximum penalty
0 yrs
Minimum security-update support period

The CRA doesn't catch companies out on paperwork. It catches them out on engineering.

Three gaps show up in almost every connected product we look at.

Nobody owns hour one.

A researcher emails you on a Friday about a vulnerability being exploited in the field. Who files the early warning within 24 hours? Who writes the 72-hour notification? Most teams find out they have no answer during the incident itself.

No SBOM, no signed update path, no evidence.

The CRA expects a machine-readable software bill of materials for every product you ship, security updates delivered through a mechanism users can trust, and documentation that proves both. If your firmware and app releases can't produce that today, December 2027 is closer than it looks.

Compliance consultants don't read your firmware.

Legal advisors map the regulation. Process auditors check your documentation. Neither one opens your BLE provisioning flow, your update signature verification, or how your app stores credentials — which is where the actual exposure lives.

The three dates that matter

One regime is already binding. The next begins on 11 September 2026. The heavy one lands in December 2027.

  1. Already in force

    1 August 2025

    Radio Equipment Directive cybersecurity requirements

    Any product with Wi-Fi, Bluetooth or cellular already has to meet cybersecurity requirements under RED Articles 3.3(d), (e) and (f). This is live today — not future work.

  2. Reporting begins

    11 September 2026

    CRA reporting obligations

    Actively exploited vulnerabilities and severe incidents must be reported through the EU Single Reporting Platform: early warning within 24 hours, full notification within 72 hours. The final report follows within 14 days of a fix for vulnerabilities, and within a month for incidents. This applies to products already on the market.

  3. Full application

    11 December 2027

    Every essential requirement

    Secure-by-design and secure-by-default, SBOM, coordinated vulnerability disclosure, free security updates across a declared support period of at least five years, technical documentation, conformity assessment and CE marking for cybersecurity.

Penalties reach €15 million or 2.5% of global annual turnover. But the realistic near-term risk is simpler: a customer's procurement team asks for your CRA file, and the deal stalls.

Ten working days. Then you know.

A technical audit of the layer we build for a living — firmware, companion app, update chain, and the process behind them.

1

Inventory

Days 1–3

We build the software bill of materials for your firmware and app releases, map every radio interface, endpoint and permission, and flag end-of-life or known-vulnerable dependencies.

2

Review

Days 4–8

Static review against the CRA essential requirements: secrets handling, transport security, credential and key storage, BLE pairing and provisioning, update signature verification, downgrade protection, exposed components and debug artefacts left in release builds.

3

Report

Days 9–10

Every finding mapped to the CRA requirement it touches, with severity, remediation and effort. Plus a one-page summary your management can read, and a prioritised backlog your engineers can start on Monday.

After the audit

Day 10+

Thirty days of follow-up questions while you align internally. If you want the remediation done, we quote it fixed-price. If you want it done in-house, the backlog is yours to keep.

What you get

Three artefacts. €4,000 fixed. Ten working days.

Findings mapped to CRA requirements

Not a generic security report. Every finding is tied to the specific requirement it touches, with severity, confidence, remediation and an effort estimate — so you can defend the priority order internally without re-doing the analysis.

Written so an engineer can act on it, not just file it.

A machine-readable SBOM

Generated from your actual firmware and app releases, with end-of-life and known-vulnerable dependencies flagged. This is the artefact the CRA expects you to maintain for the product, kept current as each release changes it — and most teams have never produced one.

Plus how to generate it in CI, so it stays current after we leave.

A 24-hour reporting playbook

Who receives a vulnerability report, who decides whether it is reportable, who files within 24 hours, what the 72-hour notification contains and where it goes. A named owner and a path you have walked through before you need it.

The thing nobody has until the incident.

Pricing

One number. No day rate. No open-ended discovery.

€4,000

Fixed. Ten working days. 50% on signing, 50% on delivery of the report.

Included

  • Dependency inventory and machine-readable SBOM for one product line
  • Static review of firmware, companion app and update chain for that product line, against the CRA essential requirements
  • Findings report — every finding mapped to a CRA requirement, with severity, remediation and effort
  • One-page executive summary and a prioritised remediation backlog
  • 24-hour reporting playbook, a 90-minute readout with your team, and 30 days of follow-up

Not included

  • Legal advice and formal conformity assessment — we cover technical readiness and refer the rest
  • Penetration testing or any live testing against your production infrastructure
  • Notified-body assessment for important or critical product categories
  • The remediation itself — quoted separately, fixed-price

Two design-partner slots at €3,000, in exchange for a testimonial and permission to name you. After that, €4,000.

€4,000. Ten working days. Then you know where you stand.

Most teams suspect there is a gap between what the regulation expects and what their product does. The audit replaces the suspicion with a list.

Is this for you?

This audit is shaped for one situation. Honesty saves us both a meeting.

Manufacturers with connected products already in the field

You sell hardware with a companion app or a cloud connection into the EU. Products shipped years ago are still yours to report on, and nobody has looked at that layer through a CRA lens.

Best fit · Products in the field · Reporting duty from 11 Sept 2026

Teams with no embedded security capacity in-house

Your engineers build the product. Nobody owns SBOMs, update signing or a vulnerability intake channel — not through carelessness, but because it was never anyone's job.

Capability gap · No named owner

Product leaders who need to defend a budget

You suspect there is work to do before December 2027, and you need something concrete — findings, effort estimates, a priority order — to take to a steering committee.

Evidence for a decision · Fixed price

Not sure? Book the call — we'll tell you within ten minutes if the audit is worth your money.

Real project

The layer the CRA regulates

Industrial IoT · EV chargingHager Group

Connected mobile app for electric vehicle charging stations

The challenge

An industrial group needed a mobile application connected to its electric vehicle charging stations: architecture from scratch, BLE communication with the hardware, installer and end-user flows, and an update path that would still work years after installation.

Our approach

  • Complete mobile and cloud architecture defined from zero, including provisioning and update paths
  • Deep BLE integration, field-tested on production charging stations
  • Progressive delivery with continuous validation on real industrial hardware

Result

Mobile app delivered in 8 months from scratch, in parallel with hardware development. Firmware interface, companion app, update chain: this is precisely the layer the Cyber Resilience Act now regulates.

8
months to delivery
0
existing stack
100%
field-tested

Frequently asked

The questions every engineering and product lead asks first.

Find out where you actually stand

Book a 30-minute call. No pitch deck. We'll tell you whether the audit is the right next step for your product — or whether it isn't.

1
Book the call
2
We confirm scope and product line
3
Audit starts — report in ten working days

30 min · No pitch · No commitment