Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

Penumbral Labs

Luxembourg firm offering CRA readiness assessments, CRA-scoped product pen tests and vulnerability-reporting retainers

CompanyCyber Resilience Act Compliance

Pricing: Fixed scope and fixed price, quoted per product. The self-check is free.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed October 2026 · How we review listings

What is Penumbral Labs?

Penumbral Labs is a Luxembourg firm that prepares manufacturers of connected products and software for the EU Cyber Resilience Act through offensive security testing. It sells three services that can be bought separately. A readiness assessment sets the product against each Annex I essential requirement, reviews the cybersecurity risk assessment and technical documentation, notes what the Annex VII documentation does not yet contain, runs automated vulnerability discovery and ends with a prioritised list of actions before December 2027. A product penetration test attacks the product, its firmware, its APIs and the back-end systems around it, records each finding against the Annex I requirement it concerns and is written to sit in the technical documentation, with a retest. A monthly retainer runs the manufacturer's vulnerability inbox, watches the software bill of materials for new vulnerabilities and prepares the early warnings, notifications and final reports that the Act's reporting duties have required since 11 September 2026. Each engagement has a fixed scope and is quoted per product, and a free self-check covers the scoping questions. The firm states that the work is done by a single offensive-security practitioner holding the CPTS, CRTO and CRTE certifications, supported by its own AI-assisted vulnerability scanner with every finding verified by hand. It does not give legal advice, write the technical documentation, sign the declaration of conformity or act as a notified body. Penumbral Labs S.à r.l.-S is registered in Luxembourg (RCS B312553, 28 September 2026) and based in Differdange.

Best for: EU manufacturers of connected products and standalone software that want CRA gaps found by testing the product rather than by questionnaire

Key Features

Readiness assessment against each Annex I essential requirement
Review of the cybersecurity risk assessment and Annex VII technical documentation
Product penetration test covering firmware, APIs and back-end systems, with a retest
Findings recorded against the Annex I requirement they concern
Monthly retainer for vulnerability handling and the Act's reporting duties
Free self-check on scope, role and product class

Do you work at Penumbral Labs? to confirm the details or send us a correction.

Add the Cyber Vendor Guide badge to your site

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent Penumbral Labs? Request a correction.

Key facts

Pricing
Fixed scope and fixed price, quoted per product. The self-check is free.
Model
Fixed-price engagements quoted per product; monthly retainer
Founded
2026

Where Penumbral Labs appears

Guides

Certifications

CPTS, CRTO and CRTE practitioner certifications (per the firm)