Advisory engagements  ·  manufacturers

CRA and NIS2 consulting

Before anyone monitors anything for you, someone has to establish what actually applies to your company, and in what order. That is a smaller, separate piece of work — and for some companies it is the only piece they need.

Two regulations, two different problems

The Cyber Resilience Act attaches to the product you place on the EU market. NIS2 attaches to your organisation as an operator. Most manufacturers we speak to are caught by both, treat them as one project, and lose a quarter to the confusion. They have different triggers, different clocks and different recipients.

 Cyber Resilience ActNIS2
Attaches to the product you place on the EU market your organisation as an entity
What triggers a report an actively exploited vulnerability in your product, or a severe incident affecting its security a significant incident affecting the services you operate
The clock 24h early warning, 72h notification, final report once a corrective measure exists 24h early warning, 72h notification, final report within one month of the notification
Reported to your CSIRT and ENISA your national CSIRT or competent authority — in Romania, DNSC
First hard date 11 September 2026 for reporting, 11 December 2027 for the remaining obligations already in force; Romania has transposed it, and in-scope entities carry a registration duty

Both clocks start when you become aware, not when you finish investigating. That single detail is what turns either regulation into an operational problem.

Where companies get stuck

What the engagements look like

EngagementWhat it covers
Scope determination Which products and which parts of your organisation fall under the CRA and under NIS2, with the reasoning written down so you can defend it to a customer or an authority. Usually one to two weeks.
Readiness roadmap What has to exist by 11 September 2026 and by 11 December 2027, sequenced by what blocks what, with an honest estimate of the internal effort rather than only ours.
Vulnerability handling process The Annex I Part II process designed end to end: intake, triage, SBOM and CVE correlation, coordinated disclosure, and a reporting decision tree with named roles and a tested 24-hour path.
NIS2 obligations mapping Entity classification, registration, the Article 21 risk-management measures, incident reporting, and the supply-chain clauses that need to reach your actual contracts.
Questionnaire and audit support Answering OEM security annexes, TISAX-adjacent assessments and market surveillance requests accurately, without over-committing to things you do not yet do.
Workshops Half a day for engineering, a shorter session for management. Same material, different altitude, so both groups leave with the same understanding of the deadline.

Advisory first, and then your call

Consulting ends when you have the decisions and the documents. If you would rather not carry the monitoring and the filing yourselves afterwards, we operate it — that is the three services on the home page. If you would rather run it in-house, then the advisory work did its job. We do not make one conditional on the other, and we will say so in writing if you ask.

Start with an exploratory discussion. Forty-five minutes, free, no deck and no obligation. The aim is narrow: establish whether you are in scope, what your first real deadline is, and whether you need consulting at all. Sometimes the honest answer is that you have more time than you think, or that an hour with your own engineering lead resolves it.

To make the call useful, write a few lines first: what you make, which markets you place it on, whether you sell under your own brand or someone else's, roughly how many product families, and whether a customer has already sent you a security questionnaire. Nothing confidential — a paragraph is plenty.

Write to [email protected].

Not sure whether any of this applies to you?

That is the most common reason people write, and it is a good reason to. Send a paragraph about what you build and we will tell you what applies, what does not, and what the first date on your calendar actually is.