CRA partner directory
Independent consultancies, product-security tooling vendors, legal advisors, and resellers who help manufacturers meet their EU Cyber Resilience Act obligations. Filter by type and country.
Looking for a notified body?
Conformity-assessment bodies and cybersecurity testing laboratories are listed separately. If you need a third-party conformity assessment under CRA Article 32, start with the notified bodies directory.
Browse notified bodies and testing labs →Listings are informational, not endorsements
As of 2026-07-24, the organisations below were curated independently from public sources. Inclusion implies no endorsement, partnership, or commercial relationship with CVD Portal unless an entry is marked as a programme partner. Verify each firm's current services and independence directly before engaging them.
Showing 13 of 13 organisations.
cetome
United Kingdom
Serves EU-wide, United Kingdom, France
Independent security consultancy with offices in London and Lyon focused on IoT and product cybersecurity regulation. Runs CRA Basics, a Cyber Resilience Act awareness initiative, and advises manufacturers on CRA compliance.
Languages: English, French
Visit website →SEC Consult
Austria
Serves EU-wide, Austria, Germany, Switzerland
Vienna-headquartered cybersecurity consultancy founded in 2002, active across the DACH region and Europe. Offers a CRA readiness assessment plus product security analysis and CVD support for manufacturers.
Languages: German, English
Visit website →UNITY Consulting & Innovation
Germany
Serves EU-wide, Germany
German management consultancy with a governance, risk and compliance practice that includes dedicated Cyber Resilience Act consulting for manufacturers.
Languages: German, English
Visit website →admeritia
Germany
Serves Germany, EU-wide
German OT security consultancy whose services include producing CRA technical documentation and user information for product manufacturers. Its CTO serves in the EU Commission CRA Expert Group and in ISA/IEC 62443 standardisation roles.
Languages: German, English
Visit website →Bird & Bird
United Kingdom
Serves EU-wide, United Kingdom
International law firm with offices across most EU member states and a dedicated Cyber Resilience Act practice within its EU cybersecurity regulatory offering. Publishes guides and runs client webinars on CRA obligations.
Taylor Wessing
United Kingdom
Serves EU-wide, United Kingdom, Germany
International law firm with a large German and pan-European presence. Maintains Cyber Resilience Act coverage in its digital regulation hub and advises manufacturers, importers and distributors on CRA obligations.
Languages: English, German
Visit website →Osborne Clarke
United Kingdom
Serves EU-wide, United Kingdom
International law firm with offices across Europe that publishes Cyber Resilience Act guidance and runs CRA webinars, including sessions on product portfolio assessment and standardisation practice.
Languages: English, German
Visit website →Noerr
Germany
Serves Germany, EU-wide
German commercial law firm headquartered in Munich that publishes Cyber Resilience Act analysis and hosts webinars on the CRA impact on industry and contract practice as part of its cybersecurity regulatory work.
Languages: German, English
Visit website →ONEKEY
Germany
Serves EU-wide
Duesseldorf-based product cybersecurity and compliance platform that analyses device firmware, generates SBOMs and includes automated compliance checks against the EU Cyber Resilience Act, IEC 62443-4-2 and ETSI EN 303 645. Also offers a CRA Fast Start programme for manufacturers.
Languages: English, German
Visit website →Cybellum
Israel
Serves EU-wide, Global
Product security platform vendor whose compliance module automates the creation of evidence for regulations including the EU Cyber Resilience Act, importing SBOM and assessment data to generate regulator-ready reports. Non-EU headquarters with an active European market presence.
Finite State
United States
Serves EU-wide, Global
US software supply chain security vendor with a dedicated EU Cyber Resilience Act compliance offering covering SBOM and technical documentation requirements. Expanded into the EMEA region citing demand driven by the CRA, NIS2 and RED.
sbomify
United Kingdom
Serves EU-wide, Global
SBOM management platform registered in Bristol, UK, with a dedicated page on EU Cyber Resilience Act SBOM requirements. Provides SBOM generation, versioned archiving and stakeholder sharing aimed at CRA technical documentation obligations.
Devoteam
France
Serves EU-wide
Pan-European technology consulting and services group headquartered in France. Offers a CRA readiness assessment that identifies a company legal role under the regulation, product scope and compliance workload, and supports SMEs applying for EU funding for CRA work.
Partner directory questions
What is the CRA partner directory?
A curated list of independent organizations that help manufacturers prepare for the EU Cyber Resilience Act. It covers advisory consultancies, product-security and SBOM tooling vendors, regulatory legal practices, and resellers.
Are the listed organizations endorsed by CVD Portal?
No. Listings are informational and independently curated from public sources. Inclusion implies no endorsement, partnership, or commercial relationship. Only entries marked "Programme partner" have joined the CVD Portal partner programme. Always verify a firm's services and independence directly before engaging them.
Where do I find notified bodies and testing labs?
Conformity-assessment bodies and cybersecurity testing labs are listed separately in the notified bodies directory, not here. Use that directory when you need a third-party conformity assessment under CRA Article 32.
How does my organization get listed?
Join the CVD Portal partner programme. Programme partners are marked with a badge in this directory.
Want to be listed here?
Join the CVD Portal partner programme to appear in this directory as a programme partner.
Join the partner programme