The paid diagnostic

The CRA Reporting
Readiness Audit


Ten business days. Fixed fee. It ends in a document your board and your notified body can both read.

Start the applicationNinety seconds. Reviewed personally, and you get a straight answer on fit.

Three lines of inquiry

What the audit examines

01 — Portfolio

What is actually in scope?


  • Full inventory of products with digital elements on the EU market
  • Annex III and Annex IV classification, and the conformity route each implies
  • SBOM state per product: current, machine-readable, or absent
  • Third-party and open-source components, and their support status
  • Legacy products still supported under Article 69(3)

02 — Detection

Could you know in time?


  • Vulnerability intake channel, and whether it is monitored in practice
  • Component-to-product traceability: “which of ours contains this?”
  • Criteria and evidence for judging active exploitation
  • Out-of-hours coverage and escalation authority
  • Measured time from public disclosure to internal determination

03 — Reporting

Could you file, in every market?


  • CSIRT coordinator mapping per market, confirmed not assumed
  • Single Reporting Platform readiness and named filers
  • The 24 / 72 / 14-day sequence walked against a real disclosure
  • User notification process and its trigger
  • Retained evidence: what you would show a surveillance authority

Core outputs

What the audit produces


  • CRA Reporting Readiness Score with per-product breakdown
  • The five structural gaps that would cause a missed window, ranked
  • Product classification matrix against Annex III and Annex IV
  • CSIRT coordinator map for every market you sell into

Executive decision package

What you do with it


  • A 30 / 60 / 90-day correction plan with named owners
  • Board-ready findings memo, written for non-technical readers
  • A 60–90 minute executive readout with the team
  • A direct recommendation on the path forward — including, where warranted, that no engagement is needed
The final line of the memo is a recommendation, not a proposal. Sometimes it says you don't need us.

Price

€9,500 – €16,000, fixed

One legal entity, one product portfolio. Quoted before you commit, invoiced on completion of the readout. The range reflects portfolio size and the number of markets in scope — nothing else.

Start the application

What is not included

Published, so you can rule us out


  • Not a penetration test
  • Not a notified-body conformity assessment
  • Not a substitute for legal advice on your CE marking route
  • Not remediation — the audit tells you what is wrong and in what order to fix it. Fixing it is a separate engagement you are under no obligation to buy.

If there isn't time

CRA Reporting Sprint — €4,500 fixed, five business days


For manufacturers who will not have a full audit finished before 11 September. Scope narrows to detection and reporting only. It answers one question — are you exposed on the eleventh — and produces the minimum viable reporting process, the CSIRT map, and named filers with escalation authority. The full audit becomes the natural follow-on in Q4.

Apply for the sprint