Products with digital elements must comply with essential cybersecurity requirements under the Cyber Resilience Act (CRA). Conformity is indicated by the CE marking. Only compliant products may be placed on the market!
Reporting Obligations
11.09.2026
Full CRA Applicability
11.12.2027
Incident Notification
24h
Initial Assessment
72h
Final Report
14 Days
We help you through each step to implement a defense-in-depth architecture from processes to products to deliver secure products and services to your customer.
Effective management requires dedicated toolsets across the entire product lifecycle.
Determine Applicability
All products with digital elements are in scope – including the railway sector.
Cybersecurity Risk Assessment
Security measures must be selected based on a risk approach.
Security-by-Design
Products must integrate cybersecurity throughout design and development.
Vulnerability Management
Identify, assess, and remediate vulnerabilities from development through the end of the support period.
Status Assessment
Existing products, processes, development – where do you stand?
Roadmap
Defining priorities to deliver ongoing projects and ensure future products are CRA-compliant.
Implementation
Executing all steps alongside your team – risk management, security-by-design, documentation, and process definition.
Lifecycle Management
Deploying tooling for efficient vulnerability management and incident reporting.
Clear targets, structured implementation
As individual as your products. Tailored solutions built for efficiency.
Turning mandatory compliance into competitive advantages.
We combine proven open-source tools in an online dashboard to support CRA product-security efficiently, repeatably and comprehensibly.
Tool Selection and Architecture
Suitable tools, secure architecture and clear responsibilities
Setup of the Online Dashboard
Central cloud-based platform for transparency and collaboration on-demand in your environment
Integration in your Secure Development Process
Automated workflows and integration in your existing CI/CD-pipelines and your existing development process to reduce friction
Assessment, Reporting and Recommendations
Meaningful reports and prioritized measures for your CRA-readiness
Status of your components, vulnerabilities and licences in one dashboard
SBOMs and reports for CRA-relevant products
Repeatable checks and clean prioritization of measures
INCYDE GmbH
Unter den Linden 21
10117 Berlin