Founding phase: Lehner & Szecsey is currently being established. Some content and details are still being finalised – feel free to get in touch with us already today.

Cyber Resilience Act · Regulation (EU) 2024/2847

The CRA affects almost every connected product.

We guide SMEs safely to conformity.

Specialised CRA consulting for small and medium-sized manufacturers – from the applicability check to CE conformity. Pragmatic, clear and without corporate overhead.

Are you affected?

If your product is connected, you probably are too.

The CRA applies to “products with digital elements” – hardware and software placed on the EU market that connect directly or indirectly to a device or network. Many small manufacturers don’t realise they qualify as a manufacturer under the CRA – with all the obligations that entails.

  • IoT devices
  • Connected machines / OT
  • Embedded systems
  • Software & apps
  • Cloud-connected products
  • Components & firmware
Note on existing products: The reporting obligations from 11 Sep 2026 also apply to products already on the market before 11 Dec 2027. Starting only in 2027 is too late.

Our framework

A scientifically grounded compliance framework.

At the heart of our consulting is our own cyber-security compliance framework – created from a master’s thesis at the University of Regensburg and proven in industrial practice. It systematically determines the cyber-security maturity of connected IIoT and OT systems and turns the flood of requirements into a clear, actionable path.

The scientific concept

Instead of working through requirements standard by standard, the framework consolidates overlapping controls from standards and regulation into a single catalogue ordered by maturity:

  1. Foundation: OWASP SAMM

    The OWASP Software Assurance Maturity Model serves as a measurable maturity model. The first goal is Maturity Level 1 in “Policy & Compliance”.

  2. Structure: OWASP ISVS

    The OWASP IoT Security Verification Standard provides the structure and three security levels (SL1–SL3) as a common language.

  3. Map standards → SRC

    OWASP ISVS and IEC 62443 are mapped against each other, making overlaps and gaps visible. The result is the Standard Requirements Catalog (SRC).

  4. Refine with the CRA → CRC

    The SRC is enriched with the requirements of the Cyber Resilience Act, producing the Compliance Requirements Catalog (CRC).

  5. Order by level & extend

    All requirements are assigned to security levels SL1–SL3 and extended with documentation- and cloud-specific topics.

  6. Questionnaire & policy

    A compliance questionnaire makes the maturity measurable and comparable; a dynamic policy framework keeps it adaptable to your environment.

Proven & evaluated: The framework was developed together with TGW Logistics Group on real smart-warehouse systems and subsequently evaluated and refined through expert interviews.
Next expansion – risk management: We are currently extending the framework with integrated risk management, so that maturity and risk are considered together and measures are prioritised on a risk basis.

Built on established standards

  • OWASP SAMM
  • OWASP ISVS
  • IEC 62443
  • BSI TR-03183
  • CRA · EU 2024/2847
  • C5:2020

Services

From the first question to demonstrable conformity.

A clear path in six building blocks – bookable individually or as end-to-end support.

01

Applicability check & initial analysis

We clarify applicability, your role (manufacturer, importer, distributor) and the product classification – so you know what’s actually coming your way.

02

Gap analysis & assessment

A target/actual comparison against the CRA requirements based on our own framework (OWASP SAMM & BSI), including a maturity rating from SL1 to SL3.

03

Measures & implementation support

Risk management, SBOM, vulnerability handling, secure SDLC with quality gates, CE declaration of conformity and technical documentation – prioritised and feasible.

04

Templates & document blueprints

Ready-to-use templates for processes, technical documentation and conformity evidence – so you don’t have to reinvent the wheel.

05

Training

“What is the CRA?” for decision-makers, awareness for the team and technical training for development departments – clearly prepared.

06

Tooling concept

A concept for technically supporting your processes – such as continuous vulnerability monitoring – tailored to your infrastructure.

All services in detail →

How we work

A transparent process instead of compliance chaos.

  1. Consultation

    Free & non-binding – plus applicability check.

