Hi, I'm David Knichel
I turn your existing architecture, security controls and engineering documentation into a structured Cyber Resilience Act (CRA) evidence package.
What does demonstrating CRA conformity actually require?
- Product architecture
- Cybersecurity risk assessment
- SBOM & component evidence
- Vulnerability & update processes
- Test & conformity evidence
I build the evidence package with you
Product scope & architecture
Define exactly what product is being assessed, including software, hardware, remote processing and third-party services.
Cybersecurity risk assessment
Identify and analyze the threats and risks specific to your product, evaluate their impact and likelihood, and assess how they are mitigated against the CRA essential requirements.
SBOM & component assurance
Generate or review the machine-readable SBOM and document the security assumptions and due diligence for important dependencies.
Vulnerability lifecycle
Document vulnerability intake, triage, remediation, coordinated disclosure, secure updates and CRA reporting.
Verification & conformity file
Organize test evidence, support-period rationale, applicable standards, user security information and the final technical-documentation structure.
A simple, low-overhead process
Get from scattered engineering information to a structured CRA evidence package without turning compliance into a second project for your team.
Share what already exists
Complete a structured intake and provide the relevant product, architecture, security and development documentation. There is no need to prepare a perfect compliance package beforehand.
I assess the product and identify the gaps
I determine what applies to your product, review the evidence you already have and identify what is missing, inconsistent or needs further technical work.
We close the evidence gaps
I create the documentation that can be derived from your existing material and provide concrete, prioritized actions where engineering input, testing or additional evidence is required.
You receive a maintainable CRA evidence package
The final package brings the risk assessment, SBOM and component evidence, lifecycle procedures, requirement mappings and supporting documentation into one structured repository your team can maintain as the product evolves.
- Remote
- Asynchronous by default
- Fixed scope
- Clear deliverables
Your sensitive product information stays protected
NDA before sharing technical information
Use your NDA or mine.
Minimum necessary access
Repository access is preferred where practical, but not required. Only the information needed for the assessment is requested.
Work in your environment when needed
Sensitive documentation and source code can remain in customer-controlled systems.
No unapproved third-party processing
Customer IP is not submitted to external AI or other third-party services without explicit approval.
You keep control of your IP, repositories and sensitive engineering data throughout the engagement.
Who you are working with
Dr.-Ing. in hardware security and applied cryptography
Research background in embedded-system security, hardware security and applied cryptography.
Hands-on product security experience
Experience analysing real systems across hardware, firmware, software, cloud infrastructure and cryptographic protocols.
Technical documentation experience
Used to translating complex security architectures and engineering decisions into precise documentation that others can review.
Independent, specialist delivery
You work directly with the person performing the assessment. No junior-consultant handoffs or large consulting team.
The same three threads run through every role: designing security architecture, meeting regulatory requirements, and writing the documentation that demonstrates both.
Solution Architect · Edgeless Systems
Customer Integration, Solution engineering, Pre-sales, technical documentation, C5 attestation
Freelance security research & technical writing · Independent
Author security white papers, specifications and engineering documentation on confidential AI, 5G security and post-quantum cryptography, for both technical and decision-making audiences.
Enterprise Security Architect · CYMOTIVE Technologies
Systematic, function-based risk analysis of embedded systems for OEMs and Tier 1 suppliers, and the architectural decisions and written rationale that keep products compliant with automotive security regulations.
Dr.-Ing., summa cum laude · Ruhr University Bochum
Formal verification and automated masking of cryptographic hardware: proving security properties of designs and documenting the argument in peer-reviewed publications.
M.Sc. IT-Security / Information Technology · Ruhr University Bochum
Graded 96% (excellent). Embedded-system security, applied cryptography and secure system design — the foundation the later architecture and verification work builds on.
German IT Security Award 2022
Awarded for the verified, automated masking of cryptographic hardware — one of the most highly endowed cybersecurity prizes in the German-speaking world.
deutscher-it-sicherheitspreis.dePeer-reviewed research
Ten peer-reviewed publications at CHES, ACM CCS and Asiacrypt on masking, side-channel analysis and formal verification of cryptographic hardware.
Google ScholarSee exactly what you receive
No generic compliance report. You receive structured, traceable evidence that connects CRA requirements to your actual product.
Requirement-to-evidence mapping
See which CRA requirements apply, how they are addressed, and where the supporting evidence lives.
Cybersecurity risk assessment
A product-specific assessment covering intended purpose, foreseeable use, attack scenarios, mitigations and residual risks.
SBOM & component assurance
A machine-readable SBOM plus documentation of security-relevant dependencies, assumptions and third-party due diligence.
Product & architecture evidence
Clear documentation of the product boundary, interfaces, software and hardware components, remote data processing and external dependencies.
Vulnerability & lifecycle procedures
Documented processes for vulnerability intake, remediation, coordinated disclosure, CRA reporting, security updates and ongoing security review.
Evidence gap register
Anything that cannot yet be demonstrated is made explicit, together with the concrete engineering or documentation action needed to close the gap.
Know the scope, cost and deliverables upfront
No hourly consulting project. Each engagement starts with a defined product, defined deliverables and a fixed scope.
CRA Scope Assessment
Start hereFor teams that first need certainty about what the CRA means for their product.
- CRA scope and product-boundary assessment
- Product classification and core-function analysis
- Remote data processing assessment
- Applicable conformity-assessment route
- High-level evidence requirements
- Initial gap assessment
- Recommended next steps
Delivered within 5 business days
Start a Scope AssessmentCRA Evidence Package
For manufacturers preparing the evidence needed to demonstrate CRA conformity for one product or product family.
- Product and architecture documentation
- Cybersecurity risk assessment
- CRA requirements-to-evidence mapping
- SBOM and component assurance
- Third-party dependency assessment
- Vulnerability and update processes
- Support-period justification
- Security verification evidence structure
- Technical documentation
- Prioritized evidence and engineering gaps
Fixed scope and price agreed after the Scope Assessment.
Assess my productWhy “from €2,900”?
Product complexity varies significantly. A single embedded device with a small software stack is fundamentally different from a product family with multiple applications, cloud components and external dependencies. The Scope Assessment establishes the boundary before any larger engagement begins.
Know what the CRA requires for your product
You do not need to commit to a full compliance project to get started.
The CRA Scope Assessment gives you a clear picture of your product boundary, classification, conformity route, evidence requirements and current gaps.
You receive a fixed-scope assessment for €950, delivered remotely and asynchronously.
- Fixed price
- No sales call required
- NDA available
- No ongoing commitment