A jointly scoped pilot with agreed systems, examples and acceptance criteria.
Set up component inventory and SBOM generation for one build
Make technical intake, assessment and handling of vulnerabilities traceable
Test release evidence and an agreed reporting workflow using one scenario
Scope, project price, schedule and required provider services are agreed before commissioning. Handover includes the agreed technical documentation and introduction.
Maintain component advisories and technical evidence for one product; agree response times and specialist responsibilities separately.
Technical takeover of the agreed existing solution
Agreed monitoring, troubleshooting and change maintenance
Documented handover of open issues and completed changes
Monthly price, allowance, service hours, term and cancellation are agreed separately. Infrastructure, licences and on-call support are included only when explicitly offered.
Product description, distribution model and clarified responsible role
Build process, dependencies and current handling of security reports
A description is enough for your first enquiry. We will then agree suitable ways to exchange files and arrange access.
What the scope covers
Technical preparation for the agreed product scope. No conformity assessment, CE approval, legal advice or promise of complete CRA compliance. Applicability, including open-source and service cases, must be clarified separately.
We check the package against your project. Your enquiry is non-binding; commissioning and scheduling are agreed afterwards.
UNDERSTAND THE TOPIC
Preparing for the CRA: an SBOM needs a working process.
The Cyber Resilience Act concerns products with digital elements within its scope. The European Commission identifies 11 September 2026 for certain reporting obligations and 11 December 2027 for the main obligations. Particular roles and product situations have specific provisions; classification must precede an implementation plan.