Boxfish Labs home
Boxfish Labs
  • Services
  • Solutions
  • Resources
  • About
  • EN
  • DE
  • HU
Book a Call
Boxfish Labs home
Boxfish Labs

Menu

    • Information Security Advisory
    • External CISO
    • External DPO
    • Data Residency & Sovereignty
    • Human-Centric Cybersecurity Awareness
    • Book a Call
    • View all services
    • By Framework
      • GDPR
      • ISO 27001
      • DORA
      • TISAX
      • EU AI Act
      • Cyber Resilience Act
    • Who We Help
      • Startups
      • Scaleups
      • SMEs
      • Organisations
      • Educators
      • Individuals
    • View all solutions
    • Courses
    • Downloads
    • Compliance Glossary
    • View all resources
    • About us
    • Pledge
    • Social impact
    • Partnerships
    • Contact
    • View about Boxfish Labs
  • EN
  • DE
  • HU
Book a Call
Cyber Resilience Act solutions

Build secure products that stay secure throughout their lifecycle.

Boxfish Labs helps software vendors, product teams, startups, scaleups, SMEs, and connected-product organisations turn Cyber Resilience Act expectations into practical secure-by-design development, vulnerability handling, product-security governance, and lifecycle resilience.

Book a Call

About Cyber Resilience Act

Customers increasingly expect the products they buy to be secure by design, responsibly maintained, and supported when vulnerabilities emerge. Regulators are reinforcing that expectation through the Cyber Resilience Act (CRA), which establishes cybersecurity requirements for many products with digital elements made available in the European market.

For product companies, cybersecurity cannot be treated as a final testing step or a policy owned only by one technical specialist. It needs to be connected to product strategy, architecture, secure development, supplier selection, vulnerability management, updates, customer communication, support, and leadership oversight.

Boxfish Labs helps teams build a proportionate product-security programme before compliance becomes an emergency. We assess your product and development reality, identify the CRA-related questions and risks most relevant to you, and turn them into a practical roadmap that supports product trust, customer requirements, and more resilient growth.

Who this is for

  • Software vendors making applications, platforms, SaaS products, developer tools, or other products with digital elements available in the EU
  • Startups and scaleups building connected devices, IoT products, smart hardware, embedded software, or digital services connected to physical products
  • Product, engineering, security, and leadership teams that need to strengthen secure-by-design and vulnerability-management practices
  • Organisations responding to customer product-security questionnaires, procurement requirements, audits, or market-access concerns
  • Companies that rely on open-source components, cloud services, external development teams, AI providers, SDKs, libraries, firmware, or complex software supply chains
  • Businesses that need senior product-security and cybersecurity leadership before a full-time CISO or product-security function is justified

What the Cyber Resilience Act means in practice

The Cyber Resilience Act introduces cybersecurity requirements for many products with digital elements placed on the EU market. Applicability, classification, duties, and timelines depend on the product and role in the value chain. The practical direction is clear: manufacturers and other relevant economic operators need to take responsibility for cybersecurity across a product’s lifecycle.

For many organisations, readiness involves building or strengthening:

  • A clear inventory of products, components, software dependencies, suppliers, and supported versions
  • Secure-by-design and secure-by-default product and development practices
  • Product-security governance, roles, decision rights, and accountability
  • Risk assessment and security requirements throughout design, development, release, operation, and change
  • Secure development lifecycle activities, testing, review, access control, and release management
  • Software supply-chain visibility, open-source governance, third-party component management, and supplier assurance
  • Vulnerability intake, assessment, prioritisation, remediation, disclosure, customer communication, and coordination
  • Security updates, patching, support periods, end-of-support decisions, and lifecycle documentation
  • Incident response, monitoring, evidence, technical documentation, and continuous improvement

The right model should fit your product, customers, architecture, development maturity, risk profile, and available resources. It should be rigorous enough to build trust, but practical enough that teams can operate it consistently.

Challenges we help solve

You are unsure whether the CRA applies to your product

We help you establish a practical product and role inventory, understand relevant product characteristics and market context, identify the questions that require deeper legal analysis, and focus your security work on the risks that matter most.

