Cyber Resilience Act Compliance: 9 Companies compared
9 Cyber Resilience Act Compliance Companies, side by side
Featured listings are paid placements.
| Company | Founded | Engagement | Specialism | Standards / accreditations |
|---|---|---|---|---|
| pi3gFeatured | 2012 | Consulting + engineering engagements | SME manufacturers of embedded-Linux and IoT products that need hands-on engineering help… | EU Cyber Resilience Act, CE marking |
| Article 14 Ready | 2020 | Freemium | Product security and compliance teams at manufacturers preparing CRA Article 14 reports f… | — |
| CVD Portal | 2026 | Freemium subscription with a permanent free tier and three paid tiers | EU manufacturers, importers and distributors that need an Article 13 disclosure contact a… | — |
| ONEKEY | 2020 | Platform subscription + advisory | Device manufacturers wanting automated SBOM, vulnerability management, and CRA evidence g… | EU Cyber Resilience Act, IEC 62443, ETSI EN 303 645 |
| Bureau Veritas | 1828 | Consulting + testing + certification | Manufacturers wanting one TIC partner spanning hands-on pen testing, RED/IEC 62443 testin… | EU Cyber Resilience Act, RED, EN 18031 |
| ConformOps | — | One-off assessment plus subscription, with free preview tier | Small software teams that want a first, evidence-led CRA readiness pass on a repository a… | — |
| DEKRA | 1925 | Training + evaluation + certification | Manufacturers planning ahead for CRA conformity assessment who want an EUCC-accredited ev… | EU Cyber Resilience Act, EUCC, Common Criteria |
| SGS | 1878 | Testing + certification + advisory | Manufacturers of higher-assurance digital products (chips, secure elements, payment, embe… | EU Cyber Resilience Act, RED, EN 18031 |
| TUV SUD | 1866 | Assessment + certification + training | Manufacturers needing accredited third-party assessment, RED/EN 18031 testing, and CE-mar… | EU Cyber Resilience Act, RED, EN 18031 |
By use case
Our read on which firm suits which job. Editorial, not paid, and separate from the alphabetical listing below.
SME embedded / IoT
pi3g
Hands-on engineering plus compliance for small and mid-size embedded-Linux and IoT manufacturers, from people who actually build the hardware.
Automated SBOM + vuln management
ONEKEY
Platform-driven firmware analysis, SBOM generation, and continuous vulnerability management with a CRA Compliance Wizard.
Cloud, Self-hosted
Conformity assessment
DEKRA
EUCC-accredited evaluator becoming a CRA notified body in June 2026, for manufacturers planning the higher-assurance route.
pi3g
German embedded-Linux and IoT specialist helping SME manufacturers make connected products compliant with the EU Cyber Resilience Act.
pi3g GmbH & Co. KG is a Leipzig-based firm with 16+ years building IoT devices, with a focus on embedded Linux. For pi3g the Cyber Resilience Act is an essential upcoming part of CE certification, and they help small and medium manufacturers of connected devices, firmware, and software components understand and meet its requirements. The service spans a fixed-price readiness assessment, hands-on engineering implementation support, and a full compliance package backed by legal-partner review and a single point of contact.
Capabilities
- Fixed-price CRA readiness assessment (training, interviews, documentation review, recommendations report)
- Compliance-supporting engineering and implementation support
- Embedded Linux stack support: Yocto, Docker, Raspberry Pi OS, Debian derivatives
- Code-level work in C/C++, Python, TypeScript, Node.js
- Full CRA compliance service with expert legal review via partners
- Single point of contact for all CRA matters
- AI-generated code compliance review and refactoring support
- Free initial scoping consultation and knowledge-transfer training
Certifications
EU Cyber Resilience Act, CE marking
Article 14 Ready
Cyber Resilience Act ComplianceProduct security and compliance teams at manufacturers preparing CRA Article 14 reports for exploited vulnerabilities or severe incidents.
Article 14 Ready is a preparation aid for manufacturers placing software or connected products on the EU market that must report under Article 14 of the Cyber Resilience Act. Its free field compiler runs in the browser, covers actively exploited vulnerabilities and severe incidents, and adapts the required fields to the 24h early warning, 72h notification and final report stages, with a reporting clock calculator. Incident entries stay in the browser and can be exported as Markdown, JSON or print/PDF. An optional 24h Dry Run, a self guided tabletop exercise delivered as a downloadable HTML file, costs EUR 79 excluding VAT as a one time purchase for business customers. The site states it is an independent aid and not an official filing channel, legal advice or a conformity assessment. It is operated by PEAK Consulting Services GmbH of Mannheim, Germany.
Bureau Veritas
Cyber Resilience Act ComplianceManufacturers wanting one TIC partner spanning hands-on pen testing, RED/IEC 62443 testing, and CRA conformity advisory
Bureau Veritas is an 1828-founded testing, inspection, and certification group. Its Bureau Veritas Cybersecurity division (built around the acquired specialist Secura) maps CRA requirements to existing standards and delivers end-to-end compliance, from gap assessment to penetration testing and conformity advisory. Its consumer-products and certification arms run accredited RED cybersecurity testing and CE-marking support across labs in Germany, France, China, and Taiwan.
