FOR MANUFACTURERS OF PRODUCTS WITH DIGITAL ELEMENTS

Cyber Resilience Act security
testing on the binary you ship

FuzzForge tests the product as you ship it, without the source code.
Your technical documentation gets the test report Annex VII asks for.

Cyber Resilience Act security testing on binaries and embedded systems
Cyber Resilience Act security testing on binaries and embedded systems

WHAT MAKES CRA SECURITY TESTING HARD

And how FuzzForge answers Annex I

01

The regulation asks for effective and regular tests, without saying how.

→A method you can put in the file.

FuzzForge runs a campaign you can describe, date and repeat.

02

You ship components whose source you never had.

→Due diligence you can actually run.

FuzzForge fuzzes, emulates and reverses the component as your supplier delivered it.

03

Since 11 September 2026, exploited vulnerabilities must be reported.

→Finding what no list contains.

An SBOM lists published CVEs. FuzzForge goes after the flaws nobody has filed yet.

PROOF

Our Stats Speak For Us

Selected for the Cyber Defense Factory (DGA).
PWN2OWN
3 Pwn2Own wins.
1,500+ vulnerabilities found.
20+ CVEs published.

THE CALENDAR

Which deadline already applies to you?

Three of the four dates are already behind you.

10 DECEMBER 2024
11 JUNE 2026
11 SEPTEMBER 2026
11 DECEMBER 2027

In force

The regulation entered into force. Nothing was asked of manufacturers yet.

Assessment bodies

Member States started designating the bodies that will assess conformity.

Reporting

Early warning within 24 hours, notification within 72, final report within 14 days of a fix. This one covers products already on the market.

Full application

Annex I requirements, conformity assessment, CE marking and a technical file for every product placed on the market.

SCOPE

Does the Cyber Resilience Act apply to what you ship?

Article 2 points to other regulations, not to industries. A product that falls outside the named act falls back under the CRA.

Yes

A product with digital elements placed on the EU market

A software or hardware component sold separately

A component placed on the market separately is a product in its own right

No

A medical device

Covered by Regulation 2017/745 or 2017/746

A complete motor vehicle

Covered by Regulation 2019/2144

An aviation product, certified under Regulation 2018/1139

Certification is what excludes it, not the sector

A product developed exclusively for defence or national security

The regulation says exclusively

Dual-use products and uncertified components stay inside the scope. Two words in Article 2 carry the whole thing: certified, and exclusively.

WHY FUZZFORGE

Three ways to answer the test requirement

Cyber Resilience Act security testing leaves you three usual options: run the scanners on the code you wrote, inventory the components you bought in, or test the binary you ship. FuzzForge does the third. It rehosts the target and writes the harness itself. Your technical file gets a report your engineers can replay.

TO SATISFY ANNEX I, CAN IT…
SAST and SCA
SBOM and CVE scanning
FuzzForge
Test the binary you actually ship

needs source

reads it

tests it

Find a flaw nobody has published

in your source

published only

coverage-guided

Cover a supplier component

no source

lists it

tests it

Run again on every release

in CI

on rebuild

continuous

Hand you a report for Annex VII

a finding list

an inventory

replayable

Annex VII lists the reports of the tests carried out among the pieces your technical documentation must contain.

FAQ

Questions from manufacturers under the Cyber Resilience Act

No technique is mandated. Annex I asks you to apply effective and regular tests and reviews of the security of the product. Fuzzing, emulation and binary analysis are ways to produce that evidence, not obligations in themselves.

No. Recital 35 lists the ways to exercise due diligence on a third-party component: check the CE marking, check that it receives regular security updates, check that no vulnerability is published against it, or carry out additional security tests. On a binary delivered without source and without CE marking, the last one is the one still available to you.

Reporting. Since 11 September 2026, manufacturers must notify actively exploited vulnerabilities and severe incidents, for every product already made available on the EU market. Full application, with CE marking and technical documentation, comes on 11 December 2027.

Not yet. The Commission ordered 41 harmonised standards in 2025 and they are still being delivered. A standard only grants presumption of conformity once its reference is published in the Official Journal. Until then, Annex VII asks you to describe the solutions you adopted to meet the requirements.

The regulation excludes products developed or modified exclusively for national security or defence purposes. A component sold to both a military programme and a civil customer does not meet that condition, and stays inside the CRA.

Build the evidence your technical file will need

A real campaign, on a target close to yours. Findings your engineers can pick up and verify.

MEET US

Meet our researchers at these upcoming events

Secure your hardware

16 – 20 November 2026 · Amsterdam

Book a meeting

Step into the future of cybersecurity

7 – 10 December 2026 · London

Book a meeting