Applicability check & initial analysis
We clarify applicability, your role (manufacturer, importer, distributor) and the product classification – so you know what’s actually coming your way.
Cyber Resilience Act · Regulation (EU) 2024/2847
We guide SMEs safely to conformity.
Specialised CRA consulting for small and medium-sized manufacturers – from the applicability check to CE conformity. Pragmatic, clear and without corporate overhead.
Are you affected?
The CRA applies to “products with digital elements” – hardware and software placed on the EU market that connect directly or indirectly to a device or network. Many small manufacturers don’t realise they qualify as a manufacturer under the CRA – with all the obligations that entails.
Our framework
At the heart of our consulting is our own cyber-security compliance framework – created from a master’s thesis at the University of Regensburg and proven in industrial practice. It systematically determines the cyber-security maturity of connected IIoT and OT systems and turns the flood of requirements into a clear, actionable path.
Instead of working through requirements standard by standard, the framework consolidates overlapping controls from standards and regulation into a single catalogue ordered by maturity:
The OWASP Software Assurance Maturity Model serves as a measurable maturity model. The first goal is Maturity Level 1 in “Policy & Compliance”.
The OWASP IoT Security Verification Standard provides the structure and three security levels (SL1–SL3) as a common language.
OWASP ISVS and IEC 62443 are mapped against each other, making overlaps and gaps visible. The result is the Standard Requirements Catalog (SRC).
The SRC is enriched with the requirements of the Cyber Resilience Act, producing the Compliance Requirements Catalog (CRC).
All requirements are assigned to security levels SL1–SL3 and extended with documentation- and cloud-specific topics.
A compliance questionnaire makes the maturity measurable and comparable; a dynamic policy framework keeps it adaptable to your environment.
Built on established standards
Services
A clear path in six building blocks – bookable individually or as end-to-end support.
We clarify applicability, your role (manufacturer, importer, distributor) and the product classification – so you know what’s actually coming your way.
A target/actual comparison against the CRA requirements based on our own framework (OWASP SAMM & BSI), including a maturity rating from SL1 to SL3.
Risk management, SBOM, vulnerability handling, secure SDLC with quality gates, CE declaration of conformity and technical documentation – prioritised and feasible.
Ready-to-use templates for processes, technical documentation and conformity evidence – so you don’t have to reinvent the wheel.
“What is the CRA?” for decision-makers, awareness for the team and technical training for development departments – clearly prepared.
A concept for technically supporting your processes – such as continuous vulnerability monitoring – tailored to your infrastructure.
How we work
Free & non-binding – plus applicability check.
Assessment & maturity (SL1–SL3).
Prioritised steps with effort.
Support & ready-made templates.
Evidence & CE marking.
Deadlines
About us
We’re not a large consultancy with off-the-shelf slide decks. We specialise in the Cyber Resilience Act and work as equals with small teams – in plain language and in feasible steps.
Author of the CRA compliance framework (M.Sc. Management Information Systems, University of Regensburg). Focus: cybersecurity for IIoT/OT systems, from gap analysis to CE conformity.
LinkedIn profileInformation-security consulting with a focus on CRA conformity and security processes for small and medium-sized manufacturers.
LinkedIn profileCRA today. More tomorrow.
Our focus is clearly on the Cyber Resilience Act. Beyond that, we will also support you with further security and compliance topics over time.
Frequently asked
Contact
A free, non-binding initial consultation usually clarifies the most important question right away: are you affected – and how big is the effort?
Note: we provide consulting on cybersecurity and CRA conformity – not legal advice.
Write to us
The fastest way to reach us is by email. Briefly describe your product and your question – we’ll get back to you promptly with a suggested time.
kontakt@ls-cybersecurity.eu