Regulation (EU) 2024/2847  ·  Article 14

Proof,not paperwork.

We keep connected products compliant with the EU Cyber Resilience Act, NIS2 and UN R155. Not a readiness report. We run the SBOM, watch it every day, and stand behind you when a vulnerability has to be reported on a clock.

Until CRA Article 14 reporting applies
days
hours
min
sec
CRA in force · 10 Dec 2024preparation windowArt. 14 · 11 Sep 2026

From 11 September 2026, an actively exploited vulnerability in your product is a 24-hour filing. By express derogation this covers products already on the market, not only new ones.

The windows

Three deadlines, counted from the moment you become aware

Not from when you finish investigating. That distinction is what makes Article 14 an operational problem rather than a documentation one.

24h
Early warning
To ENISA and your CSIRT, indicating whether exploitation appears malicious.
72h
Notification
The product, the nature of the vulnerability, and any corrective measures available.
14d
Final report
After a corrective measure exists: severity, impact, root cause, and the fix.

What Article 14 actually requires →

Check

Are your products in scope?

Four questions. No email required, nothing is sent anywhere, and the answer is sometimes no.

1. Do you place products on the EU market?
Making them available for distribution or use in the EU in the course of a commercial activity, under your own responsibility.
2. Do those products contain software, firmware, or a data connection?
A product with digital elements. A robot controller, a smart meter, an EV charger and an industrial gateway all qualify. So does software sold on its own.
3. Do you sell them under your own name or trademark?
Including where the software was written by a supplier or the hardware is manufactured for you.
4. Do you already have products in the field in the EU?
Shipped and in use, not just planned for the next release.
Regulation (EU) 2024/2847, Art. 3, 13, 14 and 69(3). Indicative only, not legal advice.
What we do

Three services, in the order most people need them

Onboard
SBOM baseline per product family, toolchain integration, and a vulnerability handling process set up to CRA Annex I Part II.
from 10,000 EUR one-off
Monitor & report
Continuous vulnerability monitoring against your SBOM, exploitability triage, and reporting support inside the 24h / 72h / 14-day windows.
from 1,800 EUR / month
Test & verify
Fuzzing and hardware-in-the-loop campaigns in our Bucharest lab. Evidence you can put in a technical file.
from 15,000 EUR / campaign
Deliverable

What you actually receive

Not a maturity score. Artefacts you can hand to an auditor, a customer, or a market surveillance authority.

finding · redacted exampleCycloneDX 1.6
vulnerabilityCVE-2026-4471  ·  CVSS 8.8  ·  exploitable in your configuration
componentopenssl 3.0.11  →  3.0.14
productcontroller-fw 4.2.x  ·  3 SKUs affected
sbomsha256:9f2c…a17d
observed2026-09-14T08:41Z
early warningdue 2026-09-15T08:41Z

Illustrative and invented. Real findings are never published.

Who this is for

Robotics manufacturers and industrial machine builders placing connected products on the EU market. Automotive tier-2 and tier-3 suppliers already exposed to UN R155. Manufacturers with NIS2 obligations on their own operations.

Typically companies with real engineering teams but no dedicated product security function, and no appetite to build one.

Why us
  • We operate the obligation, we do not just assess it. Advisory firms hand you a gap analysis. We carry the monitoring and the filing.
  • A real lab, not slideware. Fuzzing, hardware-in-the-loop and binary analysis in Bucharest.
  • Vendor-neutral where it counts. In compliance work we sell no tools and take no commission from any vendor whose product we assess. Our separate go-to-market practice is disclosed and firewalled.
  • Twenty years in the field. Automotive and industrial cybersecurity, including global head of cybersecurity and privacy for an HMI business unit at a tier-1 supplier.

Find out whether you are in scope

A free 45-minute call. No deck. We tell you what the September date means for your products, and what it does not.