Loading the latest actively exploited vulnerabilities…Powered by Achilles

Our Products & Services

Comply.Land is the only platform combining CRA advisory, AI-powered tooling, EU Authorised Representation, and Conformity Assessment Body services under one roof.

Products and services

CRA compliance requirements vary by product class, business model, and route to market. No two conformity journeys look alike. Whether you require a gap assessment, an AI-powered SAAS platform to manage your SBOM and vulnerability obligations, an EU Authorised Representative, or a Conformity Assessment Body to certify your Class I or Class II product, or ITSEF technical security evaluation for critical ICT products, Comply.Land has a dedicated service for every stage of the CRA lifecycle.

If you are unsure where to start, our CRA experts will map your unique roadmap to compliance for the EU market.

Available now

CRA Consultancy

Bespoke Cyber Resilience Act support for your company and product portfolio. Our specialists help with CRA gap assessments, product classification, technical documentation, vulnerability management and reporting obligations.

Available now

CRA Workshops

Our practical online or on-site workshops are tailored to your products, teams and current stage of CRA preparation. We help your colleagues understand their responsibilities, work through real compliance questions and build knowledge that stays within the company.

Available now

Free Assessment Review

Do you already have a compliance assessment, gap analysis or technical documentation? Our experts will review it and return a pass or fail determination within 2 working days, completely free of charge and with no obligations.

Available now

CRA Courses

Structured training on the Cyber Resilience Act for engineers, legal, compliance and leadership teams. Our first course, Cyber Vulnerability Reporting: Fundamentals, covers the reporting obligations that apply from 11 September 2026 and how to prepare for them.

Available now

Reference Materials

Books and CRA dossiers written by practitioners, available as digital downloads from our shop. Editions in further European languages are coming soon, and individual dossiers tailored to your exact needs can be ordered on request.

Demo available

Fleet

Deployed on your own infrastructure, Fleet monitors your full dependency tree, generates signed SBOMs, alerts teams when new vulnerabilities are identified, and prepares the evidence and reporting workflows required when actively exploited vulnerabilities must be notified to ENISA and national CSIRTs.

Free beta

Achilles

A free desktop app that inventories the applications installed on a machine and reports outdated runtimes, weakened hardening and known vulnerabilities, with ENISA's EU Vulnerability Database as its primary feed. Available for macOS, Windows and Linux.

Coming soon

Authorised Representation

The CRA requires any manufacturer based outside the EU to appoint an EU Authorised Representative before placing a product with digital elements on the European market. Comply.Land provides this service. We act as your compliant point of contact with market surveillance authorities.

Accreditation in progress

ITSEF Lab

We are creating an ITSEF Lab: an Information Technology Security Evaluation Facility, the licensed laboratory that evaluates the security of products under Common Criteria and the CRA's third-party assessment routes. Accreditation is under way, and we will announce it here once granted.

Platform walkthrough

Compliance in action, a walkthrough of the documentation, tracking, and certification workflow

Free documentation review

Already have a compliance assessment? We will check it for free. Our team of experts will review your existing gap analysis, conformity assessment, or technical documentation, whether it covers CRA, RED or other EU regulations. They will return a pass or fail determination within 2 working days, completely free of charge.

AI-generated and template-based assessments frequently contain errors, omissions, or misclassifications that will not hold up to regulatory scrutiny. Should yours fail, reach out to Comply.Land's advisory services for remediation support, to take you from failing to conformant. This is a free service with no obligation. By submitting, you confirm that you are authorised to share the documentation with Comply.Land.

Submit your document
Key dates

Regulatory timeline

Understanding when obligations take effect is critical for product planning.

10 December 2024

CRA entry into force

The Cyber Resilience Act officially entered into force. A 36-month transition period began for manufacturers to adapt to the new requirements.

11 June 2026

CAB notifications begin

Member States must begin notifying the European Commission of Conformity Assessment Bodies authorised to conduct third-party assessments under the CRA. This establishes the auditing infrastructure.

11 September 2026

Reporting obligations active

Manufacturers must begin reporting actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs within 24 hours of discovery. This is a critical milestone requiring operational readiness.

9 December 2026

PLD transposition deadline

Member States must transpose the new Product Liability Directive into national law. Strict liability for defective software, including data loss caused by security vulnerabilities, becomes enforceable for products placed on the market from this date.

11 December 2027

CRA full application

The transition period ends. All products with digital elements placed on the EU market must fully comply with Annex I cybersecurity requirements, possess complete technical documentation, and bear the CE marking.

Get started

Contact us for a product classification consultation, or sign up to explore the platform.

Contact us