ConformOps
Cyber Resilience Act ComplianceSmall software teams that want a first, evidence-led CRA readiness pass on a repository at a fixed published price.
ConformOps is a cloud-hosted service that reads a software repository's manifests, lockfiles, CI configuration, SBOMs and security documentation, maps what it finds to the EU Cyber Resilience Act and returns an evidence package. Analysis is static; the site states that no code is executed and that detected secrets are redacted before storage. Input is via a read-only GitHub App, a ZIP upload or individual files, and outputs include a CycloneDX inventory, Annex-oriented working documents, traceability and register CSVs and an evidence workbook, with each finding classified as evidenced, partial, gap or not applicable. The site states that ConformOps does not certify products, issue declarations, replace a notified body or make legal conclusions. Pricing is published: a free preview for up to two products, a one-time Full Assessment at EUR 99 per product, Continuous monitoring at EUR 79 per month per product, and a Portfolio plan at EUR 249 per month for five products. The legal page states the service is operated by Simone Laudani in Italy; no company registration or VAT number is published.
CVD Portal
Cyber Resilience Act ComplianceEU manufacturers, importers and distributors that need an Article 13 disclosure contact and Article 14 reporting workflow in place before the 11 September 2026 deadline.
CVD Portal is a compliance platform for manufacturers placing products with digital elements on the EU market under the Cyber Resilience Act, Regulation (EU) 2024/2847. It covers product classification under Annexes III and IV, Annex I essential requirements, Annex VII technical documentation, the EU declaration of conformity, vulnerability handling and Article 14 authority reporting. The free tier provides a branded HTTPS intake portal for the Article 13 single point of contact, with submission tracking, 48-hour acknowledgement tracking, automatic disclosure policy publication and PGP-encrypted researcher communication. Paid tiers add the Article 14 notification workflow on the 24-hour, 72-hour and 14-day deadlines, CSAF 2.0 advisory export, SBOM and hardware component registries, and CRA self-assessment tooling including STRIDE threat modelling. It is operated by Porta Regulus B.V. in the Netherlands, runs on Hetzner infrastructure in Germany with no transfers outside the EU or EEA, and is listed in the CIRCL-operated GCVE registry as numbering authority 126.
DEKRA
Cyber Resilience Act ComplianceManufacturers planning ahead for CRA conformity assessment who want an EUCC-accredited evaluator and future notified body
DEKRA is the world's largest non-listed testing, inspection, and certification body, with a product-cybersecurity practice covering the full product lifecycle. It provides CRA readiness strategy, training, and turnkey projects, plus evaluation services mapped to harmonized and draft standards. DEKRA is an accredited ITSEF and Certification Body for the EUCC scheme and is set to become a CRA Notified Conformity Assessment Body, with notification beginning June 2026.
ONEKEY
Cyber Resilience Act ComplianceDevice manufacturers wanting automated SBOM, vulnerability management, and CRA evidence generation across the product lifecycle
ONEKEY operates the ONEKEY Product Cybersecurity & Compliance Platform, which performs automated firmware analysis, SBOM generation, vulnerability detection, and zero-day discovery. Its Compliance Wizard maps product evidence against the CRA and other frameworks, and its CRA Fast Start program structures readiness assessment, SBOM creation, vulnerability management, and continuous monitoring. ONEKEY (formerly IoT Inspector) is part of PwC Germany's investment portfolio.
pi3g
Cyber Resilience Act ComplianceSME manufacturers of embedded-Linux and IoT products that need hands-on engineering help to reach CRA compliance, not just an audit
pi3g GmbH & Co. KG is a Leipzig-based firm with 16+ years building IoT devices, with a focus on embedded Linux. For pi3g the Cyber Resilience Act is an essential upcoming part of CE certification, and they help small and medium manufacturers of connected devices, firmware, and software components understand and meet its requirements. The service spans a fixed-price readiness assessment, hands-on engineering implementation support, and a full compliance package backed by legal-partner review and a single point of contact.
SGS
Cyber Resilience Act ComplianceManufacturers of higher-assurance digital products (chips, secure elements, payment, embedded) needing lab evaluation and EU type certification
SGS is the world's largest testing, inspection, and certification company. Its cybersecurity arm, SGS Brightsight, runs accredited security-evaluation laboratories (including a facility in Graz, Austria) that assess digital products against CRA requirements and RED cybersecurity standards. SGS develops tailored CRA service packages and operates a Notified Body that can issue EU type certificates for RED Article 3(3) using EN 18031.
TUV SUD
Cyber Resilience Act ComplianceManufacturers needing accredited third-party assessment, RED/EN 18031 testing, and CE-marking support from an established certification body
TUV SUD is a global testing, inspection, and certification organization with a dedicated CRA practice in its product-testing and cybersecurity divisions. It helps manufacturers interpret CRA obligations, run gap assessments, set up vulnerability management and incident reporting, and obtain third-party assessment for higher-risk products. It also runs RED cybersecurity testing against the EN 18031 series.
Related guides
Other categories you might be evaluating alongside cyber resilience act compliance.
About this listing
Cyber Resilience Act Compliance companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →