CSA Group
Compliance Engine Self-service product security & CRA compliance
How it works Standards Pricing Log in
EU Cyber Resilience Act · Self-service

Know your product is secure — before anyone else tests it.

Upload your firmware and get an automated security and CRA-compliance report in minutes, not weeks. No quote. No waiting. No manual back-and-forth.

Log in to start a scan See how it works
< 5 min
to your first result
63
automated analysis modules
100%
of findings mapped to your standard
Why it matters

Firmware is the most under-tested surface in the products you ship.

Attackers don't find new vulnerabilities — they look for known ones in components manufacturers forgot they were using. The vulnerability ships with the product.

Hidden components

Modern firmware holds hundreds of open-source libraries and legacy code no single engineer fully knows. A single unpatched one is enough.

Manual audits don't scale

Traditional audits are slow, inconsistent, and depend on individual assessor skill. Weeks pass before you learn whether a product passes.

Regulators want evidence

The EU CRA and RED require documented, traceable security evidence for every connected product placed on the market.

The clock is running

CRA vulnerability reporting begins Sept 11, 2026; full conformity and CE marking are due Dec 11, 2027.

How it works

Upload a binary in. Full security picture out.

The engine extracts your firmware, matches every component against known vulnerabilities, boots it to probe the live attack surface, and maps the evidence to each requirement — automatically.

1
Upload

Drop your production image — .bin, .img, .ubi, .ota, or vendor-encrypted.

2
Analyse

Extraction, static analysis, live QEMU emulation, SBOM & CVE matching run automatically.

3
Score

Findings mapped to your product and a technical-readiness score against your standard.

4
Report

Interactive report, CycloneDX SBOM, and CRA requirement mapping — shareable instantly.

Powered by the open-source EMBA analyzer + a Claude reasoning layer that turns raw findings into requirement-level evidence.

What the engine finds

Every layer of the image, checked.

Components & CVEs

Every package cross-referenced against NVD, CVE.org, and Exploit-DB, flagging CISA Known Exploited Vulnerabilities.

Hardcoded credentials

Default passwords, private keys, and API tokens surfaced from the filesystem before an attacker finds them.

Binary hardening

NX, PIE, RELRO, and stack canaries verified on every compiled binary in the image.

CycloneDX SBOM

A machine-readable inventory of every component and version — the foundation of ongoing CVE monitoring.

Live emulation

The firmware is booted in QEMU and probed like a real attacker would — catching runtime issues static analysis can't see.

AI requirement mapping

Every finding is mapped to the specific CRA essential requirement it affects — with the evidence, in plain language.

Standards coverage

One scan. Evidence for every standard you're tested against.

The same firmware evidence maps across the frameworks CSA Group assesses — so nothing is re-run when you move toward full certification.

EU Cyber Resilience Act ETSI EN 303 645 EN 18031 UL 2900-1 / 2900-2-1 UL 2941 ISO/SAE 21434 IEC 62443-4-2
From free scan to full certification

Every dollar of self-service credits toward certification.

STEP 1
Free scan

Upload firmware, get an instant automated report.

STEP 2
Pre-cert evidence

A signed readiness summary you can share with buyers today.

STEP 3
Gap remediation

Detailed findings, fix guidance, and unlimited re-scans.

STEP 4
Full certification

A CSA expert takes over — your scan history reduces the effort.

Plans & pricing

Start free. Scale to lifecycle compliance.

Pay per scan while you iterate, or subscribe for continuous CRA compliance. Every dollar spent on self-service is credited toward full certification.

Starter
TBDper scan

See where one product stands before committing to anything.

Full scan — extraction, CVEs, SBOM, emulation CRA readiness score & requirement mapping PDF report & CycloneDX SBOM export
Start a scan
Recommended for CRA Lifecycle
TBDper product / month

Continuous compliance for the 5-year post-market obligation.

Unlimited re-scans on every release Daily CVE monitoring with impact analysis VEX records & audit-ready evidence packs Version diffing between releases
Subscribe
Certification
TBDper product, after scoping

Expert-led conformity assessment, built on your scan history.

CSA cybersecurity expert engagement Self-service spend credited in full Formal conformity documentation
Request scoping call

Pricing to be finalised. Certification engagements are quoted per product after a scoping call.

Start with a scan. See where you stand.

No quotes, no engagement letters, no waiting weeks for a PDF. Just answers.

Log in to the Compliance Engine