CRA ARTICLE 14 · FROM 11 SEPTEMBER 2026

Twenty-four hours to report.

And it applies to what you already ship.

“Compliance consultants read the regulation. I read your firmware.”

Public sample · Severity matrix

Findings — Matter bridge-app @ c1392d5

High Attestation uses test credentials and a test VID
High Commissioning uses the published test passcode
High No device-anchored update signature check
Med Secure boot and anti-rollback off by default
Med No SBOM emitted for the built binary

Firmware shipped at

  • Samsung
  • Roku
  • Amazon Ring
  • Schneider Electric

How the deadline reaches you

Three ways this lands on your desk

  • A customer sends 180 questions on OTA and SBOM, wants a CRA attestation or a dated roadmap, and gives you ten working days.

    The OEM supplier demand

  • From 11 September you have 24 hours to report an actively exploited vulnerability — on every product you already have on the market, not just the next one.

    CRA Article 14

  • RED cybersecurity has been enforceable since August 2025 and PSTI since April 2024. Neither is a future problem.

    Already in force

Where to start

Start small. Judge the work first.

Three productised ways in, each priced and scoped up front (all prices exclude VAT). Small enough to expense, useful enough to stand alone — a second engineer’s eyes on your firmware, risks surfaced before a buyer or regulator finds them.

Sample report

Free

no email required

Published — read it now

A complete firmware readiness review in the exact format a paid engagement delivers, applied to a public open-source subject — the Matter bridge reference application. Nothing is redacted; every finding can be checked against public source, line by line.

  • The complete report — findings, remediation roadmap, evidence annexes
  • Real findings with severity and fix priorities
  • The exact structure a buyer or auditor sees
  • Every claim checkable against public source at a pinned commit
  • Published openly — no form, no email, no drip sequence

Readiness Snapshot

£950

+ VAT · one-off · paid online

Delivered within 5 working days

No code access, no NDA, no scoping call. I test whether you could detect, triage and report an actively exploited vulnerability inside Article 14’s 24 hours — from public information plus whatever artefacts you care to send. Bought online, delivered within five working days.

  • A verdict on the 24-hour clock: detect, triage, report — or not
  • Named gaps in detection, triage and escalation
  • A one-page who-does-what-when-a-report-lands
  • Known-CVE exposure across your public stack
  • Gaps ranked, with a 30-minute readout
  • Fee credited toward a Readiness Review

Readiness Review

£9,500

+ VAT · fixed scope

10 working days

Ten working days inside your firmware, build system and update path. Out the other side: a 13–16 page report that names the risks, assigns the owners, and orders the fixes.

  • 13–16 page technical report
  • Gap analysis against CRA, PSTI and RED EN 18031
  • Prioritised remediation plan with owners
  • 60-minute exec readout

Where it leads

When the evidence has to stay true

A review finds the gaps once. Article 14 then asks a harder question — who is watching on the day something lands — and that is ongoing work, not a document. Deeper project engagements sit behind this too: collecting the evidence your claims rest on, and assembling the technical file itself. Both follow a review, are scoped to your product, and are quoted in writing. Ask, and I will walk you through them.

Evidence Retainer

From £3,200

+ VAT · per month · 6-month minimum

Ongoing · 6-month minimum

Article 14 gives you 24 hours to report, and you cannot report what you cannot detect. The Retainer is continuous cover: a named engineer who already knows your product, monitoring the components you ship, triaging what lands, and keeping the evidence current as firmware moves.

  • Component monitoring against advisories, so a report is detectable
  • Vulnerability triage and the Article 14 24/72/14-day reporting path
  • Release-tied technical-file updates
  • Quarterly review with a written readout
  • Customer security-questionnaire support

Sample report · no email required

See what an auditor opens.

A complete readiness review, applied in public to the Matter bridge reference application at a pinned commit — every finding checkable against source, line by line. No form, no email, no drip sequence. Read it, or hand it straight to your firmware lead.

What is in it

  • Nine findings with severity, regulation mapping and remediation
  • The evidence standard: Demonstrated versus Declared, applied throughout
  • An SBOM gap sized against 78 pinned components and an OSV screen
  • The exec summary a budget-holder reads, and the annexes an engineer checks

About

A firmware engineer, not a compliance consultant.

I spent more than a decade shipping firmware at Samsung, Roku, Amazon Ring and Schneider Electric. I have signed production images, reviewed bootloaders, and answered for the evidence in certification audits and customer security reviews.

TallTree® exists because most CRA work is being done by people who have never written a line of embedded code. The result is paperwork that does not survive contact with the device.

You work with me directly. One engineer who can read your build system and your threat model — and explain both to your buyer's legal team.

Word of colleagues

What engineers I’ve shipped with say

From LinkedIn — managers and peers at Samsung, Roku and Schneider Electric, speaking about employment, not client engagements (those stay confidential by default).

“Behzad has a knack for diving deep to address the root of a problem, not just the symptoms… sometimes opting for a quick fix to keep things moving, and other times engineering a more thorough solution when time allows.”
Rafal Zwierz — Director of Software, managed Behzad at Roku
“Involved in all aspects of the project — design and refinement of the architecture, development, problem analysis… he continues to analyse and optimize, improving quality and making the solution more future-proof.”
Lars Pedersen — Head of Software Infrastructure, worked with Behzad at Samsung
“Consistently takes ownership of his work, approaches challenges independently, and delivers reliable results. He listens attentively before offering thoughtful input.”
James Slater — Principal Firmware Engineer, worked with Behzad at Schneider Electric

11 September won’t move. Your evidence can.

Twenty minutes tells you exactly where you stand — no preparation, no pitch. Or read the sample report first and judge the work before you speak to anyone.