Our applications

    Applications we've built

    iThing's tools help product companies meet the EU Cyber Resilience Act (CRA): Zyber Compliance shows where a product falls short of the CRA and EN 40000, Zyber Risks produces threat models, and Craflow gathers requirements, evidence and audit-ready reports.

    Zyber Compliance

    Gap analysis against the CRA and EN 40000-1-2: answer questions about your product and get a list of missing requirements, the evidence needed and what to fix first.

    Visit application

    Zyber Risks

    AI-assisted threat modelling and risk assessment – for example identifying the attack surfaces of a connected product and documenting the risks the way the CRA requires.

    Visit application

    Craflow

    Compliance workspace that guides product teams through the EU Cyber Resilience Act and the EN 40000-1-2 process — requirements, evidence, tasks and audit-ready reports in one place.

    Visit application

    Frequently asked questions

    What is a CRA gap analysis and how do I do one?
    A gap analysis compares your product and development process today with the requirements of the CRA and the EN 40000 standard. The result is a list of what is missing, for example a risk assessment, an SBOM, a vulnerability handling process or secure default settings, and in which order to fix it. In Zyber Compliance you answer questions about the product and get the list directly.
    What does the CRA require of an SBOM?
    The manufacturer must produce an SBOM (Software Bill of Materials) listing at least the product's top-level dependencies, in a common machine-readable format such as SPDX or CycloneDX. The SBOM is part of the technical documentation and is used to quickly see whether a new vulnerability affects the product. It does not have to be published, but must be available to market surveillance authorities.
    When does the Cyber Resilience Act apply?
    The CRA entered into force on 10 December 2024. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA. From 11 December 2027 all requirements apply, and products with digital elements must meet the CRA to carry the CE mark and be sold in the EU.
    Which tool should I start with?
    Start with Zyber Compliance to see where your product stands against the CRA. Then use Zyber Risks for the risk assessment and Craflow to gather requirements, evidence and reports ahead of an audit.

    Need an application of your own?

    We design and build custom web and cloud applications tailored to your needs.

    Contact us