TrustnGoTrustnGo

Embedded security specialists

Cybersecurity for digital products

The Cyber Resilience Act is coming. Get your products ready.

Products are increasingly targeted

Cameras, routers, industrial controllers, connected medical devices: products with digital elements have become prime targets. The Mirai botnet showed as early as 2016 that unchanged default credentials were enough to hijack hundreds of thousands of connected devices.

Vulnerabilities found in widely reused software stacks, such as Ripple20 in 2020, simultaneously affected millions of industrial, medical and consumer devices, sometimes years after they were placed on the market.

These repeated incidents pushed EU lawmakers to require cybersecurity by design for the first time, rather than as an afterthought.

Three regulations, one requirement: security by design

The Cyber Resilience Act will require a cybersecurity CE marking for any product with digital elements from December 2027. But its first deadline comes much earlier: from 11 September 2026, manufacturers will have to report any actively exploited vulnerability affecting their products to the authorities.

Since August 2025, the cybersecurity provisions of the RED directive apply to wireless radio equipment. And from January 2027, the new Machinery Regulation will require cybersecurity for connected industrial machinery for the first time.

Three different texts, one consequence for manufacturers: security can no longer be an afterthought.

Our commitment

Securing an embedded device can be a challenge and demonstrating this security is another one.

During the past years, the EU has severely tightened cybersecurity requirements for IoT & embedded devices. Since August 2025, the cybersecurity part of the 2014/53/UE RED directive has entered into force and vendors of wireless digital products have to fulfill the requirements of the related EN 18031 standard.

TrustnGo provides assessment & hardening services or products to tackle these challenges and allow you to meet the requirements of the EN 18031 standard.

  • Conformity Through Self-Assessment

    In most cases it is not necessary to go through a notified body to demonstrate a product's compliance with RED-DA or CRA. TrustnGo can carry out such a self-assessment on your behalf.

  • Reduced Costs & Delays

    Notified bodies are often overwhelmed with demand, driving up fees and lead times. As an independent evaluator, TrustnGo helps you get assessed faster and at a lower cost.

  • A Skilled Evaluator

    With a ten-year experience in cybersecurity assessment at the highest assurance level, TrustnGo's evaluator can help you in every aspect of your cybersecurity needs.

  • Technical Support to Fix Deviations

    When a deviation is found, TrustnGo can help you fix it through our consulting & development services, so you quickly meet the standard's requirements.