-- days to go until CRA Incident and Vulnerability Reporting Obligations come into effect Get Started Now

CRA DEADLINE: SEPTEMBER 2026

Don’t Lose Access to the EU Market
in 2026

Become an Attestra Design Partner.

From September 2026, manufacturers of connected products must comply with mandatory vulnerability handling and reporting requirements, with further obligations extending into 2027.

Attestra is an AI-powered platform designed to help you meet these requirements and go further, covering risk, documentation, and ongoing compliance as the regulation evolves.

WHAT IS THE CYBER RESILIENCE ACT?

What is the EU Cyber Resilience Act (CRA)?

For the first time, manufacturers must prove their products are cyber secure before selling them in Europe, and most don’t yet know they’re in scope

The EU Cyber Resilience Act requires all digital products (including software, loT devices, and industrial hardware) to meet defined cybersecurity standards before they can be placed on the EU market.

The first mandatory obligations come into force in September 2026, with broader requirements following through to December 2027, giving teams a limited window to implement the processes, tooling, and documentation needed to comply.

Become a Design Partner

WHAT IS ATTESTRA?

Everything you need to comply with CRA without hiring expensive consultants

Product security consultants cost €1,200-€1,800 per day. Attestra gives your team a structured. guided platform to manage the entire CRA compliance journey internally. From understanding the regulation through to producing the documentation required for compliance.

Learn More

WHAT you get

  • Vulnerability & Incident

    Meet the September 2026 obligations. Manage vulnerability disclosure, triage, and regulatory reporting in one place.

  • Risk Assessment

    Import your SBOM, assess product risks, and document security-by-design decisions.

  • Product Testing

    Create security test suites and collect evidence required for CRA compliance.

  • Documentation & Attestation

    Generate technical documentation and prepare your Declaration of Conformity.

  • Product Maintenance

    Track and monitor risks, vulnerabilities, fixes, product lifecycle updates while your product is on the market.

  • Attestra Academy

    Training courses that help your team understand and apply CRA requirements, building internal capability without relying on external experts.

Not sure if you're in scope?

Most manufacturers are unsure whether the Cyber Resilience Act applies to them. 
If you’re unsure, it’s time to take action.

Start with our free CRA scope assessment to determine whether your products fall under the CRA and what obligations may apply.

Take the free assessment

Why join the Design Partner Programme?

The September 2026 CRA vulnerability reporting deadline is closer than most teams realise.

The Design Partner Program gives you access to the first release of Attestra so you can start building compliance capability now, not under pressure later.

You’ll begin with the Vulnerability Management module, which addresses the September 2026 requirements directly. As further modules covering Risk and Documentation are released, they’re added to your licence automatically, giving you a clear, phased path to the December 2027 deadline.

You’ll also get a first look at Attestra Academy, our CRA training programme, with previews of the modules built for product, engineering, and quality teams.

Join the Design Partner Program

WHAT’S Included

  1. Beta Access to Attestra

    Be among the first to use the Vulnerability Management module live today, with every future module added to your licence as it's released.

  2. Product Influence

    Shape how Attestra evolves. Design Partners work directly with our product team and help prioritise what we build next.

  3. Expert Guidance and Support

    Direct access to CRA specialists, practical interpretation of the regulation, and invitations to workshops that help you apply requirements with confidence.

  4. Design Partner Program Pricing

    Lock in launch pricing with higher incentives at renewal, and a 20% coupon toward Attestra Academy when your team is ready to train.

About us

"We've spent years inside the detail of the CRA. Our job is to make sure none of that stays locked inside the experts' heads, it belongs with the manufacturers doing the work, and that's what we built Attestra to do."

Cyber Cert Labs is a European cybersecurity company built around one focus: helping manufacturers of connected products meet their product security obligations.

We’re actively involved in CRA standardisation work, collaborate with leading European cybersecurity organisations, and lead the CRA-Al project – an EU co-funded initiative supporting manufacturers preparing for the regulation.

That expertise is embedded directly into Attestra.

Built with EU backing through the CRA-Al project

Attestra is powered by the CRA-AI project, a European co-funded initiative under the Digital Europe Programme (DEP), supported by the European Cybersecurity Competence Centre (ECCC). Cyber Cert Labs leads the consortium, building highly automated AI-powered software to help SMEs achieve CRA compliance. Learn more about the CRA-AI-Project.

Find Out More

FAQs

Get Started Today

Prepare for the Cyber Resilience Act before 
the deadline arrives.

Join the Attestra Early Adopter Programme and start preparing your organisation for CRA compliance.