Security is happening too late in product development

We help embed security into product discovery, architecture, requirements, design, development, testing, release, and change management -so issues are addressed earlier, with less cost and disruption.

You do not have a formal vulnerability-management process

We help create practical routines for receiving, triaging, assessing, prioritising, fixing, documenting, disclosing, communicating, and learning from vulnerabilities.

You lack visibility of software components and dependencies

We help map products, modules, services, libraries, open-source components, vendors, cloud dependencies, development tools, and supply-chain risks so teams can make more informed security and lifecycle decisions.

Product security has unclear ownership

We help define leadership accountability, product and engineering responsibilities, security decision rights, escalation paths, risk acceptance, reporting, and evidence ownership.

Customers need better security answers

We help turn product-security practices into credible customer, procurement, audit, investor, and partner responses -supported by clear documentation, governance, and evidence.

People need secure-development and reporting habits

We design practical awareness, engineering guidance, interactive learning, simulations, and role-aware reinforcement so developers, product managers, support teams, and leaders can recognise and act on product-security responsibilities.

A practical CRA readiness roadmap

01 - Understand products, roles, and market context

Identify the products with digital elements you provide, the product versions and support model, intended uses, users, markets, suppliers, distribution channels, development arrangements, and your role in the value chain.

02 - Map the product-security baseline

Review architecture, assets, data flows, development practices, components, dependencies, access, testing, release processes, vulnerability handling, updates, support, incident response, policies, ownership, and current evidence.

03 - Assess risk and prioritise gaps

Identify material threats, security weaknesses, supply-chain exposure, customer commitments, product risks, and likely regulatory or market expectations. Turn the findings into a proportionate roadmap with accountable owners and realistic sequencing.

04 - Build secure lifecycle practices

Strengthen secure-by-design requirements, development and review routines, component governance, vulnerability management, disclosure, updates, supplier assurance, documentation, incident processes, and relevant awareness activities.

05 - Maintain, monitor, and improve

Product security continues after release. Review vulnerabilities, threats, component changes, supplier updates, customer feedback, incidents, support obligations, documentation, and control effectiveness throughout the product lifecycle.

Key product-security capability areas

Secure by design and by default

Security requirements and risk decisions are addressed early in product design and architecture. Default settings, access, data handling, dependencies, interfaces, and operational controls are designed to reduce avoidable exposure.

Secure development lifecycle

A repeatable approach to integrating security into planning, design, implementation, review, testing, release, deployment, change, and maintenance. The appropriate activities depend on your product and risk profile.

Software supply-chain security

Visibility and governance for libraries, open-source software, SDKs, APIs, build pipelines, external development, cloud platforms, model providers, firmware, and other components that can introduce security or availability risk.

Vulnerability management and disclosure

Clear processes for receiving reports, monitoring sources, assessing severity, prioritising remediation, coordinating fixes, communicating with customers, publishing advisories where needed, and learning from recurring weaknesses.

Updates, patching, and support lifecycle

A practical model for security updates, patching, version support, end-of-support decisions, customer communication, change management, and evidence that the product can be maintained securely over time.

Product-security governance

Defined roles and accountability across leadership, product, engineering, security, support, legal, privacy, and suppliers. This includes decision-making authority, risk acceptance, escalation, reporting, and review.

Technical documentation and evidence

A maintainable evidence base covering product scope, security requirements, risk assessments, architecture, components, testing, vulnerabilities, updates, supplier arrangements, decisions, and lifecycle activities.

Incident readiness and recovery

Preparation for product-security incidents: detection, escalation, technical response, containment, recovery, customer communication, regulatory considerations, lessons learned, and improvement.

Outcomes

  • A clearer view of which product-security and CRA questions are most relevant to your business
  • A practical secure-by-design and lifecycle-security roadmap tailored to your product and team maturity
  • Stronger governance, ownership, risk management, evidence, and leadership visibility for product security
  • More reliable secure-development, component, vulnerability, disclosure, patching, and support practices
  • Better answers for customers, procurement teams, investors, partners, and future regulatory scrutiny
  • Improved resilience across cloud, supplier, data, and software dependencies
  • Security capability that becomes part of how products are built and maintained -not a late-stage obstacle

How Boxfish Labs can help

Information Security Advisory

Get a focused CRA readiness assessment, product-security gap analysis, framework interpretation, risk roadmap, policy guidance, evidence review, and support for customer or stakeholder requirements.

