Loading the latest actively exploited vulnerabilities…Powered by Achilles

EU Cyber Resilience Act Compliance and Authorised Representative Services

Your CRA partner, from gap assessment to Declaration of Conformity.

Explore our servicesTalk to us
EU

The Cyber Resilience Act – together with the Product Liability Directive, and AI Act – are transforming how products enter the EU market. Whether you build hardware, develop software, or distribute digital solutions, compliance is no longer optional.

Live threat feed

Actively exploited right now

Under the CRA, actively exploited vulnerabilities must be reported to ENISA within 24 hours. The list never stops:

Newest known-exploited vulnerabilities · sources: CISA KEV & ENISA EUVD · updated daily · powered by Achilles

The clock is running

Incident & vulnerability reporting

Mandatory now

In force since 11 September 2026

Next deadline11 December 2027Full CRA compliance required

The CRA deadlines are approaching. Are you ready?

Talk to us

Is your compliance documentation actually correct?

Many compliance assessments, including AI-generated ones, contain errors, omissions, or misclassifications that will not hold up to regulatory scrutiny. Our experts will review your existing gap analysis, conformity assessment, or technical documentation, whether it covers the CRA, the Radio Equipment Directive, or another EU regulation. Within 2 working days, they will tell you whether the documentation passes or fails, completely free of charge.

Submit your documentation below. If it fails and you need help understanding why or bringing it into conformity, our team is ready to help. This is a free service with no obligation. By submitting, you confirm that you are authorised to share the documentation with Comply.Land.

Submit your document

Built for complexity ahead

The clock is running. The Cyber Resilience Act entered into force in December 2024, with full enforcement - and market bans for non-compliant products - landing December 2027. For UK and non-EU manufacturers, that means appointing an EU Authorised Representative before a single unit can legally be placed on the European market. Comply.Land provides exactly that, from our base in Malta: an English-speaking EU member state, and the most accessible gateway into Europe for companies outside the Union.

We combine CRA consultancy, training, evidence tooling and Authorised Representation under one roof, built by ETSI Rapporteurs who are translating the Regulation into European standards for market entry. The notified body framework only opened in June 2026. There is no entrenched market leader yet. Comply.Land is already ahead, with over 7,000 Comply.Land community members and the first clients onboarded.

Conference presentation
Daniel Thompson-Yvetot on the Cyber Resilience Act, what it means for software manufacturers and how Comply.Land helps

A complete compliance ecosystem

Consultancy & Workshops

Consultancy & Workshops

Bespoke assistance for your company's individual product line and reporting needs. Our CRA experts work with your team on gap assessment, product classification, technical documentation and vulnerability reporting, and run workshops on site or online.

Talk to us
Free Assessment Review

Free Assessment Review

Already have a compliance assessment, gap analysis or technical documentation? Our experts will review it and return a pass or fail determination within 2 working days, free of charge and with no obligations.

Submit here
CRA Courses

CRA Courses

Structured training on the Cyber Resilience Act for engineers, legal, compliance and leadership teams, starting with the reporting obligations that apply from 11 September 2026.

Enrol now
Reference Materials

Reference Materials

Books and CRA dossiers written by practitioners, available as digital downloads. Editions in further European languages are coming soon, and dossiers tailored to your exact needs can be ordered on request.

Visit the shop
Fleet

Fleet

Deployed on your own infrastructure, Fleet monitors your full dependency tree, generates signed SBOMs, alerts teams to new vulnerabilities, and prepares the evidence and reporting workflows required when actively exploited vulnerabilities must be notified.

Explore Fleet
Achilles

Achilles

A free desktop app that inventories the applications installed on a machine and reports outdated runtimes, weakened hardening and known vulnerabilities, with ENISA's EU Vulnerability Database as its primary feed.

Explore Achilles
Events

Events

Comply.Land is Europe's premier compliance conference, bringing together regulators, policymakers and tech leaders to shape the future of EU digital compliance. Speak, exhibit, sponsor, or simply be in the room.

Find out more
Authorised Representation

Authorised Representation

Based outside the EU? The CRA requires an authorised representative within the Union. Our office in Malta provides a compliant point of contact for market surveillance authorities and shortens your go-to-market timeline.

Get in touch
ITSEF Lab

ITSEF Lab

We are creating an ITSEF Lab, an Information Technology Security Evaluation Facility: the licensed laboratory that evaluates the security of products under Common Criteria and the CRA's third-party assessment routes. Accreditation is under way.

Get in touch
People walking

We built Comply.Land to make compliance achievable for companies of any size.

Get started

Ready to talk? Contact us to discuss your compliance needs, or sign up for our newsletter to stay informed about regulatory developments.

Contact us