The EU Cyber Resilience Act (CRA) comes into force in December 2027, requiring all manufacturers of connected products to meet mandatory cybersecurity requirements before selling in Europe. Attestra is an AI-powered platform designed to guide product companies—particularly SMEs without dedicated cyber teams—through the full CRA compliance journey. From understanding what applies to you, through risk assessment and security testing, to producing the documentation needed for conformity. Alongside the platform, Attestra Academy provides training courses to help your team build the knowledge and skills needed to meet CRA obligations confidently.
Vulnerability & Incident Reporting Meet your September 2026 obligations—manage vulnerability disclosure, triage, and reporting from day one.
Risk Assessment Import your SBOM, build a digital twin of your product, conduct threat-led risk assessments, and document security-by-design decisions.
Product Testing Create test suites, link them to security objectives, collect evidence, and produce test reports.
Documentation & Attestation Generate the technical documentation required for conformity and prepare your Declaration of Conformity.
Product Maintenance Manage the ongoing lifecycle—track fixes, update documentation, and loop back through assessments as products evolve.
Attestra Academy Training courses to help your team understand and apply CRA requirements with confidence.
Become a Design Partner
24 months, starting January 1, 2025
€2,873,164.00 /€2,043,272.00
Watch our videos
WHAT WE DO
Find out if you're in scope. Find out how ready you are. Both available for free, online.
The AI-powered software that runs your CRA compliance, from vulnerability reporting to CE marking.
Online CRA training that gives your team the expertise to own and improve product security internally.
We lead the CRA-AI project and contribute to CRA standardisation. That expertise sits inside everything we build.
Get a free online readiness assessment. Find out how prepared you are for the Cyber Resilience Act !
Follow the CRA-AI project on LinkedIn to keep up to date with our progress and find out about our webinars, events, case studies, trainings and early adopter program.
Follow UsCo-Funded by the European Union. The views and opinions expressed are those of the author(s) and do not necessarily reflect the views of the European Union or the European Cybersecurity Competence Centre. Neither the European Union nor the European Cybersecurity Competence Centre can be held responsible for them.