Does your product fall under the Cyber Resilience Act (CRA)?

Does your product fall under the Cyber Resilience Act (CRA)?

Cyber Resilience Act without the panic. We help you verify whether your digital product falls under the CRA, what duties apply to you, and what needs to be organized before sale, deployment, or B2B client discussions.

Cyber Resilience Act without the panic. We help you verify whether your digital product falls under the CRA, what duties apply to you, and what needs to be organized before sale, deployment, or B2B client discussions.

launch security

0+

0+

Years of experience

the knowledge that underpins every project we undertake

0/7

0/7

Support in Crisis

Incidents don't keep office hours. We respond while others are still drafting proposals.

0.0

0.0

Average Customer Rating

Clients value our collaboration for the clarity of decisions, calmness, and partnership-driven approach.

0+

0+

Practical recommendations

We deliver concrete solutions that are feasible to implement and have a solid business justification.

0+

0+

Years of experience

the knowledge that underpins every project we undertake

0/7

0/7

Support in Crisis

Incidents don't keep office hours. We respond while others are still drafting proposals.

0.0

0.0

Average Customer Rating

Clients value our collaboration for the clarity of decisions, calmness, and partnership-driven approach.

0+

0+

Practical recommendations

We deliver concrete solutions that are feasible to implement and have a solid business justification.

0

0

Years of experience

the knowledge that underpins every project we undertake

0/7

0/7

Support in Crisis

Incidents don't keep office hours. We respond while others are still drafting proposals.

0%

0%

Understanding

We don't begin with selling. We start by analyzing your problem and situation.

0%

0%

Understanding

We don't begin with selling. We start by analyzing your problem and situation.

Compliance with NIS2, DORA, and GDPR
— without the chaos or overinterpretation.

CRA Product Security Assessment

CRA Product Security Assessment

CRA Product Security Assessment

Are you developing software, a SaaS platform, an app, an IoT device, or a product with digital elements? The CRA may impact you sooner than you think.

The Cyber Resilience Act is not just another "paper-only compliance" exercise. It is a product regulation for any entity placing products with digital elements onto the EU market.

We help you get clear answers to three key questions quickly:

Does the CRA apply to me?
What are my obligations as a manufacturer, importer, distributor, or software house?
What do I need to improve in my product, process, and documentation so I’m not operating in the dark?

Are you developing software, a SaaS platform, an app, an IoT device, or a product with digital elements? The CRA may impact you sooner than you think.

The Cyber Resilience Act is not just another "paper-only compliance" exercise. It is a product regulation for any entity placing products with digital elements onto the EU market.

We help you get clear answers to three key questions quickly:

Does the CRA apply to me?
What are my obligations as a manufacturer, importer, distributor, or software house?
What do I need to improve in my product, process, and documentation so I’m not operating in the dark?

API integration is a strategic initiative that enables seamless connectivity between systems, enhancing operational efficiency and fostering innovation. As IT leaders, your expertise in navigating these integrations ensures robust solutions that drive your organization's success. Embrace this opportunity to advance your capabilities and strengthen your market position through effective partnerships.

What situations
bring clients to us

What situations
bring clients to us

"We're building a SaaS application and aren't sure if the CRA applies to us."

"We're a software house, and our clients have started asking us about the CRA."

"We have an IoT product, an embedded system, or a cloud application, and we aren't sure if it qualifies as a product with digital elements."

“We sell software to B2B clients and want to know exactly what they will expect from us.”

"We have our repositories, dependencies, APIs, integrations, and updates in place, but we don't have them documented for CRA compliance yet."

Compliance with NIS2, DORA, and GDPR
— without the chaos or overinterpretation.

CRA is not NIS2. It is a product regulation.

CRA is not NIS2. It is a product regulation.

CRA is not NIS2. It is a product regulation.

NIS2 primarily focuses on organizations and their operational resilience.
CRA, on the other hand, addresses products with digital elements, focusing on their security, vulnerabilities, updates, technical documentation, and manufacturer liability throughout the entire product lifecycle.

