About Cyber Resilience Act
Customers increasingly expect the products they buy to be secure by design, responsibly maintained, and supported when vulnerabilities emerge. Regulators are reinforcing that expectation through the Cyber Resilience Act (CRA), which establishes cybersecurity requirements for many products with digital elements made available in the European market.
For product companies, cybersecurity cannot be treated as a final testing step or a policy owned only by one technical specialist. It needs to be connected to product strategy, architecture, secure development, supplier selection, vulnerability management, updates, customer communication, support, and leadership oversight.
Boxfish Labs helps teams build a proportionate product-security programme before compliance becomes an emergency. We assess your product and development reality, identify the CRA-related questions and risks most relevant to you, and turn them into a practical roadmap that supports product trust, customer requirements, and more resilient growth.
Who this is for
- Software vendors making applications, platforms, SaaS products, developer tools, or other products with digital elements available in the EU
- Startups and scaleups building connected devices, IoT products, smart hardware, embedded software, or digital services connected to physical products
- Product, engineering, security, and leadership teams that need to strengthen secure-by-design and vulnerability-management practices
- Organisations responding to customer product-security questionnaires, procurement requirements, audits, or market-access concerns
- Companies that rely on open-source components, cloud services, external development teams, AI providers, SDKs, libraries, firmware, or complex software supply chains
- Businesses that need senior product-security and cybersecurity leadership before a full-time CISO or product-security function is justified
What the Cyber Resilience Act means in practice
The Cyber Resilience Act introduces cybersecurity requirements for many products with digital elements placed on the EU market. Applicability, classification, duties, and timelines depend on the product and role in the value chain. The practical direction is clear: manufacturers and other relevant economic operators need to take responsibility for cybersecurity across a product’s lifecycle.
For many organisations, readiness involves building or strengthening:
- A clear inventory of products, components, software dependencies, suppliers, and supported versions
- Secure-by-design and secure-by-default product and development practices
- Product-security governance, roles, decision rights, and accountability
- Risk assessment and security requirements throughout design, development, release, operation, and change
- Secure development lifecycle activities, testing, review, access control, and release management
- Software supply-chain visibility, open-source governance, third-party component management, and supplier assurance
- Vulnerability intake, assessment, prioritisation, remediation, disclosure, customer communication, and coordination
- Security updates, patching, support periods, end-of-support decisions, and lifecycle documentation
- Incident response, monitoring, evidence, technical documentation, and continuous improvement
The right model should fit your product, customers, architecture, development maturity, risk profile, and available resources. It should be rigorous enough to build trust, but practical enough that teams can operate it consistently.
Challenges we help solve
You are unsure whether the CRA applies to your product
We help you establish a practical product and role inventory, understand relevant product characteristics and market context, identify the questions that require deeper legal analysis, and focus your security work on the risks that matter most.
Security is happening too late in product development
We help embed security into product discovery, architecture, requirements, design, development, testing, release, and change management -so issues are addressed earlier, with less cost and disruption.
We help create practical routines for receiving, triaging, assessing, prioritising, fixing, documenting, disclosing, communicating, and learning from vulnerabilities.
You lack visibility of software components and dependencies
We help map products, modules, services, libraries, open-source components, vendors, cloud dependencies, development tools, and supply-chain risks so teams can make more informed security and lifecycle decisions.
Product security has unclear ownership
We help define leadership accountability, product and engineering responsibilities, security decision rights, escalation paths, risk acceptance, reporting, and evidence ownership.
Customers need better security answers
We help turn product-security practices into credible customer, procurement, audit, investor, and partner responses -supported by clear documentation, governance, and evidence.
People need secure-development and reporting habits
We design practical awareness, engineering guidance, interactive learning, simulations, and role-aware reinforcement so developers, product managers, support teams, and leaders can recognise and act on product-security responsibilities.
A practical CRA readiness roadmap
01 - Understand products, roles, and market context
Identify the products with digital elements you provide, the product versions and support model, intended uses, users, markets, suppliers, distribution channels, development arrangements, and your role in the value chain.
02 - Map the product-security baseline
Review architecture, assets, data flows, development practices, components, dependencies, access, testing, release processes, vulnerability handling, updates, support, incident response, policies, ownership, and current evidence.
03 - Assess risk and prioritise gaps
Identify material threats, security weaknesses, supply-chain exposure, customer commitments, product risks, and likely regulatory or market expectations. Turn the findings into a proportionate roadmap with accountable owners and realistic sequencing.
04 - Build secure lifecycle practices
Strengthen secure-by-design requirements, development and review routines, component governance, vulnerability management, disclosure, updates, supplier assurance, documentation, incident processes, and relevant awareness activities.
05 - Maintain, monitor, and improve
Product security continues after release. Review vulnerabilities, threats, component changes, supplier updates, customer feedback, incidents, support obligations, documentation, and control effectiveness throughout the product lifecycle.
Key product-security capability areas
Secure by design and by default
Security requirements and risk decisions are addressed early in product design and architecture. Default settings, access, data handling, dependencies, interfaces, and operational controls are designed to reduce avoidable exposure.
Secure development lifecycle
A repeatable approach to integrating security into planning, design, implementation, review, testing, release, deployment, change, and maintenance. The appropriate activities depend on your product and risk profile.
Software supply-chain security
Visibility and governance for libraries, open-source software, SDKs, APIs, build pipelines, external development, cloud platforms, model providers, firmware, and other components that can introduce security or availability risk.
Vulnerability management and disclosure
Clear processes for receiving reports, monitoring sources, assessing severity, prioritising remediation, coordinating fixes, communicating with customers, publishing advisories where needed, and learning from recurring weaknesses.
Updates, patching, and support lifecycle
A practical model for security updates, patching, version support, end-of-support decisions, customer communication, change management, and evidence that the product can be maintained securely over time.
Product-security governance
Defined roles and accountability across leadership, product, engineering, security, support, legal, privacy, and suppliers. This includes decision-making authority, risk acceptance, escalation, reporting, and review.
Technical documentation and evidence
A maintainable evidence base covering product scope, security requirements, risk assessments, architecture, components, testing, vulnerabilities, updates, supplier arrangements, decisions, and lifecycle activities.
Incident readiness and recovery
Preparation for product-security incidents: detection, escalation, technical response, containment, recovery, customer communication, regulatory considerations, lessons learned, and improvement.
Outcomes
- A clearer view of which product-security and CRA questions are most relevant to your business
- A practical secure-by-design and lifecycle-security roadmap tailored to your product and team maturity
- Stronger governance, ownership, risk management, evidence, and leadership visibility for product security
- More reliable secure-development, component, vulnerability, disclosure, patching, and support practices
- Better answers for customers, procurement teams, investors, partners, and future regulatory scrutiny
- Improved resilience across cloud, supplier, data, and software dependencies
- Security capability that becomes part of how products are built and maintained -not a late-stage obstacle