If your product has a chip in it and connects to anything, a new EU law now makes security your legal responsibility. PandaX handles it — we read your product's software, find the vulnerabilities, and produce the paperwork Brussels asks for. Built for people who make devices, not for security engineers.
The Cyber Resilience Act sets out a long list of duties for anyone selling a connected product in Europe. This is that list — and what PandaX takes off your desk for each one.
Upload your software list if you have one, or point us at the firmware and we'll build it for you. No command line, no pipeline setup, no integration project.
PandaX checks every software part against the world's vulnerability databases, every day, and tells you in plain words when something in your product needs attention.
One click produces the technical file, the EU Declaration of Conformity and the CE checklist — the pack you hand to a regulator, a customer or a distributor.
Your product almost certainly falls in scope, and most likely on the self-check route — the lightest one. That still means a software list, ongoing vulnerability monitoring and a technical file.
Almost certainly yes. The law covers any product with digital elements — a lamp with an app, a sensor with Bluetooth, a toy with firmware. Size doesn't exempt you, and neither does simplicity. A handful of categories are carved out because other rules already cover them, such as medical devices, cars and marine equipment. Our 30-second check above will tell you where you stand.
It's simply a list of the software inside your product — the open-source libraries and components your firmware is built from. The law requires you to keep one and to know when something on that list develops a security problem. If you don't have one, PandaX can generate it from your firmware; you don't need to produce it yourself.
For roughly nine out of ten products, no. Most sit in the default category, where you're allowed to assess your own product and declare conformity yourself — provided you can show the evidence. That evidence is exactly what PandaX produces. Certain higher-risk categories, such as firewalls and password managers, do need an outside body, and we'll tell you clearly if that's you.
No. Bring what you have — existing risk assessments, test reports, update policies — and PandaX slots them into the structure the law expects, then shows you only the gaps that are left. Most teams find they're further along than they feared, and that what's missing is the ongoing monitoring rather than the paperwork.
Most customers are live on the same day. Upload a software list or a firmware image, answer three questions about your product, and the dashboard fills in. There's no build-system integration and nothing for your engineers to maintain — which is the whole point.
Two minutes, one product, no card. We'll show you exactly what the Cyber Resilience Act asks of you — and how much of it we can take off your desk.