That is why, in the case of CRA, it is not enough to simply ask, "Is our company covered by the regulation?"

You need to ask:

"Does our product fall within the scope of the CRA?"
"What are our responsibilities as a manufacturer, provider, or software house?"
"Do we have the necessary processes for vulnerability management, updates, SBOMs, and technical documentation?"

In their guide for manufacturers, CERT Polska/NASK emphasizes that the CRA requires thinking about security throughout the entire product lifecycle: from design, through development and maintenance, all the way to retirement from the market. They also highlight key areas such as security by design, risk assessment, SBOM, vulnerability handling, security updates, and technical documentation.

Recommended reading: CERT Polska/NASK Guide: Best practices for software security management in the context of the CRA

We help you translate these best practices into a specific product, development process, and documentation, ensuring your team knows exactly what needs to be done.

NIS2 primarily focuses on organizations and their operational resilience.
CRA, on the other hand, addresses products with digital elements, focusing on their security, vulnerabilities, updates, technical documentation, and manufacturer liability throughout the entire product lifecycle.

That is why, in the case of CRA, it is not enough to simply ask, "Is our company covered by the regulation?"

You need to ask:

"Does our product fall within the scope of the CRA?"
"What are our responsibilities as a manufacturer, provider, or software house?"
"Do we have the necessary processes for vulnerability management, updates, SBOMs, and technical documentation?"

In their guide for manufacturers, CERT Polska/NASK emphasizes that the CRA requires thinking about security throughout the entire product lifecycle: from design, through development and maintenance, all the way to retirement from the market. They also highlight key areas such as security by design, risk assessment, SBOM, vulnerability handling, security updates, and technical documentation.

Recommended reading: CERT Polska/NASK Guide: Best practices for software security management in the context of the CRA

We help you translate these best practices into a specific product, development process, and documentation, ensuring your team knows exactly what needs to be done.

How SPIREE helps

How SPIREE helps

We determine whether your product falls under the CRA and identify the specific role your organization plays.

Secure Your Brand's Image with Confidence

We map Cyber Resilience Act (CRA) requirements onto specific areas of your product, development process, and documentation.

Secure Your Brand's Image with Confidence

We assess what's currently missing to ensure your product, processes, and documentation are fully aligned with CRA requirements.

Secure Your Brand's Image with Confidence

We show you what to tackle now, what to handle later, and which actions will have the greatest impact before a client review, audit, or market launch.

What do we evaluate as part of the CRA Product Security Check?

As part of the health check, we analyze:

CRA Scope and the Organization's Role
Whether the product falls under the CRA scope and whether your role is that of a manufacturer, importer, distributor, integrator, component supplier, or a software house supporting a manufacturer.

The Product and Its Digital Elements
Applications, SaaS, firmware, IoT, APIs, admin panels, mobile apps, open-source components, cloud services, integrations, and update mechanisms.

Security by Design
Whether security is an integral part of the design process, rather than an afterthought added just before deployment.

Product Risk Assessment
Whether cybersecurity risks for the product and its users are identified, and whether this assessment is updated when significant changes are made.

SBOM and Dependencies
Whether the organization knows which libraries, components, and dependencies make up the product, and can quickly assess the impact of a newly discovered vulnerability.

Vulnerability Management
Whether there is a dedicated reporting channel, an owner, a triage process, impact assessment, response timelines, documented decision-making, and readiness to cooperate with CERT/CSIRT.

Security Updates
Whether the product features a security patching mechanism, clear communication to users, and a defined support lifecycle.

Technical Documentation and Evidence
Whether there are artifacts demonstrating due diligence: descriptions of the architecture, security mechanisms, components, vulnerabilities, incidents, and risk-related decisions.

Tell us what you are building, and we will check if your product is ready for its first users.

