CRA and NIS2 consulting
Before anyone monitors anything for you, someone has to establish what actually applies to your company, and in what order. That is a smaller, separate piece of work — and for some companies it is the only piece they need.
Two regulations, two different problems
The Cyber Resilience Act attaches to the product you place on the EU market. NIS2 attaches to your organisation as an operator. Most manufacturers we speak to are caught by both, treat them as one project, and lose a quarter to the confusion. They have different triggers, different clocks and different recipients.
| Cyber Resilience Act | NIS2 | |
|---|---|---|
| Attaches to | the product you place on the EU market | your organisation as an entity |
| What triggers a report | an actively exploited vulnerability in your product, or a severe incident affecting its security | a significant incident affecting the services you operate |
| The clock | 24h early warning, 72h notification, final report once a corrective measure exists | 24h early warning, 72h notification, final report within one month of the notification |
| Reported to | your CSIRT and ENISA | your national CSIRT or competent authority — in Romania, DNSC |
| First hard date | 11 September 2026 for reporting, 11 December 2027 for the remaining obligations | already in force; Romania has transposed it, and in-scope entities carry a registration duty |
Both clocks start when you become aware, not when you finish investigating. That single detail is what turns either regulation into an operational problem.
Where companies get stuck
- Scope, in both directions. Whether a given product is in scope. Whether an obligation you have been handed is actually yours or your supplier's. Whether you are the manufacturer, the importer or the distributor for a particular SKU — because that determines who files.
- Treating the CRA as a documentation exercise. Annex I Part II is a process obligation. A technical file describing a vulnerability handling process that nobody operates fails at the first real report, and it fails in writing.
- A 24-hour clock that starts earlier than expected. Awareness, not conclusion. Most internal escalation processes are built around having an answer first.
- Running NIS2 as an IT project. The obligation sits with management bodies, and the supply-chain requirements land on procurement and contracts long before they reach a SOC.
- Customer questionnaires arriving before the strategy. An OEM's security annex is often the first deadline that genuinely bites. Answering it badly sets a precedent you will live with for years.
What the engagements look like
| Engagement | What it covers |
|---|---|
| Scope determination | Which products and which parts of your organisation fall under the CRA and under NIS2, with the reasoning written down so you can defend it to a customer or an authority. Usually one to two weeks. |
| Readiness roadmap | What has to exist by 11 September 2026 and by 11 December 2027, sequenced by what blocks what, with an honest estimate of the internal effort rather than only ours. |
| Vulnerability handling process | The Annex I Part II process designed end to end: intake, triage, SBOM and CVE correlation, coordinated disclosure, and a reporting decision tree with named roles and a tested 24-hour path. |
| NIS2 obligations mapping | Entity classification, registration, the Article 21 risk-management measures, incident reporting, and the supply-chain clauses that need to reach your actual contracts. |
| Questionnaire and audit support | Answering OEM security annexes, TISAX-adjacent assessments and market surveillance requests accurately, without over-committing to things you do not yet do. |
| Workshops | Half a day for engineering, a shorter session for management. Same material, different altitude, so both groups leave with the same understanding of the deadline. |
Advisory first, and then your call
Consulting ends when you have the decisions and the documents. If you would rather not carry the monitoring and the filing yourselves afterwards, we operate it — that is the three services on the home page. If you would rather run it in-house, then the advisory work did its job. We do not make one conditional on the other, and we will say so in writing if you ask.
To make the call useful, write a few lines first: what you make, which markets you place it on, whether you sell under your own brand or someone else's, roughly how many product families, and whether a customer has already sent you a security questionnaire. Nothing confidential — a paragraph is plenty.
Write to [email protected].
Not sure whether any of this applies to you?
That is the most common reason people write, and it is a good reason to. Send a paragraph about what you build and we will tell you what applies, what does not, and what the first date on your calendar actually is.