Our Products
The compliance operating system - manage execution, documentation, and certification entirely online.
Request a demoCRA compliance requirements vary by product class, business model, and route to market. No two conformity journeys look alike. Whether you require a gap assessment, an AI-powered SAAS platform to manage your SBOM and vulnerability obligations, an EU Authorised Representative, or a Conformity Assessment Body to certify your Class I or Class II product, or ITSEF technical security evaluation for critical ICT products, MVC has a dedicated service for every stage of the CRA lifecycle.
If you are unsure where to start, our CRA experts will map your unique roadmap to compliance for the EU market.
Regulatory timeline
Understanding when obligations take effect is critical for product planning.
CRA entry into force
The Cyber Resilience Act officially entered into force. A 36-month transition period began for manufacturers to adapt to the new requirements.
CAB notifications begin
Member States must begin notifying the European Commission of Conformity Assessment Bodies authorised to conduct third-party assessments under the CRA. This establishes the auditing infrastructure.
Reporting obligations active
Manufacturers must begin reporting actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs within 24 hours of discovery. This is a critical milestone requiring operational readiness.
PLD transposition deadline
Member States must transpose the new Product Liability Directive into national law. Strict liability for defective software, including data loss caused by security vulnerabilities, becomes enforceable for products placed on the market from this date.
CRA full application
The transition period ends. All products with digital elements placed on the EU market must fully comply with Annex I cybersecurity requirements, possess complete technical documentation, and bear the CE marking.
The compliance operating system
Stop managing compliance in spreadsheets. MVC provides the centralised platform manufacturers need to manage technical documentation and declarations of conformity.
Smart documentation
Our document management integrates vulnerability disclosure records, software bill of materials, risk assessments, and conformity documentation in one place.
Digital product passport
Each passport links to your technical documentation, update history, and support contact information.
API integration
Our API supports webhooks for regulatory deadline alerts and document expiration notifications.
Product categories
The CRA distinguishes between default products, important products (Class I and Class II), and critical products. Each category carries different conformity assessment requirements.
Default products
Self-assessment is permitted. MVC guides you through the process and generates the required documentation.
Important products (Class I)
Harmonised standards or third-party assessment required. Our platform tracks relevant standards and connects you with notified bodies when needed.
Important products (Class II)
Mandatory third-party assessment. MVC prepares your documentation package and facilitates CAB engagement.
Critical products
Certification by an accredited CAB required. Our CAB subsidiary handles the full assessment process.
Learn about our CABGet started
Contact us for a product classification consultation, or sign up to explore the platform.