SERVICES
Bringing an industrial product to the European market, compliant and without surprises
Every package has a closed scope, a stated duration and an output you know before you start. No open-ended audits: you know what you get, and when.
- An OEM customer asks you for compliance during vendor qualification — without it, you're out of the running.
- You've adopted AI in processes or products without knowing what the AI Act actually requires.
- You have products already on the market, and the 11 September CRA deadline applies to them too.
- You need to train the team — on AI, on IEC 62443, or on both together.
Below, the packages grouped by need. If you're not sure which one fits, start with the Regulatory Spark.
DEADLINE · 11 SEPTEMBER 2026
CRA Reporting Ready — your reporting process, ready in three weeks
From 11 September, every manufacturer of products with digital elements on the EU market must report actively exploited vulnerabilities and severe incidents: early warning within 24 hours, full notification within 72. A closed-scope engagement takes you from no process to a tested, operational system. Three weeks, declared output, immediate start.
Discover CRA Reporting Ready →STARTING POINT — FREE
Not sure which package to start from? Begin with the Regulatory Spark.
45 minutes with a CEO or CTO. No preparation. We map your actual regulatory exposure — AI Act, NIS2, CRA — and identify the most urgent package for your situation. Written summary within 24 hours.
Book the Regulatory SparkTRAINING
Three tracks, the team leaves with something that works
4-hour modules in a Learn · Practice · Build format: each participant builds a deliverable in the room that's usable immediately — not slides.
ASSESSMENT
See where you're exposed, with output declared item by item
Radar
1 day. A 4–6 page document with priority gaps and 90-day actions. To get your bearings fast.
Compass
2 days. A 15–20 page report with a 6–12 month roadmap. To decide and plan.
Two specialised tracks: AI (AI Act exposure) and OT (NIS2 / CRA). The Radar doesn't commit you to the Compass.
Radar and Compass →PROJECT-BASED CONSULTING
Closed-scope engagements, not consulting by the day
When you need a specific intervention — not training, not ongoing oversight — consulting is project-based: scope, duration and output declared before you start. A few real examples.
ANNUAL OVERSIGHT
The obligations that don't end with a project
The AI Act, NIS2 and CRA create ongoing obligations: CVE monitoring, SBOM updates, AI register, supply chain. Structured oversight over time — not generic support.
External AI Officer
When you use high-risk AI systems and the AI Act requires a responsible figure you don't have in-house.
Learn more →CRA Compliance Manager
When products on the market need ongoing vulnerability management and technical documentation.
Learn more →OT Security Advisor
When a plant or OT line needs a security posture maintained over time.
Learn more →WHY A SINGLE POINT OF CONTACT
Three lenses on the same problem
The AI Act, OT cybersecurity and EU regulation aren't three separate conversations: they're three lenses on the same problem — bringing an industrial product to the European market with the skills, posture and compliance that customers and regulations require. A single point of contact holding them together keeps training from ignoring regulatory constraints, keeps the assessment talking to the oversight, and spares you from integrating across different vendors.
- ISO/IEC 42001
- IEC 62443
- UNI 11814
- UNI/CT 533
- ETSI TC CYBER