Industry
SECURITYFRAMEWORKEU CRA

Pentesting for EU CRA

The EU Cyber Resilience Act sets cybersecurity duties for hardware and software products with digital elements placed on the EU market. Manufacturers must build them securely by design and manage vulnerabilities through the support period. Products must ship free of known exploitable vulnerabilities, tested effectively before release. Breaches can bring fines of up to €15 million or 2.5% of worldwide turnover.

The controls we cover

Requirement summary

Products with digital elements must be designed, developed, and produced for a level of security appropriate to the risks, placed on the market free of known exploitable vulnerabilities, with secure-by-default configuration and limited attack surfaces.

AISafe tests the product’s web, API, and code surfaces before release and confirms that no known exploitable vulnerabilities ship in the built artifact.

Requirement summary

Manufacturers must identify and document vulnerabilities and components, remediate them without delay through security updates, regularly test and review security, and run a coordinated vulnerability disclosure policy.

AISafe preserves a traceable record of each finding from discovery to validated fix, supporting the remediation and retest duties during the whole support period.

Quick facts

ApplicabilityManufacturers of products with digital elements placed on the EU market, plus importers and distributors.
RequirementYes once the regulation applies; manufacturers carry the core duties, with exclusions by product type.
CostScales with the product’s risk class and complexity, not headcount; automated testing cuts the per-product cost of lifecycle evidence.
CadenceContinuously across the support period: testing before release and for each update, plus ongoing vulnerability handling.

AISafe Labs delivers on-demand, audit-ready evidence for the EU CRA: web, API, and source-code testing with validated findings and confirmed fixes, in hours, where other vendors take weeks. Technical testing is one input to the manufacturer’s wider conformity assessment.

Related frameworks

Get your Audit Evidence right now

Run a security assessment of your system, or contact us if your compliance programme requires additional support.