PandaX · Venture Studio EU Cyber Resilience Act · Compliance platform
Scroll to open
EU Cyber Resilience Act · reporting starts 11 Sep 2026

Cyber
compliance
without a
cyber team

If your product has a chip in it and connects to anything, a new EU law now makes security your legal responsibility. PandaX handles it — we read your product's software, find the vulnerabilities, and produce the paperwork Brussels asks for. Built for people who make devices, not for security engineers.

Check my product — free See the platform

You build products.
Not threat models.

The problem
01
A law you didn't
ask for
The Cyber Resilience Act covers anything with software that connects — Wi-Fi, Bluetooth, USB, a cloud app. Sell it in the EU and security documentation is no longer optional.
02
Nobody in-house
to do it
It asks for a software bill of materials, vulnerability monitoring, incident reporting and a technical file. Most hardware teams have never written one, and hiring for it is expensive.
03
Getting it wrong
is expensive
Penalties reach €15 million or 2.5% of worldwide turnover — and regulators can order a product off the shelves entirely.

Everything the law
asks for. Handled.

The platform

The Cyber Resilience Act sets out a long list of duties for anyone selling a connected product in Europe. This is that list — and what PandaX takes off your desk for each one.

01 Your software list The law wants an inventory of every software component inside your product. If you don't have one, we build it from your firmware — you don't have to produce anything.
02 Daily vulnerability checks Every component is watched against the world's vulnerability databases, every day. You hear about a problem long before your customers or a regulator do.
03 Alerts in plain language No jargon and no security background needed. You get told which part of which product needs updating, why it matters, and what to do about it.
04 The technical file The core compliance document the regulation demands, generated from what we already know about your product — and re-versioned every time the product changes.
05 Declaration of Conformity The signed statement and the CE marking checklist that let you keep selling in the EU, ready to hand to a distributor or a customer who asks.
06 Incident reporting If something in your product is actively exploited the law gives you 24 hours, then 72. We start the clocks, draft the wording and file to the right authorities.
07 Ten-year retention Everything kept, dated and exportable for as long as the regulation requires — so an audit years from now is a download, not a panic.

Three steps.
That's the job.

How it works
01Tell us
what you built

Upload your software list if you have one, or point us at the firmware and we'll build it for you. No command line, no pipeline setup, no integration project.

02We watch
it for you

PandaX checks every software part against the world's vulnerability databases, every day, and tells you in plain words when something in your product needs attention.

03Export the
proof

One click produces the technical file, the EU Declaration of Conformity and the CE checklist — the pack you hand to a regulator, a customer or a distributor.

Does this law
apply to you?

30-second check · no signup
Question 01Does your product contain software, firmware or a chip that runs code?
Question 02Can it connect to anything — Wi-Fi, Bluetooth, a cable, a phone app or a cloud service?
Question 03Do you sell, import or distribute it in the European Union?
Result
The CRA applies

Your product almost certainly falls in scope, and most likely on the self-check route — the lightest one. That still means a software list, ongoing vulnerability monitoring and a technical file.

Guidance, not legal advice
Start with PandaX

The dates are
already set

Getting ready takes months, not days
Reporting starts
11 Sep 2026
From this date you must report actively-exploited vulnerabilities to the authorities within 24 hours.
Days
Hrs
Min
Sec
Everything applies
11 Dec 2027
After this date you cannot CE-mark or sell a connected product in the EU without the full compliance pack.
Days
Hrs
Min
Sec

Priced like
a tool. Not a project.

14-day free trial · no card
Single
One product
€49/ month
  • One product, unlimited versions
  • Daily vulnerability monitoring
  • Technical file & Declaration of Conformity
  • Incident reporting clocks
  • Email support
Start free trial
RangeMost chosen
Up to 5 products
€149/ month
  • Everything in One product
  • Firmware analysis included
  • Public security contact page
  • Distributor & customer evidence packs
  • Onboarding call with a specialist
Start free trial
Portfolio
Larger catalogue
Talkto us
  • Unlimited products & sub-brands
  • Multiple teams and sites
  • Importer & distributor roles
  • Single sign-on
  • Named compliance contact
Book a call

Straight
answers

FAQ

Almost certainly yes. The law covers any product with digital elements — a lamp with an app, a sensor with Bluetooth, a toy with firmware. Size doesn't exempt you, and neither does simplicity. A handful of categories are carved out because other rules already cover them, such as medical devices, cars and marine equipment. Our 30-second check above will tell you where you stand.

It's simply a list of the software inside your product — the open-source libraries and components your firmware is built from. The law requires you to keep one and to know when something on that list develops a security problem. If you don't have one, PandaX can generate it from your firmware; you don't need to produce it yourself.

For roughly nine out of ten products, no. Most sit in the default category, where you're allowed to assess your own product and declare conformity yourself — provided you can show the evidence. That evidence is exactly what PandaX produces. Certain higher-risk categories, such as firewalls and password managers, do need an outside body, and we'll tell you clearly if that's you.

No. Bring what you have — existing risk assessments, test reports, update policies — and PandaX slots them into the structure the law expects, then shows you only the gaps that are left. Most teams find they're further along than they feared, and that what's missing is the ongoing monitoring rather than the paperwork.

Most customers are live on the same day. Upload a software list or a firmware image, answer three questions about your product, and the dashboard fills in. There's no build-system integration and nothing for your engineers to maintain — which is the whole point.

Find out where
you stand

Two minutes, one product, no card. We'll show you exactly what the Cyber Resilience Act asks of you — and how much of it we can take off your desk.