Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / Prepare

Prepare

Product security assessment and CRA preparation

Assess the actual capability to design, maintain, patch and document a product intended for Europe.

In your situation

What the scoping will need to take into account.

Ability to establish

Examine security across the actual lifecycle of each product.

Scope follows products, versions and support periods to link design, dependencies, vulnerabilities, fixes and maintained documentation.

Point of convergenceProduct cycle mapGovernance, technical and evidence

Subject of the work

Security follows each product throughout its lifecycle.

Demonstration example
01Map products, versions and supportProduct cycle map
02Review the development cycle, dependencies, SBOM and patchesSecurity gaps
03Test vulnerability and incident operationsProduct evidence index
04Link market requirements to product evidencePreparation plan

How it actually unfolds

Organise the review before mobilising the teams.

Working format

Assessment by product line combining product interviews, a review of the development cycle and version sampling.

Client-side mobilisation

Product, engineering and security present design decisions, dependencies, vulnerabilities and support practices.

Starting elements

Product portfolio, supported versions, architecture, repositories and pipelines in scope, SBOM, vulnerabilities, incidents and support policy.

Building the schedule

Depth depends on the number of products and versions; the work follows delivery milestones and the relevant market deadlines.

Review

Track versions, dependencies and vulnerabilities throughout the lifecycle.

01

Map products, versions and support

The portfolio is broken down by product, supported version, support period and maintenance responsibility.

02

Review the development cycle, dependencies, SBOM and patches

Design, dependencies, build chain, SBOM and patch delivery are examined against identifiable versions.

03

Test vulnerability and incident operations

The handling of a report is replayed from receipt through to qualification, the product decision and communication.

04

Link market requirements to product evidence

Market requirements are linked to the evidence from the product lifecycle and to the validations that remain outside the technical mandate.

Handover

The security file associated with the product cycle.

Product cycle map

The map links products, supported versions, components, build chain and maintenance responsibilities.

Security gaps

Gaps are linked to the affected versions, their exploitability, and the fix or support decisions.

Product evidence index

The index brings together architecture, SBOM, tests, tickets and fixes with the exact version they serve to document.

Preparation plan

The plan sequences the work required before a market launch, a client audit or a regulatory deadline.

Scoping the engagement

Define the products and versions that will be included in the review.

The list of products, maintained versions and market deadlines makes it possible to select the cycle and evidence that will need to be examined.