CRA Snapshot for manufacturers
We establish the product class, the gaps against Annex I and readiness for art. 14 of the Cyber Resilience Act.
PRODUCT AND OT CYBERSECURITY
We establish what your organisation can demonstrate today across the CRA, IEC 62443, KSC/NIS2, PSIRT/SBOM and cyber insurance. You receive a clear account of the gaps, the material you can show and the decisions to take next.
See a sample report01 Method
We follow the same sequence whatever the topic: facts first, then evidence, and decisions last.
What triggered the work?
Where does fact end and assertion begin?
What can be shown safely?
What needs doing now, and what can wait?
02 Situations
Choose the situation closest to yours. We will point to the right service and the topic to raise. Every answer is visible straight away.
We establish the product class, the gaps against Annex I and readiness for art. 14 of the Cyber Resilience Act.
An assessment of your OT security in the IEC 62443 language your customer or group function expects.
We turn the declarations in the cyber questionnaire into concrete evidence of controls before you speak to a broker.
A working vulnerability-handling process and an SBOM you can show to customers and auditors.
We check whether and how you fall under KSC/NIS2 and which evidence is worth preparing.
A short call to establish where to start and which piece of evidence is most urgent.
03 Services
Each one delivers concrete evidence and a 60–90 day action plan.
A fixed-price assessment of 1–2 product families against the Cyber Resilience Act: classification, gaps against Annex I, readiness for art. 14, an SBOM-lite and an action plan.
A short OT security assessment: remote access, segmentation, updates, vulnerabilities, logging and the evidence required by industrial customers, brokers and auditors.
From declarations in the cyber questionnaire to concrete evidence of controls: MFA, backups, EDR/logs, remote access, an incident procedure and a plan of first fixes before the conversation with your broker.
Check whether your company may fall under KSC/NIS2 and what evidence is worth preparing for the board, a customer, an auditor or an insurer. Facts and deadlines, not scare tactics.
04 Sample report
DEMO – sample structure, not a client result
Scenario: an unnamed manufacturer; a connected device with firmware, a mobile application and a cloud service.
A public reporting route is documented; ownership and response evidence is incomplete.
An SBOM exists for the current build; the release-to-SBOM trace is inconsistent.
Product events are defined; retention and customer-export evidence is missing.
0–30 days: establish owners and reproducible evidence. 31–60 days: close the highest-risk gaps. 61–90 days: rehearse and package the evidence.
DEMO – sample structure, not a client result.
05 Process
Short, concrete and with evidence you can show to a customer, an auditor or an insurer.
We set the scope, classify the product or entity and map the current state against the requirements of the CRA, IEC 62443, KSC/NIS2 or a cyber questionnaire.
We show what is missing and what is risky, separate the technical part from the legal interpretation and organise the evidence.
You get an evidence pack and a concrete action plan with priorities, ready for a conversation with a customer, a broker or an auditor.
06 R&D
In industrial cybersecurity, documentation alone is not enough. We build prototypes to better understand OT/IT separation, event monitoring, compliance evidence and vulnerability handling.
A prototype for passing selected logs and telemetry from OT to IT/SIEM while limiting the return path.
A local monitoring node for smaller industrial environments that builds an evidence trail without the public cloud.
An internal tool for organising product evidence, an SBOM-lite and mapping to the CRA, IEC 62443 and KSC/NIS2.
Experiments with local AI and RAG to analyse documentation without sending data to public models.
These are research and development prototypes, proof of practice rather than products for sale.
07 Person and company
Helena Czarnecka · CISSP · GCFE · ISO 27001 Lead Auditor · ISA Senior Member.
We have been operating since 2014. We specialise in industrial and product cybersecurity: OT/ICS, product security, CRA, PSIRT/SBOM and preparing evidence for KSC/NIS2 and cyber insurance questionnaires. We serve manufacturers, industrial companies and the regulated sector, including civil aviation and defence.
We separate the technical part from the legal part so that it is clear what is a technical assessment and what is a legal interpretation. On matters that require a legal opinion, we work with advisers and law firms. On cyber policies we do not broker insurance sales; we help prepare the technical answers and evidence.
Trusted by, among others
08 FAQ
The CRA (EU Regulation 2024/2847) applies to manufacturers, importers and distributors of products with digital elements, meaning hardware and software that connects to a device or network. Full application and CE marking apply from 11 December 2027, and vulnerability reporting obligations (art. 14) from 11 September 2026.
IEC 62443 is usually not a legally mandatory standard for every company with OT. It is, however, a recognised language of security evidence for industrial systems and products that industrial customers, auditors and insurers increasingly expect.
KSC is the act on the national cybersecurity system, which implements the EU NIS 2 directive. The obligations of Polish entities stem from the act, not directly from the directive.
The most commonly needed items are evidence of controls: multi-factor authentication (MFA), backups with a restore test, EDR and logs, management of remote access and privileged accounts, and an incident response procedure. We help prepare the technical answers and evidence; we do not broker insurance sales.
09 Contact
Briefly describe your situation. We will get back to you and determine whether and how we can help.
Prefer to pick a time straight away?
Book a meeting →