Entry offer
Readiness Review
The document you hand to the customer who asked.
£9,500
+ VAT · fixed scope
· 10 working days
Ten working days inside your firmware, build system and update path — run by an engineer who has shipped firmware, not a consultant working from a checklist.
Most people book this because somebody has asked them for something: a customer wanting a CRA attestation, an acquirer wanting a threat model, a notified body wanting documented posture. The deliverable is written to be handed over — risks named in plain language, gaps mapped to the CRA and PSTI clauses they trip, fixes ordered by what that reader will weigh most. It closes with a 60-minute readout for the people who own the budget.
What you get
- 13–16 page technical report
- Gap analysis against CRA, PSTI and RED EN 18031
- Prioritised remediation plan with owners
- 60-minute exec readout
Worth booking if
- A customer wants a CRA attestation or a dated roadmap, and a maybe will not do.
- Your product has a radio, which means the RED cybersecurity requirements (EN 18031) already apply to it.
- A customer security questionnaire just landed and it has more than a hundred questions.
- An acquirer or notified body is asking for documented security posture.
- You have inherited firmware nobody fully owns and need an honest baseline.
How it works
-
Scoping call
Twenty minutes to confirm fit, agree access, and fix the start date. Fixed price, fixed scope.
-
NDA, then access
I sign your NDA before any code or schematic access — standard turnaround is one business day.
-
The investigation
Days 1–8: build system, boot chain, update path, secrets handling, compliance artifacts. Two structured interview slots with your engineers. Draft report on day 8.
-
The readout
Day 10: final report handed over, 60-minute readout with engineering and leadership together.
Asked before booking
-
Do you sign an NDA before the Review?
Yes. I sign your NDA before any code, schematic, or repository access. Standard turnaround is one business day.
-
What do you need from us?
Repository access or firmware images, a build walkthrough, and two interview slots with the engineers who know the product. The kickoff checklist spells it out — nothing exotic.
-
What hardware classes do you cover?
Connected consumer devices, industrial gateways, and medical-adjacent IoT. C, C++, Rust, and embedded Linux; ARM Cortex-M, Cortex-A, and RISC-V targets.
Book the scoping call
Twenty minutes, no preparation needed. If the Snapshot came first, its fee is credited here — and the Review fee is itself credited against your next engagement (how credits apply is set out in the Terms).
Field notes
Join the list
One field — your work email. One email every two weeks.