R&D COPILOT
ROLet’s talk

AI + engineering services

Product security work for the Cyber Resilience Act

For software and connected devices within its scope, the Cyber Resilience Act sets requirements for how products are built and supported. Reporting obligations apply from 11 September 2026, and the main obligations from 11 December 2027. We prepare the engineering side together with your product team. That covers a software bill of materials for each release, a review of default settings and how updates are delivered, a process for monitoring dependencies, and a way for outside researchers to report vulnerabilities to a named owner. We also draft the technical documentation and set how long each version will receive security updates. Product classification and conformity assessment stay with the appropriate specialists. We prepare the material they will examine.

Start with your workflow. We agree the first deliverable, data boundaries, scope and budget before work begins.

What we can deliver

What your team receives.

  • Product scope and component inventory, with an SBOM for each release
  • Review of secure defaults, authentication and update delivery
  • Dependency monitoring and a vulnerability triage process
  • Public vulnerability disclosure route with an internal owner
  • Technical documentation and a support-period plan

Illustrative project example

CRA product readiness

A company sells a building-sensor gateway with a companion web app. The firmware includes an open-source network library that is two years out of date, and the default admin password is printed on the label. We generate the SBOM and plan the library upgrade. The shared password is replaced with per-device credentials set on first use. We also add a security.txt file and a disclosure inbox that sends reports to the firmware lead.

The final design follows your systems, documents and operating requirements.

Keep your team in control.

Data protection

Map approved data sources, access rules, retention and provider use before connecting AI to company information.

EU infrastructure options

Scope EU servers or self-hosting and disclose the processing location of model APIs, logs and backups.

Human approval

Agree where AI may suggest, where it may act and where a person must approve the next step.

Can we start small?

Yes. Start with one workflow, one team and an agreed outcome. We scope the pilot after learning about your data, systems and constraints.

Can our data stay in the EU?

We can scope EU-hosted or self-hosted options. The proposal identifies where each component processes and stores data, which providers are involved, and any transfer or remote-access implications. EU hosting alone does not establish compliance.

Do you help with the AI Act, NIS2 and CRA?

We help prepare inventories, data flows, security controls, documentation and remediation work for specialist review. Applicability depends on your role, sector, jurisdiction and product. We do not offer a blanket compliance certificate.