Our Products & Services
Comply.Land is the only platform combining CRA advisory, AI-powered tooling, EU Authorised Representation, and Conformity Assessment Body services under one roof.
Products and services
CRA compliance requirements vary by product class, business model, and route to market. No two conformity journeys look alike. Whether you require a gap assessment, an AI-powered SAAS platform to manage your SBOM and vulnerability obligations, an EU Authorised Representative, or a Conformity Assessment Body to certify your Class I or Class II product, or ITSEF technical security evaluation for critical ICT products, Comply.Land has a dedicated service for every stage of the CRA lifecycle.
If you are unsure where to start, our CRA experts will map your unique roadmap to compliance for the EU market.
CRA Consultancy
Bespoke Cyber Resilience Act support for your company and product portfolio. Our specialists help with CRA gap assessments, product classification, technical documentation, vulnerability management and reporting obligations.
CRA Workshops
Our practical online or on-site workshops are tailored to your products, teams and current stage of CRA preparation. We help your colleagues understand their responsibilities, work through real compliance questions and build knowledge that stays within the company.
Free Assessment Review
Do you already have a compliance assessment, gap analysis or technical documentation? Our experts will review it and return a pass or fail determination within 2 working days, completely free of charge and with no obligations.
CRA Courses
Structured training on the Cyber Resilience Act for engineers, legal, compliance and leadership teams. Our first course, Cyber Vulnerability Reporting: Fundamentals, covers the reporting obligations that apply from 11 September 2026 and how to prepare for them.
Reference Materials
Books and CRA dossiers written by practitioners, available as digital downloads from our shop. Editions in further European languages are coming soon, and individual dossiers tailored to your exact needs can be ordered on request.
Fleet
Deployed on your own infrastructure, Fleet monitors your full dependency tree, generates signed SBOMs, alerts teams when new vulnerabilities are identified, and prepares the evidence and reporting workflows required when actively exploited vulnerabilities must be notified to ENISA and national CSIRTs.
Achilles
A free desktop app that inventories the applications installed on a machine and reports outdated runtimes, weakened hardening and known vulnerabilities, with ENISA's EU Vulnerability Database as its primary feed. Available for macOS, Windows and Linux.
Authorised Representation
The CRA requires any manufacturer based outside the EU to appoint an EU Authorised Representative before placing a product with digital elements on the European market. Comply.Land provides this service. We act as your compliant point of contact with market surveillance authorities.
ITSEF Lab
We are creating an ITSEF Lab: an Information Technology Security Evaluation Facility, the licensed laboratory that evaluates the security of products under Common Criteria and the CRA's third-party assessment routes. Accreditation is under way, and we will announce it here once granted.

Free documentation review
Already have a compliance assessment? We will check it for free. Our team of experts will review your existing gap analysis, conformity assessment, or technical documentation, whether it covers CRA, RED or other EU regulations. They will return a pass or fail determination within 2 working days, completely free of charge.
AI-generated and template-based assessments frequently contain errors, omissions, or misclassifications that will not hold up to regulatory scrutiny. Should yours fail, reach out to Comply.Land's advisory services for remediation support, to take you from failing to conformant. This is a free service with no obligation. By submitting, you confirm that you are authorised to share the documentation with Comply.Land.
Submit your documentRegulatory timeline
Understanding when obligations take effect is critical for product planning.
CRA entry into force
The Cyber Resilience Act officially entered into force. A 36-month transition period began for manufacturers to adapt to the new requirements.
CAB notifications begin
Member States must begin notifying the European Commission of Conformity Assessment Bodies authorised to conduct third-party assessments under the CRA. This establishes the auditing infrastructure.
Reporting obligations active
Manufacturers must begin reporting actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs within 24 hours of discovery. This is a critical milestone requiring operational readiness.
PLD transposition deadline
Member States must transpose the new Product Liability Directive into national law. Strict liability for defective software, including data loss caused by security vulnerabilities, becomes enforceable for products placed on the market from this date.
CRA full application
The transition period ends. All products with digital elements placed on the EU market must fully comply with Annex I cybersecurity requirements, possess complete technical documentation, and bear the CE marking.
Get started
Contact us for a product classification consultation, or sign up to explore the platform.