Cyber Security: Painless

Declarations of Conformity (CRA) and NIS2 seamlessly integrated within your processes.

Secure IT Landscape (NIS2) for Secure Software Engineering (CRA)

We make your organisation cyber-resilient

We support your organisation in raising the security level of your products with digital elements. We help you meet the technical and regulatory requirements of the EU Cyber Resilience Act (CRA) and the NIS 2 Directive — through tailored integration and automation. Our established and well-attuned approaches bring security into your software development without impacting your productivity.

Cyber Resilience Act (CRA)

We guide organizations through every phase of CRA readiness — from portfolio assessment to secure-by-design implementation. Our structured methodology ensures your connected products meet regulatory security and documentation requirements while maintaining development agility.

CE Compliance

We design and implement CE workflows that align technical documentation, test evidence, and manufacturer declarations. With our support, your CE process becomes traceable, audit-ready, and seamlessly integrated into your product lifecycle.

Process Management

We gonna make your Secure Software Development Lifecycle (SSDLC) processes smooth and pragmatic. Through gap analyses, best-practice frameworks, and integration into your existing QMS structures, we get your security and compliance as a natural part of your daily operations.

Software Compliance

Our experts ensure that your software meets the latest cybersecurity and legal expectations. From secure coding and vulnerability management to verification & validation — we help you prove and maintain compliance according to IEC 62443-4-1, IEC-62443-4-2, ISO 27001, and CRA requirements.

New Product Development

We support teams in developing new products under Security-by-Design principles. Through architecture reviews, dependency checks, and automated test/documentation pipelines, we help you launch secure, CRA-ready products faster or keep your fast-paced productivity alive.

Refit / Retrofit

Legacy systems remain critical to many businesses. We encapsulate, isolate, and secure your existing software in controlled environments (VMs or containers) — enabling continued operation and CRA-conformity without costly redevelopment.

NIS2 – Your IT Security in Focus

From the initial assessment of whether NIS2 applies to your organisation, through the introduction of an Information Security Management System (ISMS) based on ISO 27001, to communication with the supervisory authority — we accompany you step by step.

NIS2 – Our Services

We assess your NIS2 applicability, identify areas for action, develop a clear implementation roadmap, and establish robust structures for supply chain protection, incident reporting, and long-term compliance.

Time is running out

Fixed Deadlines on your Radar

If you don't act, its going to be expensive

9/11/26
Vulnerability Reporting in place
12/11/27
CE Marking, User Docs, Essential Reqs & SSDLC
in force
NIS 2 – Implementation, deadline, national law, entry into force

Your Guidance to Compliancy

Empowering Your Cyber & Business Resilience

At die RESILIENZ GmbH,

we support organizations navigate the challenges of the EU-Cyber Resilience Act (CRA) and related European regulatory frameworks with confidence and proven processes to lower compliance-related fractions dramatically.

CE-Compliance Integration

Integrate CE conformity workflows directly into your development pipelines for traceable, audit-ready product releases through automation, and tooling w/o additional pain for your engineering team.

Secure Development Processes (SSDLC)

Design and implement structured, secure development workflows that align with CRA, IEC 62443-4-1, and ISO 27001 standards without losing your development speed.

Product Retrofit & Re-Engineering

Modernize or encapsulate existing systems to achieve CRA readiness and extend the lifecycle of legacy products securely. Keep your cash cow alive by retrofitting them.

Empowering your teams to build secure, compliant, and future-ready products.

CRA Readiness & Compliance Consulting

Assess product portfolios abd development processes to verify your CRA readiness. Identify regulatory gaps, and develop individually tailored strategies to achieve full Cyber Resilience Act compliance painlessly.

Security Verification & Validation

Ensure your software's security requirements are met through structured testing, vulnerability analysis, and audit-ready documentation; as part of your automated test suite.

Project Management for CRA Implementation

Lead and coordinate cross-functional teams to ensure smooth integration of CRA and CE requirements into ongoing projects to be able to sell your products safely after the CRA must be fulfilled.

Non-compliance brings your business to the edge of existential threat

Massive Financial & Market Impact

Non-Compliance Aspects Embraces Every Layer — Product, Process, Reporting, Documentation & each leads to Heavy Fines, Sanctions, and Long-Term Legal Exposure

€ 15 Mio or up to 2,5 % of your total worldwide annual turnover

Non-compliance with the essential cybersecurity requirements as set out in Annex I and the obligations set out in Articles 13 and 14.

€ 10 Mio or up to 2 % of your total worldwide annual turnover

Non-compliance with the obligations set out in Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32(1), (2) and (3), Article 33(5), and Articles 39, 41, 47, 49 and 53

€ 5 Mio or up to 1 % of your total worldwide annual turnover

The supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request

Loss of CE-Marking and Ban from the EU Market

Loss of CE can trigger sales bans, recalls, heavy fines — and in severe cases company-wide EU restrictions — causing market exclusion, trust and reputation loss.

CRA & NIS2 Packages for your Cybersecurity

With our packages we will get your products with digital elements CRA-ready and your IT landscape NIS2-compliant — to keep your cashflow running. Choose up to your needs.

