Insights

Regulatory Insights

What matters — and what is changing — in CRA, automotive (ISO/SAE 21434), OT (IEC 62443), and machinery (EN 50742) regulation. From a self-check to organization-level preparation, published step by step.

CRA · Self-CheckAvailable now

CRA Self-Check

Is your product in scope of the EU Cyber Resilience Act? Check digital elements, EU market placement, and product classification (default · important · critical) in about a minute — with your next steps.

Start the self-check →
CRA · UpdateAvailable now

Manufacturer reporting from 11 Sep 2026 — what to prepare now

Reporting of severe incidents and actively exploited vulnerabilities starts on 11 September 2026. The 24/72-hour deadlines, the ENISA Single Reporting Platform (SRP), and the minimum you should prepare now.

Read the article →
CRA · PracticeNew service · Jul 24

Reporting duty: can you respond within 24 hours, on your own?

Turning the reporting duty into practice hits a wall — the limits of spreadsheets and manual work, 10-year evidence retention, and 24/72-hour clocks that run through nights and weekends. The answer ACE LABS has long been building arrives soon.

Read the article →
CRA · GuideAvailable now

How should our organization prepare?

From building a cybersecurity management system to roles, processes, technical documentation, and vulnerability handling — a step-by-step guide to preparing for the CRA at the organizational level.

Read the article →
Threat Analysis · TARAComing soon

Products need a health check too — threat analysis (TARA)

Just as a health check finds weak spots before they become problems, a product needs to know where its threats are first. Threat analysis (TARA) is that check-up — systematically identifying assets, threats, and attack paths, so you can decide what to protect and how. It is the shared first step required by the CRA, automotive (ISO/SAE 21434), and OT (IEC 62443).

Coming soon