From regulation to running process.
Three practice areas, one integrated methodology. Every engagement is scoped to your product and your team — delivered on-site in the Munich area or remotely, in English or German.
EU Cyber Resilience Act
The CRA introduces binding cybersecurity requirements for virtually every product with digital elements sold in the EU — hardware and software, whether or not your company is based in Europe. Most manufacturers underestimate both the documentation burden and how soon the first deadlines arrive.
Applicability & classification
Find out what the regulation actually requires of your product — before you invest in the wrong things.
- Product portfolio screening: what's in scope, what isn't
- Risk-class determination (default, important, critical)
- Conformity route: self-assessment vs. notified body
- Role clarification: manufacturer, importer, distributor
Gap analysis to conformity
A prioritized path from where you are to a defensible technical file.
- Gap analysis against the essential requirements
- Vulnerability handling & Article 14 reporting process
- SBOM and secure-development practices
- Technical documentation & CE-marking preparation
- Workshops and team training
Functional Safety
Safety lifecycle support for electrical, electronic, and programmable systems — from the base standard to the automotive derivatives, and into the territory classical standards don't cover.
Industrial functional safety
The base standard for safety-related E/E/PE systems in industrial applications.
- Safety lifecycle planning and management
- Hazard and risk analysis, SIL determination
- Safety requirements specification
- Assessment and audit preparation
Automotive functional safety
Road-vehicle functional safety across the full V-model, for OEMs and suppliers.
- Item definition, HARA, and ASIL determination
- Functional and technical safety concepts
- Safety case construction and review
- Confirmation measures and assessment support
Safety of the intended functionality
For functions whose risk comes from performance limitations rather than faults — perception, driver assistance, automated driving.
- SOTIF analysis and scenario identification
- Triggering-condition and misuse analysis
- Validation strategy for known/unknown scenarios
Safety management & training
Making the safety process work as an organization, not just as documents.
- Safety process setup and tailoring
- Gap analysis of existing safety work products
- Role-specific training for engineers and managers
Product Cybersecurity
Cybersecurity engineering that connects to your safety work instead of running parallel to it — threat analyses that share assumptions with your hazard analyses, and one change process that evaluates both.
Automotive cybersecurity engineering
The cybersecurity counterpart to ISO 26262 — required in practice for anyone supplying into vehicles.
- TARA — threat analysis and risk assessment
- Cybersecurity concepts and requirements
- Cybersecurity case and work-product reviews
- Supplier cybersecurity capability evaluation
Cybersecurity management
The organizational side: a management system that satisfies type approval and survives audits.
- CSMS setup and gap analysis
- Incident and vulnerability management processes
- Alignment with CRA obligations to avoid duplicate work
Integration of both disciplines
The interface where projects most often stall — and where I do my most distinctive work.
- One system description, one set of assumptions
- Cross-referenced hazard and threat analyses
- Combined safety–security change management
- Mapping safety work products onto CRA documentation
Workshops & enablement
Practical, role-specific training so your team carries the process forward without external help.
- CRA fundamentals for engineering teams
- TARA and HARA methodology workshops
- Management briefings: obligations, risks, timelines
Not sure which of these you need?
That's normal — the regulations overlap and the standards cross-reference each other. Describe your product and your situation, and I'll tell you honestly what applies and what doesn't.