Baseline

CRA/NIS2 GAP-Analysis

Your development processes for your (digital) products and your IT landscape

from €  20K
Depending on your product's complexity
  • Inventory: Delta for a secure development process according to standards
  • Highlighting standards of good practice
  • Report with action points

Implementation

Achieving CRA compliance for your products with digital elements

from €  70K
Through coaching or through our teams
  • Retrofit of existing products
  • Complete reimplementation
  • Securing the development process (supply chain, SBOM, vulnerability, update, and incident management)

Auditing

Validation of established development processes by an auditing body

from €  30K
Depends on auditor and market situation
  • Through established institutions
  • e.g., according to IEC 62443-4-1, BSI-TR-03183, ISO 27001 with ISO 27005, or ISO 33001 for risk management
  • Prove CRA compliance
  • Evidence of NIS2 compliance

References

Talks, Publications & Workshops

We regularly appear in public and share our knowledge on cybersecurity, CRA and NIS2. Our expertise in cybersecurity dates back to the early 2000s. Here you will find a selection of publications directly related to CRA and NIS2.

05/26
Selka, Sebastian; Sänn, Alexander (2026): Magdeburg – Ein schönes Produkt haben Sie da – wäre schade, wenn Sie das nicht mehr verkaufen können. Wie Cybersecurity Business Continuity gewährleistet. Seminar.
03/26
Kirchner, Lutz; Sänn, Alexander (2026): DEEP DIVE: Digitale Resilienz – Wie sicher sind unsere Unternehmensdaten wirklich?
03/26
Sänn, Alexander (2026): Stimmen aus der Praxis - IRAPS Netzwerkveranstaltung zu NIS2 und CRA
03/26
Sänn, Alexander (2026): Zuse-Business-Talk: EU-Richtlinie NIS2 und EU Cyber Resilience Act (CRA)
09/25
Sänn, Alexander; Selka, Sebastian (2025): Die EU Cyber Security-Regulierung – innovativer Booster für cyber-innovative Produkte oder Belastung im Business? 15 Jahre Berlin Institute for Innovation (BIFI)
07/25
Sänn, Alexander (2025): Cyber Resilience Act - Neue Pflichtvorgaben zu Software- und Hardware-Sicherheit. Workshop - BFM Bayreuth
05/25
Sänn Alexander; Selka, Sebastian (2025): Cyber Resilience Act: Belastung beim Business oder innovativer Booster für sichere Software? 4.Regensburger Cybersecurity-Kongress
12/24
Sänn, Alexander (2024): 38th Chaos Communication Congress - Let´s talk about regulatorische Cyber Sec Dev, baby!
11/24
Sänn, Alexander (2024): How does the Cyber Security Regulation for Processes and Products go hand in hand for Europe?, IECON 2024 - 50th Annual Conference of the IEEE Industrial Electronics Society, Chicago, IL, USA, pp. 1-5, doi: 10.1109/IECON55916.2024.10905887  

From the video series "Zukunftssicherer Mittelstand"

The Cyber Resilience Act – tracked since 2022

Since 2022, we have been following and explaining the development of the Cyber Resilience Act. Two early analyses from our YouTube series "Zukunftssicherer Mittelstand" show which questions have shaped the European debate from the very beginning – complemented by the LinkedIn posts of the original publications.

From the archive202235:45

CRA crash course: the draft explained clearly

When the European Commission presented its CRA draft in 2022, we broke down what the planned requirements would mean for manufacturers, product development, and users. The recording shows which questions have shaped the further path of the Cyber Resilience Act from the very beginning.

From the archive202310:33

CRA update 2023: key developments and points of discussion

By 2023, the European debate had gained considerably more shape. Our update brings together the most important developments and points of discussion – with a view to their relevance for manufacturers and product owners.

Contact

Let's talk

We look forward to hearing from you — whether you prefer a quick call, a video meeting, or written communication.

By Phone

Let's discuss your projects, goals, and cybersecurity challenges directly.
Phone: +49 173-2038076

Write to Us

The easiest way to reach us is by email. Please send your message to:
anfrage@resilienz.gmbh

By Post

If you prefer traditional mail, you can also contact us here:
DR – die RESILIENZ GmbH
Willy-Brandt-Platz 2
12529 Schönefeld,
Deutschland

FAQs

Frequently Asked Questions

Answers to the most important questions about CRA readiness, secure development, and our approach to compliance.

What does die RESILIENZ GmbH do?

We help organizations achieve Cyber Resilience Act (CRA) and CE compliance by integrating security, process management, and software engineering best practices. Our services cover the full lifecycle — from secure product development and retrofit solutions to training, audits, and certification support.

Who are your typical clients?

We primarily work with manufacturers, software vendors, system integrators, resellers and importers and importers who need to demonstrate CRA compliance to ensure that their products can continue to be sold on the EU market.

What is the Cyber Resilience Act (CRA) and why is it important?

The EU Cyber Resilience Act introduces binding cybersecurity requirements for connected products sold in the EU. It ensures that software and hardware are secure by design, maintained throughout their lifecycle, and supported by transparent documentation. Compliance is essential for continued market access and customer trust.

Can you help us retrofit existing products to meet CRA requirements?

Yes. Our Refit/Retrofit approach encapsulates legacy software in controlled environments — such as containers or VMs — to isolate vulnerabilities and enforce secure operation without a full redevelopment.

How long does CRA readiness typically take?

Timelines depend on product complexity and organizational maturity. After an initial GAP analysis, we provide a clear roadmap with milestones — ranging from quick improvements to full compliance integration.

Can we integrate CRA and CE compliance into our existing processes?

Yes. We specialize in embedding compliance workflows directly into your development and quality-management systems, ensuring traceability, automation, and minimal disruption to existing pipelines.

Does the integration into our existing processes hurt?

Well, not much. We are specialized in smooth integration within your development processes. We have well-attuned approaches and automations at hand, which foster your given engineering process instead of instead of tossing them aside.

Do I need all three packages?

No. If you have well trained engineers with a vast amount of experience in secure development and automation, you can use the outcomes of our GAP Analysis to get CRA-compliant without any further consultancy – but it may takes longer and is less error-prone.