Entry offer

Readiness Review

The document you hand to the customer who asked.

£9,500

+ VAT · fixed scope

· 10 working days

Ten working days inside your firmware, build system and update path — run by an engineer who has shipped firmware, not a consultant working from a checklist.

Most people book this because somebody has asked them for something: a customer wanting a CRA attestation, an acquirer wanting a threat model, a notified body wanting documented posture. The deliverable is written to be handed over — risks named in plain language, gaps mapped to the CRA and PSTI clauses they trip, fixes ordered by what that reader will weigh most. It closes with a 60-minute readout for the people who own the budget.

What you get

  • 13–16 page technical report
  • Gap analysis against CRA, PSTI and RED EN 18031
  • Prioritised remediation plan with owners
  • 60-minute exec readout

Worth booking if

  • A customer wants a CRA attestation or a dated roadmap, and a maybe will not do.
  • Your product has a radio, which means the RED cybersecurity requirements (EN 18031) already apply to it.
  • A customer security questionnaire just landed and it has more than a hundred questions.
  • An acquirer or notified body is asking for documented security posture.
  • You have inherited firmware nobody fully owns and need an honest baseline.

How it works

  1. Scoping call

    Twenty minutes to confirm fit, agree access, and fix the start date. Fixed price, fixed scope.

  2. NDA, then access

    I sign your NDA before any code or schematic access — standard turnaround is one business day.

  3. The investigation

    Days 1–8: build system, boot chain, update path, secrets handling, compliance artifacts. Two structured interview slots with your engineers. Draft report on day 8.

  4. The readout

    Day 10: final report handed over, 60-minute readout with engineering and leadership together.

Asked before booking

  • Do you sign an NDA before the Review?

    Yes. I sign your NDA before any code, schematic, or repository access. Standard turnaround is one business day.

  • What do you need from us?

    Repository access or firmware images, a build walkthrough, and two interview slots with the engineers who know the product. The kickoff checklist spells it out — nothing exotic.

  • What hardware classes do you cover?

    Connected consumer devices, industrial gateways, and medical-adjacent IoT. C, C++, Rust, and embedded Linux; ARM Cortex-M, Cortex-A, and RISC-V targets.

Book the scoping call

Twenty minutes, no preparation needed. If the Snapshot came first, its fee is credited here — and the Review fee is itself credited against your next engagement (how credits apply is set out in the Terms).

Field notes

Join the list

One field — your work email. One email every two weeks.

We’ll email you one confirmation link — click it and you’re on the list. Unsubscribe any time, in every issue. Handled per the privacy notice.