Pentesting for EU CRA
The EU Cyber Resilience Act sets cybersecurity duties for hardware and software products with digital elements placed on the EU market. Manufacturers must build them securely by design and manage vulnerabilities through the support period. Products must ship free of known exploitable vulnerabilities, tested effectively before release. Breaches can bring fines of up to €15 million or 2.5% of worldwide turnover.
The controls we cover
Requirement summaryProducts with digital elements must be designed, developed, and produced for a level of security appropriate to the risks, placed on the market free of known exploitable vulnerabilities, with secure-by-default configuration and limited attack surfaces.
AISafe tests the product’s web, API, and code surfaces before release and confirms that no known exploitable vulnerabilities ship in the built artifact.
Requirement summaryManufacturers must identify and document vulnerabilities and components, remediate them without delay through security updates, regularly test and review security, and run a coordinated vulnerability disclosure policy.
AISafe preserves a traceable record of each finding from discovery to validated fix, supporting the remediation and retest duties during the whole support period.
Quick facts
| Applicability | Manufacturers of products with digital elements placed on the EU market, plus importers and distributors. |
| Requirement | Yes once the regulation applies; manufacturers carry the core duties, with exclusions by product type. |
| Cost | Scales with the product’s risk class and complexity, not headcount; automated testing cuts the per-product cost of lifecycle evidence. |
| Cadence | Continuously across the support period: testing before release and for each update, plus ongoing vulnerability handling. |
AISafe Labs delivers on-demand, audit-ready evidence for the EU CRA: web, API, and source-code testing with validated findings and confirmed fixes, in hours, where other vendors take weeks. Technical testing is one input to the manufacturer’s wider conformity assessment.
