Testing & Conformity BodiesModule B + C / HImportant Class IIAudited: September 2026 (Active SRP Era)

Doyensec CRA Practice

Elite European Offensive Security Engineering & Notified Body Preparation

Executive Conformity Assessment Verdict

The premier offensive security firm in Europe for hardware manufacturers preparing for high-stakes third-party Notified Body audits or demanding enterprise procurement reviews.

High-end European offensive security engineering consultancy providing rigorous technical penetration testing and Notified Body preparation.

Verified Pricing Tier€15,000 – €60,000 / audit
Deployment ModelProfessional Service
Applicable CRA RouteModule B + C / H
Target Product TierImportant Class II
Statutory Audit

Statutory Capability & Article Coverage Matrix

How Doyensec CRA Practice performs against non-negotiable statutory mandates of Regulation (EU) 2024/2847.

Technical Documentation Dossier
Annex VIIPartial / Template Export
EU Declaration of Conformity
Annex VNo
Coordinated Vulnerability Disclosure (CVD)
Article 10 & RFC 9116Workflow Only
24-Hour ENISA Early Warning Dispatch
Article 14 (Active Sept 2026)Runbook / Guidance
Substantial Modification Diff Engine
Article 22Manual Check
Binary Firmware Disassembly & SCA
Annex I Part I (1)(a)Hardware Lab Only
Air-Gapped / Island-Mode Deployment
Data Sovereignty & IP ProtectionBespoke Consulting
Multi-Act Cross-Walk Coverage:CRARED Delegated Act 2022/30NIS2
Technical Architecture

Architectural Fit & Deployment Analysis

Operates in laboratory and white-box engineering environments. Engineers analyze physical PCBs, probe debug ports, dissect custom protocols, and attempt remote exploit chaining against live hardware.

Finds vulnerabilities automated scanners miss: logic flaws in authentication handshakes, insecure bootloader configurations, and memory safety flaws in custom RTOS network drivers.

Consulting does not scale infinitely. When a manufacturer produces 50 distinct hardware SKUs, conducting manual penetration tests on every revision becomes cost-prohibitive.

Verified Key Strengths
Elite technical vulnerability discovery, hardware interface fuzzing (JTAG, UART, SPI), and side-channel testing
Formal threat modeling directly mapped against character-exact Annex I essential requirements
Defensible third-party technical audit reports recognized by European Notified Bodies and enterprise buyers
Hands-on embedded engineering guidance providing exact C/C++ source remediation code
Structural Limitations & Gaps
Manual human engagement model with limited calendar availability and potential booking delays
Point-in-time assessment; does not provide continuous automated cloud monitoring between audits
Higher one-off cost per product compared to self-service software subscriptions
Commercial Model

Pricing, Packaging & Total Cost of Ownership (TCO)

€15,000 – €60,000 / audit
Entry Tier
Firmware Audit: €15,000 (Targeted binary review, vulnerability discovery, remediation report)
Mid / Scale Tier
Full CRA Assessment: €35,000 (Hardware lab testing, Annex I gap audit, threat modeling)
Enterprise Tier
Pre-CAB Bundle: €60,000 (Full Notified Body preparation, Class II technical dossier audit)
Hidden Cost Factors:
  • Remediation re-testing fees if critical vulnerabilities are discovered during audit
TCO Verdict:Project-based professional consulting investment; provides authoritative third-party technical proof.
Statutory Honesty Notice • Article 32 & Article 24

A Doyensec audit report is world-class technical evidence, but Doyensec is not a designated Notified Body and cannot issue official EU-Type Examination certificates.

Recommended Complementary Directory ToolsView All 18 Evaluated Tools
Recommended Pair
Regulus Cyber
Inspect in Directory
Recommended Pair
Cybellum
Inspect in Directory
Recommended Pair
TÜV SÜD CRA Service
Inspect in Directory

This Site Uses No Cookies

Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.