  2. Gap analysis

    Assessment & maturity (SL1–SL3).

  3. Action plan

    Prioritised steps with effort.

  4. Implementation

    Support & ready-made templates.

  5. Conformity

    Evidence & CE marking.

Deadlines

The CRA timeline – and why 2026 is the decisive year.

  1. The Cyber Resilience Act enters into force. The clock is ticking, still without immediate manufacturer obligations.
  2. Rules on the notification of conformity assessment bodies (Chapter IV) apply.
  3. relevant now
    Reporting obligations under Article 14: actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT – early warning within 24 hours, notification within 72 hours. Applies to existing products too.
  4. Full application: essential cybersecurity requirements, conformity assessment, CE marking and technical documentation.
Penalties: Infringements of the essential requirements can lead to fines of up to €15 million or 2.5% of worldwide annual turnover – whichever is higher.

About us

Two specialists. One focus: your CRA conformity.

We’re not a large consultancy with off-the-shelf slide decks. We specialise in the Cyber Resilience Act and work as equals with small teams – in plain language and in feasible steps.

  • Our own CRA framework from a master’s thesis, built on OWASP SAMM and ISVS and aligned with the technical guidelines of the German BSI.
  • Practical, not theoretical – risk management, SBOM, secure SDLC and conformity evidence that work in everyday operations.
  • Made for SMEs – understandable, focused and without unnecessary overhead.
Maximilian Lehner
CRA & Security Consulting

Author of the CRA compliance framework (M.Sc. Management Information Systems, University of Regensburg). Focus: cybersecurity for IIoT/OT systems, from gap analysis to CE conformity.

LinkedIn profile
Tamara Szecsey
CRA & Security Consulting

Information-security consulting with a focus on CRA conformity and security processes for small and medium-sized manufacturers.

LinkedIn profile
Our promise: After every conversation you should know exactly where you stand and what the next step is – no jargon, no fear-selling.

CRA today. More tomorrow.

Cyber resilience is only the beginning.

Our focus is clearly on the Cyber Resilience Act. Beyond that, we will also support you with further security and compliance topics over time.

  • Cyber Resilience Act · focus
  • ISO/IEC 27001 · in preparation
  • IEC 62443 · in preparation

Frequently asked

Briefly explained, without the jungle of paragraphs.

What is the Cyber Resilience Act?
An EU regulation (2024/2847) that sets binding cybersecurity requirements for connected products across their entire lifecycle – from development through security updates to technical documentation. It is the first horizontal product cybersecurity law of its kind.
Am I even affected as a small company?
Most likely yes, as soon as you place a product with digital elements on the EU market that connects to a network or devices. There are exceptions (e.g. certain medical devices). That’s exactly what we clarify in the applicability check.
What applies from when?
Reporting obligations for actively exploited vulnerabilities from 11 Sep 2026 – including existing products. The full requirements including CE marking apply from 11 Dec 2027. The frequently cited “2027 date” therefore hides the actually earlier first deadline.
What happens in case of non-conformity?
Market surveillance measures up to a sales ban, plus fines of up to €15 million or 2.5% of worldwide annual turnover – comparable in scale to the GDPR.
Is buying a tool enough?
No. The CRA is mostly a process and documentation obligation. Tools provide evidence for individual requirements but don’t make a product conformant on their own. This is exactly where we come in with processes, templates and a tooling concept.
We don’t have our own security team – now what?
No problem. That’s exactly why we exist: we translate the requirements into concrete, prioritised steps and support the implementation – at your team’s pace.

Contact

Let’s talk about your product.

A free, non-binding initial consultation usually clarifies the most important question right away: are you affected – and how big is the effort?

Note: we provide consulting on cybersecurity and CRA conformity – not legal advice.

Write to us

The fastest way to reach us is by email. Briefly describe your product and your question – we’ll get back to you promptly with a suggested time.

kontakt@ls-cybersecurity.eu

Send an email