Technical assessment and implementation at firmware level – complemented by our partner law firm where needed.
From 11 September 2026, the CRA reporting obligations apply to actively exploited vulnerabilities and severe security incidents. The initial early warning is generally due within 24 hours.
From 11 December 2027, the essential requirements of the Cyber Resilience Act apply to products in scope, including conformity assessment and CE marking.
The Cyber Resilience Act is EU regulation and applies across all member states. What I advise on is the concrete implementation for the German market: the German authorities and notified bodies, the documentation practice expected here, and, where legal questions arise, our German partner law firm. I work with you in English, but the regulatory context I know inside out is the German one.
One day of analysis plus a written report: a technical pre-assessment of CRA exposure, product category and required actions. Legal edge cases can be reviewed separately by our partner law firm on request.
You receive a technical assessment with open legal questions, priorities and next steps. Fixed price, credited against a follow-up engagement.
Your products checked against the essential requirements of the CRA, directly at firmware level.
A working process for the 24-hour early warning, the subsequent 72-hour notification and the final report: roles, procedures and templates, verified in a test run.
SBOM pipeline, secure boot, signed updates, vulnerability handling. This is the part you cannot read up on.
For clarity: I advise and prepare things technically; legal advice is provided exclusively by our partner law firm and is commissioned and billed separately. Responsibility for the declaration of conformity and CE marking remains with the manufacturer. Which conformity assessment procedure is required depends on the product category, the harmonised standards applied and any existing certifications. Certain important and critical products require an external assessment.
For torcbrain I developed large parts of the software of an IoT cordless high-torque screwdriver: embedded Linux, a secure bootloader with TrustZone-protected M4 firmware IP protection, secure OTA updates, remote management and device administration via the cloud. The system has been in the field for over two years, and idastroem runs the cloud operations to this day. More in the blog.
Dipl.-Inf., Managing Director of idastroem GmbH
25 years of software development for electronics and industrial automation. I have shipped secure boot, encrypted firmware and secure OTA updates in series-production devices long before the CRA made them mandatory.
30 minutes are enough for a first assessment. Free of charge, no obligation. If I cannot help, I will tell you during the call.
Arrange a call now30 minutes: products, connectivity, deadlines. Afterwards you know whether you need to act.
One day of analysis plus a written report: a technical pre-assessment of CRA exposure, product category and required actions. Legal edge cases can be reviewed separately by the partner law firm on request.
You receive a technical assessment with open legal questions, priorities and next steps. Fixed price, credited against a follow-up engagement.
Gap analysis, reporting process, SBOM pipeline or firmware hardening, depending on what the check turns up. With clear milestones.