Prepare
Product security assessment and CRA preparation
Assess the actual capability to design, maintain, patch and document a product intended for Europe.
In your situation
What the scoping will need to take into account.
Ability to establish
Examine security across the actual lifecycle of each product.
Scope follows products, versions and support periods to link design, dependencies, vulnerabilities, fixes and maintained documentation.
Subject of the work
Security follows each product throughout its lifecycle.
How it actually unfolds
Organise the review before mobilising the teams.
Assessment by product line combining product interviews, a review of the development cycle and version sampling.
Product, engineering and security present design decisions, dependencies, vulnerabilities and support practices.
Product portfolio, supported versions, architecture, repositories and pipelines in scope, SBOM, vulnerabilities, incidents and support policy.
Depth depends on the number of products and versions; the work follows delivery milestones and the relevant market deadlines.
Review
Track versions, dependencies and vulnerabilities throughout the lifecycle.
Map products, versions and support
The portfolio is broken down by product, supported version, support period and maintenance responsibility.
Review the development cycle, dependencies, SBOM and patches
Design, dependencies, build chain, SBOM and patch delivery are examined against identifiable versions.
Test vulnerability and incident operations
The handling of a report is replayed from receipt through to qualification, the product decision and communication.
Link market requirements to product evidence
Market requirements are linked to the evidence from the product lifecycle and to the validations that remain outside the technical mandate.
Handover
The security file associated with the product cycle.
The map links products, supported versions, components, build chain and maintenance responsibilities.
Gaps are linked to the affected versions, their exploitability, and the fix or support decisions.
The index brings together architecture, SBOM, tests, tickets and fixes with the exact version they serve to document.
The plan sequences the work required before a market launch, a client audit or a regulatory deadline.
Scoping the engagement
Define the products and versions that will be included in the review.
The list of products, maintained versions and market deadlines makes it possible to select the cycle and evidence that will need to be examined.

