CRA Consulting
Prepare Your Products for the Cyber Resilience Act (CRA)
Pictor helps manufacturers of connected and embedded products understand CRA requirements, identify compliance gaps and establish the engineering process and technical documentation needed for compliance.
CRA is changing the requirements for connected products
The Cyber Resilience Act (CRA) is the EU’s horizontal cybersecurity law for products with digital elements. It cover hardware and software placed on the EU market and introduces obligations throughout the product lifecycle.
- 11 sep 2026 — Reporting obligations begin
- 11 dec 2027 — CRA fully applies
Is your organisation affected?
CRA applies broadly to products with digital elements placed on the EU market. We work with manufacturers across a wide range of industries.
- Embedded Devices
- Industrial Products
- Connected Systems
- Software-enabled Equipment
Our CRA consulting services
CRA Scope & Classification
Understand whether your product falls within CRA scope and what requirements apply.
Readiness Gap Assessment
Assess your current development, documentation and support process against CRA requirements.
Secure Product Lifecycle
Translate CRA requirements into practical engineering activities across design, development, production and post-market support.
Vulnerability Mangement
Establish processes for vulnerability reporting, triage, remediation and coordinated vulnerability handling.
Technical Documentation
Prepare the technical evidence and documentation required for conformity assessment.
Interim Compliance Leadership
Provide experienced senior leadership to drive CRA preparation within your organisation.
MANAGEMENT TEAM
Staffan Skogby
CEO & Senior System Architect
Kjell-Åke Grandin
Senior Advisor
PARTNERS