40+ Years of cybersecurity evaluation
50+ Accreditation schemes
Global laboratory network
Part of the SGS Group
40+ Years of cybersecurity evaluation
50+ Accreditation schemes
Global laboratory network
Part of the SGS Group
REGULATORY OVERVIEW
What is the Cyber Resilience Act?
Key facts
Applies to products incorporating third-party components, including open-source software.
REGULATORY OVERVIEW
What is the Cyber Resilience Act?
Key facts
Applies to products incorporating third-party components, including open-source software.
CONFORMITY PATHWAYS
CRA conformity assessment routes
Module A - self-assessment
Self-assessment performed by the manufacturer to demonstrate compliance with the CRA essential cybersecurity requirements, based on technical documentation and internal verification.
Module B + C - third-party assessment
Conformity assessment involving a Notified Body, combining EU-type examination (Module B) and conformity to type based on internal production control (Module C).
Module H - full quality assurance
CRA READINESS FLOW
The CRA compliance journey
Understand CRA
Determine product category & conformity assessment route
Leverage existing certifications
Assess readiness
Review processes
Prepare for conformity assessment
START PREPARING
Preparing for the CRA today
Where to start
START PREPARING
Preparing for the CRA today
Where to start
Perform cybersecurity risk assessments
OUR APPROACH
How Brightsight supports CRA
Active role in industry and CRA standardization working groups
Future CRA Notified Body capabilities
Leverage of existing schemes
Consistency and predictable evaluation approach
CRA SERVICES
Services supporting CRA preparation
CRA workshops
CRA introduction
Client use case
Module H application
CRA preparation services
CRA product classification analysis
CRA requirements alignment review
Vulnerability handling process assessment
Module H quality system assessment
Evidence mapping analysis
CRA compliance services
Module B - classic product evaluation
- security testing,
- conformity assessment,
- guidance and documentation,
- essential requirements.
Module H - full quality assurance
- secure development lifecycle,
- vulnerability management,
- update management,
- supply chain security,
- testing process,
- post-market monitoring
OUR ROADMAP
Brightsight's journey towards becoming a CRA Notified Body
Brightsight is progressing through the accreditation process required to operate as a CRA Notified Body for Module B and Module H. The roadmap below reflects current and upcoming activities.
This accreditation will enable Brightsight to support manufacturers in meeting CRA conformity assessment requirements as the regulation becomes fully applicable.
CURRENT STATUS
Accreditation in progress
Brightsight is progressing through the accreditation process required to operate as a CRA Notified Body for Module B and Module H.
NEXT MILESTONE
Accreditation granted
FINAL MILESTONE
CRA Notified Body designation
CAPABILITIES AND EXPERTISE
Why Brightsight
Part of the SGS Group
40+ Years of evaluation experience
50+ Accreditation schemes
Recognitions and accreditations across more than 50 cybersecurity schemes, including EUCC, Common Criteria, SESIP, EMVCo, PSA Certified, and IEC 62443.
Global laboratory network
Active participation in CRA working groups
Independent lab and certification services
ANSWERS


