Embedded Security · Compliance

Your product has to pass. We make sure it does.

We build the firmware security, updates and evidence the EU Cyber Resilience Act requires, so you ship on time without hiring a security team you can’t find.

We build the engineering. The evidence comes from your build, not from a form.

Built against
EU Cyber Resilience ActRED EN 18031UK PSTIIEC 62443ISO 26262 disciplineSPDXCycloneDXYocto · Zephyr builds
The deadline

The deadline is real. The scramble is optional.

CRA reporting obligations begin on 11 September 2026; the main obligations follow on 11 December 2027. PSTI and the RED security rules already apply today. The firmware is the gap most teams close last.

What this means for you
Time until reporting obligations

11 September 2026

·
Days
·
Hrs
·
Min
·
Sec

Actively exploited vulnerabilities must be reported within 24 hours from this date.

Choose your path

One deadline. Three ways to meet it.

Some teams want it done, some want to own it, some want to learn it. The two-minute check points you to yours.

Fastest to compliant
For teams without security firmware skills in-house

We build it for you

A fixed-price assessment of where you stand, then we build what’s missing and hand over an audit-ready technical file.

You get: a fixed-price plan, the engineering done, an audit-ready technical file.
See the service path
Free to start
For firmware teams who want to own it

You build it, with Firmproof

Point Firmproof at the build you already produce: it generates the SBOM, watches your components, and assembles the evidence as you work.

You get: a founding place, your first gap report within days, and founding pricing locked before public launch.
Explore Firmproof
For engineers
For engineers making this their skill

Learn to build it

The Academy teaches the builder’s side of embedded security: the same mechanisms we deliver in real engagements, taught as they’re built.

You get: module-by-module skills, real artifacts, founding-member pricing from the list.
See the Academy
Why Aceman

We build what the auditors check.

Whichever path you take, the same discipline stands behind it.

Built to the standard

The CRA’s essential requirements, implemented rather than approximated, in your codebase rather than a slide deck.

Assessor-aligned evidence

Every deliverable maps to what a notified body or test lab expects to see: the technical file, the traceability, the test reports.

Automotive-grade rigour

The discipline of the industry with the least tolerance for firmware that fails, brought to your connected product.

Insights

Field notes on building compliant firmware.

Short, specific write-ups from the build: answer first, sources cited.

Cyber Resilience Act

What the CRA actually requires of your firmware

The thirteen essential requirements, in plain terms, and what each one means for the code on the device.

Coming soon
SBOM

Generating a CRA-ready SBOM from a Yocto build

A real walkthrough: from build metadata to a machine-readable bill of materials you can actually maintain.

Coming soon
Origin

What automotive functional safety taught me about the CRA

Lessons from safety-critical automotive software, and why connected products are about to learn them.

Coming soon
Browse all field notes

Ship it secure. Skip the scramble.

Two minutes tells you where you stand. The rest becomes a plan.