Pentesting for EU CRA
The EU Cyber Resilience Act applies to all manufacturers of hardware and software products with digital elements sold on the EU market. Products with their own EU rules, such as medical devices, motor vehicles, or civil aviation, and non-commercial open source are out of scope. Covered products must ship without known exploitable vulnerabilities, stay tested and maintained through a support period of at least five years, and report exploited flaws quickly. Breaches can bring fines of up to 15 million EUR or 2.5 percent of worldwide turnover.
The controls we cover
Requirement summaryManufacturers must place products on the market without any known exploitable vulnerabilities. This is the release-gate obligation and forces a pre-release vulnerability assessment with evidence that the shipped version was clean.
AISafe provides a validated, timestamped record proving the deployed version was free of known exploitable flaws when scanned. The ML Classifier reduces scanner false positives by 50 percent, and Sniper Auto-Exploiter marks findings as Confirmed only with request, response, proof, or equivalent forensic artifact. Authenticated and API scanning extends that confirmation behind login and across API surfaces where the most exploitable behavior lives.
Requirement summaryProducts require effective and regular tests and reviews of product security. Auditors and notified bodies expect to see the testing cadence and sample test results, not just a written policy.
Scheduled scanning sets assessments on a cadence that matches the release cycle and the CRA reporting period, with a timestamp that the scan ran and the finding was recorded. Vulnerability monitoring and diff-based alerting fires when something new appears between scheduled scans, so the record shows handling across the whole support period, not just on scan days.
Requirement summaryManufacturers must handle vulnerabilities effectively for the entire support period, a minimum of five years for most products. Vulnerability handling is a lifecycle obligation, not a release-time check.
The VPN Agent operates inside embedded, on-prem, or private-network deployments, so no permanent on-premises appliance is needed per product line. The offensive research team builds dedicated scanners for high-impact and actively exploited CVEs, and monitoring alerts the moment that check flags something across in-scope products, answering whether the product is actually affected without slow manual CVE-to-component mapping.
Requirement summaryManufacturers must report any actively exploited vulnerability and any severe incident affecting product security through ENISA Single Reporting Platform: an early warning within 24 hours of discovery, a notification within 72 hours, and a final report within 14 days of the corrective measure.
Because Sniper-validated findings carry proof and the ML Classifier cuts noise by 50 percent, security teams do not waste the Article 14 window triaging unconfirmed detections. Dedicated scanners for newly exploited CVEs, retesting workflows with before-and-after proof, and exports in PDF, DOCX, or JSON drop directly into the technical documentation required by Article 31 and Annex VII.
Quick facts
| Applicability | All manufacturers of hardware and software products with digital elements sold on the EU market, plus importers and distributors. |
| Requirement | Yes once the regulation applies; sector-specific products and non-commercial open source are out of scope. |
| Cost | Risk-based, but at least five years of support and handling are the legal minimum; the cost scales with product line, not headcount. |
| Cadence | Before release and for every update, plus continuous monitoring. Exploited flaws need an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of the fix. |
AISafe Labs delivers on-demand, audit-ready evidence for the full CRA chain. Scheduled scans match the release and reporting cadence, diff-based monitoring catches new issues between scans, and the VPN Agent reaches embedded, on-prem, or private-network targets without a permanent appliance. The ML Classifier cuts scanner noise by 50 percent, and Sniper Auto-Exploiter confirms findings with request, response, and proof, so the annex-level evidence is timestamped, validated, and report-ready in PDF, DOCX, or JSON.
