Looking for a penetration test? Fixed-scope engagements for GDPR, NIS2 & DORA.Get a quote today →
Request a Quote
Compliance

Cyber Resilience Act Security Testing

Reporting obligations under Article 14 began 11 September 2026; the full Annex I essential requirements apply from 11 December 2027. If you sell software into the EU, that applies to you regardless of where you're based.

At a Glance
Included WithAny Testing Engagement
Delivery FormatAudit-Ready Report
Best ForSoftware & Connected-Product Vendors Selling into the EU
FrameworksCRA Annex I

Built for the auditor, not just your team

Every engagement includes reporting written for direct submission, not internal notes you have to reformat before your auditor can use them.

01

Secure-by-Design Testing (Annex I, Part I)

Core Coverage

Manual testing against the product-property requirements in Annex I Part I: no known exploitable vulnerabilities at release, secure-by-default configuration, and proper access control and encryption.

  • The same manual application and API testing we run for any engagement, mapped explicitly to Annex I line items.
02

Vulnerability Handling Review (Annex I, Part II)

Core Coverage

We review whether your coordinated vulnerability disclosure (CVD) policy, intake channel, and remediation workflow meet the lifecycle-handling requirements in Annex I Part II.

  • Includes a look at your SBOM practices — you can't meet the reporting deadline without knowing what's in your software.
03

Article 14 Reporting Readiness

Core Coverage

We help you pressure-test whether you could meet the 24-hour early warning, 72-hour notification, and 14-day final report timeline for an actively exploited vulnerability, before you have to do it for real.

  • This obligation is already active as of 11 September 2026.
04

Conformity Documentation Support

Core Coverage

Findings and remediation evidence structured to feed into the technical documentation your CE-marking submission will eventually need.

  • Useful groundwork ahead of the December 2027 full-application deadline, whichever conformity route applies to your product class.

What to expect

What's Included

  • Manual security testing mapped to Annex I Part I product requirements
  • Review of your vulnerability handling process and CVD policy against Annex I Part II
  • A practical check against the Article 14 reporting timeline
  • Documentation structured to support later technical-documentation and CE-marking work

Deliverables

  • Audit-ready report with findings mapped to specific Annex I clauses
  • A gap list against your vulnerability handling and disclosure process
  • Retest evidence once findings are closed
  • A summary suitable to hand to whoever owns your CRA compliance programme

Ready to get ahead of the December 2027 deadline?

Tell us what you're selling into the EU and where you are on Annex I readiness, and you'll get a proposal back directly.