Explore: Information Security AdvisoryUseful when →

Useful when

you need to understand the product-security work ahead, respond to a customer question, assess a new product, or launch a defined readiness project.

Explore: Information Security AdvisoryBack →

External CISO

Gain ongoing senior cybersecurity leadership for product-security strategy, risk oversight, governance, secure-development priorities, vulnerability-management maturity, executive reporting, and continuous improvement.

Explore: External CISOUseful when →

Useful when

product cybersecurity needs sustained leadership and accountability across engineering, product, operations, suppliers, and leadership.

Explore: External CISOBack →

Data Residency and Sovereignty Strategy

Map product data flows, cloud and SaaS dependencies, supplier concentration, data locations, third-country exposure, access patterns, recovery needs, and regional alternatives that affect resilience and customer trust.

Explore: Data Residency and Sovereignty StrategyUseful when →

Useful when

your product relies on cloud infrastructure, external platforms, AI services, data-intensive workflows, or suppliers that create critical availability and sovereignty dependencies.

Explore: Data Residency and Sovereignty StrategyBack →

Human-Centric Cybersecurity Awareness

Build security capability across the people who design, build, launch, support, and operate products. Use role-aware learning for secure development, vulnerability reporting, secure product decisions, incident response, and customer communication.

Explore: Human-Centric Cybersecurity AwarenessUseful when →

Useful when

product and engineering teams need practical security habits that go beyond generic corporate awareness training.

Explore: Human-Centric Cybersecurity AwarenessBack →

External DPO

Connect product-security work with personal-data processing, privacy-by-design, DPIAs, vendor and processor arrangements, transparency, retention, breach response, and the GDPR obligations relevant to your product.

Explore: External DPOUseful when →

Useful when

your product processes personal data or product-security decisions overlap with privacy, customer-data, and contractual responsibilities.

Explore: External DPOBack →

FAQs

Applicability depends on the product, its functions, how it is made available, and the organisation’s role in the value chain. The CRA covers many products with digital elements, but the exact interpretation can be nuanced. We can help establish a practical product inventory and readiness view; for formal legal interpretation, work with qualified legal counsel.

No. The CRA concerns products with digital elements and can be relevant beyond connected hardware. Software products, applications, components, and connected systems may all need to consider applicability and lifecycle cybersecurity responsibilities.

Not always. Smaller organisations can establish proportionate product-security roles, practices, and external support before they need a full dedicated team. The important point is clear ownership, repeatable processes, and the ability to manage risk throughout the product lifecycle.

ISO 27001 helps establish organisational information-security management, governance, risk management, and continuous improvement. CRA readiness focuses on cybersecurity requirements for products with digital elements throughout their lifecycle. An ISO 27001 programme can provide useful foundations, but it does not automatically cover all product-specific CRA expectations.

Yes. We can help design practical vulnerability intake, triage, severity assessment, remediation, communication, disclosure, record-keeping, and improvement processes that fit your product, customers, team, and support model.

We provide practical cybersecurity, governance, risk, privacy, human-factors, and implementation support. For formal legal interpretation or legal representation, consult qualified legal counsel. We can collaborate with your counsel to translate applicable requirements into usable product, engineering, and operational practices.

Need a practical way to build product security into your lifecycle?

Tell us what you are building, how it is delivered, which components and suppliers you rely on, or what a customer has asked. We will help you identify the product-security priorities and next steps that matter most.

Book a Call
  • About Cyber Resilience Act
  • Who this is for
  • What the Cyber Resilience Act means in practice
  • Challenges we help solve
  • A practical CRA readiness roadmap
  • Key product-security capability areas
  • Outcomes
  • How Boxfish Labs can help
  • FAQs
Boxfish Labs

Human-centred security for teams that need to move fast.

LinkedInInstagramYouTubeFacebook

Explore

  • Services
  • Solutions
  • Resources
  • About

Legal

  • Privacy Policy
  • Impressum

© 2026 Boxfish Labs