As part of this assessment, we analyze the critical areas that could impact your application's security before launch:

  • secrets and access credentials

  • authentication and access control

  • user data access

  • database and storage rules

  • API endpoints

  • payments and integrations

  • file uploads

  • elements generated or assisted by AI

Our Results

We work with real systems and genuine challenges. Here are the results of our collaborative approach.

Banner Graphic
Clarity

You know whether and to what extent the CRA applies to your product

Banner Graphic
Priorities

You know exactly what needs to be done first, and what shouldn't be overthought.

Banner Graphic
Roadmap

You get a clear, actionable roadmap tailored for your board, CTO, product owner, and development team.

Banner Graphic
Our Track Record

You understand exactly which documents, registers, and artifacts need to be created throughout the software development lifecycle.

Banner Graphic
Clarity

You know whether and to what extent the CRA applies to your product

Banner Graphic
Roadmap

You get a clear, actionable roadmap tailored for your board, CTO, product owner, and development team.

Banner Graphic
Priorities

You know exactly what needs to be done first, and what shouldn't be overthought.

Banner Graphic
Our Track Record

You understand exactly which documents, registers, and artifacts need to be created throughout the software development lifecycle.

Banner Graphic
Clarity

You know whether and to what extent the CRA applies to your product

Banner Graphic
Priorities

You know exactly what needs to be done first, and what shouldn't be overthought.

Banner Graphic
Roadmap

You get a clear, actionable roadmap tailored for your board, CTO, product owner, and development team.

Banner Graphic
Our Track Record

You understand exactly which documents, registers, and artifacts need to be created throughout the software development lifecycle.

Packages

Packages

Choose a level of verification tailored to your product stage, complexity, and risk.


Choose a level of verification tailored to your product stage, complexity, and risk.


CRA Scope & Impact Check

from 2,900 PLN

For companies looking to quickly assess whether the CRA applies to them

evaluating the product and the organization's role,

initial CRA readiness assessment,

identifying core responsibilities,

a prioritized list of key vulnerabilities,

recommended next steps,

a concise summary for the executive board or product owner,

A 30-minute review of your results.

The best choice when a company says: “We don’t know if the CRA applies to us.”

Check the scope of the CRA

CRA Product Readiness Review

from 7,900 PLN

For companies looking to assess the readiness of their product, processes, and documentation.

everything included in the CRA Scope & Impact Check

product lifecycle analysis,

an overview of the vulnerability management process,

reviewing security update strategies,

SBOM, dependency, and component reviews,

a gap analysis against CRA requirements,

a 30/60/90-day roadmap,

a workshop with your product or technical team.

The best choice when a company says, “We know that CRA might apply to us"

Schedule a product review

Premium Launch Assessment

from 12,900 PLN net

For companies looking to practically implement the processes and artifacts required under the CRA

support in designing our vulnerability management process,

security.txt and a vulnerability disclosure channel

templates for vulnerability and incident registers,

SBOM and component management model,

security update procedure,

technical documentation support,

workshops with your product and development teams,

consultation on implementing the recommendations,

The best choice when a company says: "We want to get things organized."

Let's talk about your deployment

Compliance with NIS2, DORA, and GDPR
— without the chaos or overinterpretation.

Still not sure if the CRA applies to your product?

Still not sure if the CRA applies to your product?

Still not sure if the CRA applies to your product?

Start with a brief assessment. Answer a few questions about your product, your organization's role, and your software delivery process to receive an initial recommendation on whether this is an area worth exploring further.

Start with a brief assessment. Answer a few questions about your product, your organization's role, and your software delivery process to receive an initial recommendation on whether this is an area worth exploring further.

Grid
Cta Icon
Cta Icon

Your security begins with a single decision.

We'll help you assess whether your product is ready for its first users.

Grid
Cta Icon
Cta Icon

Your security begins with a single decision.

We'll help you assess whether your product is ready for its first users.

Grid

Your security begins with a single decision.

We'll help you assess whether your product is ready for its first users.