Welcome to ExcID

Your Cyber Resilience Partner

Governance, risk & compliance

Building resilience into digital products

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, introduces cybersecurity requirements for products with digital elements placed on the EU market. It covers hardware and software within its scope, bringing security into product design, development, and maintenance.

Manufacturers must address vulnerabilities and provide security updates throughout the support period. The CRA also introduces conformity assessment and reporting obligations, making product security a responsibility across the lifecycle.

ExcID contributes practical expertise through research, training, and webinars, helping teams understand the CRA and develop secure software update processes.

Schedule a free 15 min. consultation

CRA timeline

Important dates

The CRA entered into force.

The rules on notification of conformity assessment bodies start applying.

Manufacturers’ reporting obligations for actively exploited vulnerabilities and severe incidents affecting product security start applying.

The main CRA obligations start applying, including cybersecurity requirements and conformity assessment for products within scope.

Source: European Commission — CRA summary and implementation dates.

European collaboration

CRACY: CRA made easy

ExcID participates in CRACY, a European project helping organisations, especially small and medium-sized enterprises, prepare for the Cyber Resilience Act.

The project develops tools and methods to support product assessment, secure development, and compliance documentation. ExcID contributes secure software update procedures, confidentiality tools, and cryptographic key management.

Explore the CRACY project
CRACY project logo

Learn with ExcID

Webinars and trainings

Explore our CRA activities and resources for building more secure digital products.

CRA webinar by ExcID

Webinar · Greek

CRA webinar by ExcID

An introduction to the Cyber Resilience Act by ExcID, presented in Greek for teams exploring the regulation and its implications for digital products.

Watch the CRA webinar
Nikos Fotiou in IT Security Pro

Interview · Greek

Nikos Fotiou in IT Security Pro

ExcID CEO Nikos Fotiou discusses the CRA, artificial intelligence, and post-quantum security in an interview on the evolving cybersecurity agenda.

Read the interview
Secure software updates training

Training · GitHub

Secure software updates training

Learn about update-system threats, signed metadata, and trust roles with The Update Framework (TUF), then practise creating a secure update repository using TUF-on-CI.

Explore the training
Secure software updates webinar

Webinar

Secure software updates webinar

Watch ExcID’s webinar on secure software updates and their role in protecting digital products as teams prepare for the Cyber Resilience Act.

Watch the updates webinar

Talk to ExcID

What does the CRA mean for your product?

Book a free 15-minute CRA consultation to discuss your questions and next steps with our team.

Schedule a free 15 min. consultation