Services
From the first gap assessment to the accredited test report.
Fixed price, not hourly.
Every service on this page is quoted as a fixed price with a binding delivery date, or as a monthly subscription. You get budget certainty; we are paid for the result rather than for hours on the clock. That is only possible because we automate heavily — and it is the reason we can support manufacturers for whom this level of help would otherwise be out of reach.
Advisory & preparation — not accredited10
- Article 14 reporting readiness11 Sept 2026PSIRT process, 24/72-hour and 14-day workflow, ENISA registration, incident templates, escalation matrix. Typically three to four weeks.CRA Art. 14 · PSIRT · SBOM · ENISA
- Scope & module assessmentCredited to the programmeProduct inventory, classification against Annex III and IV, and which conformity module actually applies. For many manufacturers the answer removes a notified-body procedure they do not need.Fixed price · fixed delivery date
- Module A conformity dossierGap analysis against Annex I, SBOM, vulnerability handling process, technical documentation per Annex VII. The result is a signature-ready self-assessment dossier — not a certificate.Annex I · Annex VII · SBOM
- Substantial modification procedureA documented way to decide, at each release, whether a change triggers a new conformity assessment. The test is risk-based, not size-based — and security updates generally do not count.Art. 3(30) · Art. 21 · Art. 22
- Supply chain security programmeNIS2 requires you to assess and document supplier security. We build the methodology once, then assess at a fixed price per supplier — in four languages, in your suppliers' time zones.NIS2 · Volume tiers from 20 suppliers
- CRA Compliance StackSubscriptionThe CRA requires a maintained SBOM and a working vulnerability handling process for as long as you support the product — at least five years. We build the pipeline once, connect it to your build process, and then run it: continuous component monitoring, alerts on new critical findings, a monthly status report, and an annual audit pack you can hand to a customer or an authority. Built on open-source tooling. No licence lock-in, and the pipeline stays yours.SBOM · CycloneDX · CRA Art. 13
- OT network visibilityMost industrial sites do not know their production network completely: which devices talk, over which protocols, and what reaches the outside. For IEC 62443 and NIS2 that knowledge is the starting point for everything else. We listen passively — no active scans, no interference with production. You get a full asset and communication inventory, the unexpected connections, the IT/OT boundary crossings, and an assessment against the zone and conduit model. Where you want detection afterwards, we write a rule set derived from what we actually found — not a standard set that produces a hundred false positives a day.Suricata · Zeek · IEC 62443 · § 31 BSIG
- M&A cyber due diligenceAcquiring a software or hardware company? Know the cybersecurity liabilities before you sign: CRA and NIS2 gaps, SBOM analysis, open vulnerabilities.PE · Corporate M&A
- Cyber insurance readinessInsurers price what they can verify. Outside-in scans show your external attack surface — they cannot show whether MFA is actually enforced, whether a backup actually restores, or whether your incident response plan has ever been tested. We assess and document what the scan cannot see, in a form your broker or underwriter can rely on. Reporting on the renewal cycle keeps the evidence current, so the next renewal is not a fresh negotiation.Underwriting evidence · Renewal reporting · IR readiness
- Digital Product PassportFrom 2027The battery passport becomes mandatory on 18 February 2027 for LMT batteries, industrial batteries above 2 kWh and EV batteries — the first legally fixed DPP deadline. Iron and steel, textiles, furniture and electronics follow. Someone has to verify that what the passport claims is actually true. Register your interest and we will come back to you when the programme opens.EU ESPR · Battery Regulation · 18.02.2027

Accredited testing — Teligencia Labs SARL03
- Industrial & automotiveIEC 62443-4-2 for ICS components. TARA and ISO/SAE 21434 — the evidence your OEM requires from you as a supplier.IEC 62443 · ISO/SAE 21434 · UNECE R155
- Radio & connected productsEN 18031 and ETSI EN 303 645 assessments for RED Article 3.3 and CRA evidence.EN 18031 · ETSI EN 303 645
- Penetration testing & VAPTVulnerability and penetration testing with formal laboratory reports recognised under the ILAC MRA.VAPT · Formal reporting
Impartiality
Where we have provided advisory or preparation services for a product, accredited testing of that same product is performed by an independent laboratory. This safeguards the impartiality required under ISO/IEC 17025 clause 4.1.
Primary sources
Read it yourself.
We would rather you checked. These are the texts and the bodies behind everything claimed on this site.
The legislation
- Cyber Resilience ActOpens on an external siteThe full text, including Annex I requirements and the Article 14 reporting duty.Regulation (EU) 2024/2847
- NIS2 DirectiveOpens on an external siteRisk management and reporting duties for essential and important entities.Directive (EU) 2022/2555
- Radio Equipment Directive, Art. 3(3)Opens on an external siteThe delegated regulation that activated the network, privacy and fraud requirements.Delegated Reg. (EU) 2022/30
- Battery RegulationOpens on an external siteArticle 77 sets the first legally fixed Digital Product Passport deadline.Regulation (EU) 2023/1542
Standards & accreditation bodies
- ENISAOpens on an external siteThe EU agency that receives Article 14 reports and runs the single reporting platform.ENISA
- TUNACOpens on an external siteThe accreditation body that issued our ISO/IEC 17025 accreditation, 2-0155 — recognised internationally through the ILAC Mutual Recognition Arrangement. Verify it here.TUNAC
- ILAC signatory searchOpens on an external siteConfirm for yourself that a TUNAC report is recognised under the mutual recognition arrangement.ILAC MRA
- ETSIOpens on an external sitePublisher of EN 303 645, the consumer IoT baseline we assess against.ETSI
- BSIOpens on an external siteThe German federal cyber security authority behind Section 31 BSIG and the C5 catalogue.BSI