Cyberexpert turns complex requirements into a product-specific plan, so you know what applies, what evidence to prepare and what to do next.
Identify applicable EN 18031 requirements
Get an evidence checklist and AI-assisted drafts
Get expert review when needed
Free to start. Unlimited products. No credit card needed.
CRA reporting is next. Can’t show EN 18031 conformity? You risk losing market access, held shipments, and products pulled from sale. The standards are new and easy to misread. Get them wrong, and the cost shows up late, when it’s hardest to fix.
Not sure where your product stands? Answer a few quick questions and get an instant estimate of your RED and CRA compliance readiness, before you start a full assessment.
Try the Compliance Readiness CalculatorKnow exactly what applies to your product, instead of reading the standard cover to cover.
Reach readiness in a fraction of the time: scope in about an hour rather than waiting on external reviewers.
Spend roughly three to four times less than traditional consultancy, per product.
Generate evidence and justifications with AI, then export them straight into your technical file.
Get a human in the loop when it counts, with expert review and a CCLab testing pathway.
RED cybersecurity readiness for connected device manufacturers
QIMA Cyberexpert Platform helps manufacturers of internet connected devices with radio capability understand and apply EU Radio Equipment Directive (RED) cybersecurity requirements and EN 18031. It turns complex standards into a practical workflow your team can use early, while architecture and design decisions are still flexible.
Clarify what is in scope across device, app, backend, then run a structured threat and risk assessment to identify what you need to protect and evidence you must collect.
Turn EN 18031 into a product-specific, simplified requirements map and evidence check, tailored to your device architecture and compliance scope.
Get expert review of your assessment and documentation, and when needed, follow a testing pathway with CCLab to validate specific security requirements before release.
Why we built it
RED cybersecurity and EN 18031 are new, technical, and easy to misread. Many teams want to comply, but do not have a clear way to translate the standards into product decisions and documentation without expensive, slow external cycles.
Get the regulatory context for your product, then use Cyberexpert to scope what applies and prepare the evidence you need.
For manufacturers of wireless connected products, compliance with EN 18031 is effectively the fastest path to CRA readiness. It already addresses the core cybersecurity principles the CRA will apply across digital products, but in the specific context of products that fall within RED scope.
In practice, EN 18031 provides the technical backbone for CRA compliance well before full enforcement in 2027. The main gap is not in the security fundamentals, but in lifecycle obligations and product categorisation. Even there, vulnerability management, including identification, remediation, and coordinated disclosure, is already largely aligned.
This means manufacturers investing in RED cybersecurity today are already building much of the technical backbone of CRA compliance, including evidence, processes, and technical documentation, for the wireless connected products within their portfolio.
With CRA harmonised standards still under development, EN 18031 remains the most concrete and actionable standard available today for manufacturers of products in RED scope, and the most practical starting point for achieving CRA compliance with minimal rework.
Cyberexpert’s CRA compliance capabilities are already in development, with release expected in 2027.
The same structured approach also supports early CRA preparation by helping teams document product cybersecurity decisions, risks, requirements, and evidence in a more traceable way.
QIMA Cyberexpert Platform is a readiness layer between spreadsheets and external support, like consultants, labs, and notified bodies. When uncertainty remains, expert escalation is available, including expert review and, when needed, a testing pathway via CCLab.
QIMA Cyberexpert Platform helps you prepare for RED cybersecurity requirements with a structured self-assessment workflow and documentation support. It is designed for readiness. Responsibility remains with the manufacturer. Read more
Applicability summary, which EN 18031 standards apply to your product
Answer structured questions about your device, app, and backend. Cyberexpert maps the EN 18031 requirements that apply based on your product profile. About one hour, free.
Run a guided threat and risk assessment. You get a product-specific requirements map and a live risk graph that shows where attention is needed.
Use the AI assistant to draft evidence notes, justifications, and supporting documentation. You get an exportable evidence set for your technical file.
Request expert review from QIMA and CCLab, with an optional testing pathway before release. Conformity responsibility stays with you. Cyberexpert helps you get ready.
Cyberexpert is built for manufacturers that need to design and maintain products that meet European cybersecurity regulations. It gives cross-functional teams a shared workspace to map requirements, collect evidence, and stay on track through releases.
The first CRA reporting obligations apply from September 11, 2026. Manufacturers will need processes to identify, assess, document, and report actively exploited vulnerabilities and severe incidents affecting product security.
Incoming: Cyberexpert helps manufacturers begin that work early by connecting product scoping, risk assessment, evidence, documentation, and vulnerability management in one structured workflow.
Start with scope, upgrade when you need readiness outputs
QIMA Cyberexpert Platform helps connected device manufacturers understand EU Radio Equipment Directive (RED) cybersecurity requirements and EN 18031, then prepare self-assessment and documentation with structure.
Yes. Cyberexpert is operated by QIMA and uses security measures such as encryption for data in transit and at rest, access controls, monitoring, and anti-malware protection. Customer data uploaded to the platform is treated as confidential information, and customers remain the owners of their data.
Initial scoping takes about an hour. You get a product-specific requirements map immediately.
Cyberexpert gets you ready: it maps requirements, structures your self-assessment, and helps you produce evidence. Responsibility for conformity remains with you as the manufacturer. Expert review and the CCLab testing pathway are available when you want assurance before testing.
Yes. The platform enables organizations to rapidly assess the security posture of their IoT devices against the harmonized EU standard EN 18031.
Within approximately one hour, you can generate product-specific requirements that you can use to design or verify your product’s security posture and compliance.
You can submit your assessment to our cybersecurity professionals for review and validation, which can then be used for testing and the official EU Declaration of Conformity (DoC).
We offer a Free Plan for immediate product scoping and risk assessment—perfect for seeing exactly which requirements apply to your device at no cost.
Our Professional Plan is designed for compliance execution. It unlocks the exact security requirements, the AI assistant, expert verification, vulnerability management, and more. License fees are reinvested into the continuous development of the platform, ensuring an ever-stronger solution.
Cyberexpert is live and available now. The platform already supports core RED cybersecurity readiness workflows, including EN 18031 scoping, product risk assessment, requirements mapping, evidence checklists, documentation support, and vulnerability management. The platform continues to evolve, with CRA-specific capabilities planned as part of the roadmap. These include expanded vulnerability management workflows, policy support, reporting readiness, and AI-assisted verification features designed to help manufacturers prepare for upcoming Cyber Resilience Act obligations. Early customers can start with RED cybersecurity readiness today and benefit from launch pricing while helping shape upcoming CRA-focused capabilities.
The platform is developed and supported by a team of seasoned cybersecurity professionals and industry advisors from QIMA and CCLab. Together, they bring extensive expertise in securing embedded devices and ensuring compliance with international standards like EN 18031.
Traditional consultancy is slow and often costs 3–4x more per product. Excel spreadsheets are prone to errors and difficult to update as standards change. Cyberexpert is an automated, specialized platform that stays up-to-date with the latest RED cybersecurity regulations, saving you weeks of manual work and significantly reducing costs.
Scope your product for free in about an hour. Upgrade when you are ready to generate evidence and book expert review.