Skip to content
BCF Embedded by Bright Coders' Factory (home page)
Discuss your project

Secure & comply

Embedded cybersecurity and Cyber Resilience Act readiness

Engineering support for manufacturers who must adapt their devices to the EU Cyber Resilience Act: secure boot, secure updates, SBOM and a working vulnerability-handling process.

· by BCF Embedded engineering team

Book a CRA gap analysisGet the CRA checklist

What the CRA changes for device makers

The CRA applies in stages. Reporting obligations already apply, also to products placed on the market earlier.

  1. December 2024

    Regulation (EU) 2024/2847 enters into force

    The Cyber Resilience Act becomes law, with staged application dates.

  2. 27 July 2026

    Commission guidance for manufacturers

    The European Commission publishes practical guidelines for manufacturers.

  3. 11 September 2026

    Reporting obligations apply

    Manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the competent national CSIRT through the Single Reporting Platform — also for products placed on the market before this date.

  4. 11 December 2027

    Main obligations apply

    Security-by-design requirements, SBOM, vulnerability handling and CE marking under the CRA apply to products placed on the EU market.

Sources

Reporting deadlines and penalties

  • Early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
  • Detailed notification within 72 hours.
  • Final report: for vulnerabilities within 14 days after a fix or mitigation is available; for incidents within one month after the notification.
  • Fines for breaching reporting obligations: up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher.
  • Security updates must be provided for at least 5 years, or for the expected time of use if it is shorter.

Our engineering scope

Secure boot

A chain of trust from immutable code to the application. See secure boot and OTA.

Hardware crypto and key storage

Using the security features of your MCU or a secure element to protect keys.

Secure OTA

Signed, verified updates with rollback — designed with IoT & connectivity.

SBOM

Software bills of materials generated in the build for every release.

Vulnerability handling

Intake, triage, fixing and the 24/72-hour reporting procedure.

Logging

Security-relevant events recorded and available for incident analysis.

CRA readiness and gap analysis

A gap analysis compares your product and processes with the engineering requirements of the CRA and gives you a prioritised plan. Inputs, outputs and the format are described on the CRA readiness audit page.

What we do and what we don't

We do

  • Assess firmware, hardware and update architecture against CRA engineering requirements
  • Implement secure boot, secure OTA, SBOM generation and logging
  • Set up a vulnerability-handling and reporting procedure with your team
  • Prepare technical documentation that your legal and compliance advisers can use

We don't

  • Provide legal advice or legal interpretations of the regulation
  • Act as a conformity assessment (CE) body
  • Certify products or issue declarations of conformity

Long-term support

CRA obligations last for the whole support period. We can maintain firmware, monitor components from the SBOM and prepare security patches for years after launch. For products already on the market, see legacy modernization.

Selected work

Security project descriptions are shared under NDA during the first call.

FAQ

Discuss your project

Describe your device and goal. An engineer replies within one business day.

Prefer e-mail?

[email protected]
  • Reply within one business day
  • NDA available before any technical deep-dive

Our offices

Opole (Headquarters): ul. Technologiczna 2, 45-837 Opole

Wrocław (Office): ul. Strzegomska 42B, 53-611 Wrocław

Warsaw (Office): ul. Żurawia 6/12, 00-503 Warsaw

BCF Embedded by Bright Coders' Factory (home page)

Firmware, hardware and security engineering for connected devices — from PoC to production.


BCF Software Sp. z o.o.

ul. Technologiczna 2, 45-837 Opole, Poland

NIP: PL 754 31 26 298 · KRS: 0000634606 · REGON: 365280382

[email protected]

Offices

Opole (Headquarters) — ul. Technologiczna 2, 45-837 Opole

Wrocław (Office) — ul. Strzegomska 42B, 53-611 Wrocław

Warsaw (Office) — ul. Żurawia 6/12, 00-503 Warsaw

© 2026 BCF Embedded by Bright Coders' Factory. All rights reserved.

Privacy & cookie policy