EmberKat

Cyber Resilience Act consulting

Cyber Resilience Act Consulting

EmberKat helps software manufacturers turn Cyber Resilience Act duties into product-security lifecycle work, SBOM and vulnerability processes, secure development controls and evidence.

Discuss the scope
Typical durationUsually 3–6 weeks
Starting priceFrom €18,000 excl. VAT
Commercial basisWritten scope and proposal

Service definition

From CRA duties to product-security delivery

The engagement maps the product, its dependencies and its development process to the CRA obligations that need to be owned before conformity assessment, customer scrutiny or market-surveillance questions.

Scope

Work included in the scope

  1. 01

    Product scope, role and CRA applicability assessment

  2. 02

    Product-security lifecycle and secure-development review

  3. 03

    SBOM ownership, dependency inventory and supplier inputs

  4. 04

    Vulnerability handling, coordinated disclosure and reporting route

  5. 05

    Technical documentation and evidence-gap assessment

  6. 06

    Implementation sequence, owners and release controls

Client problems

Use this service when

  1. 01

    The software is a product, but security work is still treated as a project after release.

  2. 02

    Customers ask for an SBOM and nobody owns the answer across releases.

  3. 03

    Vulnerability handling depends on individual judgement and inboxes.

  4. 04

    Product, engineering and compliance teams have different views of readiness.

Deliverables

Documents and decisions provided

  1. 01

    CRA applicability and product-scope position

  2. 02

    Product-security lifecycle and control map

  3. 03

    SBOM, vulnerability and disclosure operating model

  4. 04

    Technical documentation and evidence-gap register

  5. 05

    Prioritised implementation and release-readiness plan

From the glossary

coordinated disclosure
The agreed process for handling a reported security flaw: who is told, in what order, and by when.
conformity assessment
The formal check that a product meets its legal requirements before it is placed on the market.
SBOMSoftware Bill of Materials
A list of every component inside a piece of software — an ingredients label, in a form a machine can read.
CRACyber Resilience Act, Regulation (EU) 2024/2847
An EU law that puts security requirements on the product itself — effectively anything containing software that is sold in the EU.
The full glossary

Related engagement

Regulated Product Software

The environment page explains how CRA duties, NIS2 pressure and customer evidence requests meet in practice.

View engagement