Hi, I'm David Knichel

I hold a PhD (Dr.-Ing.) in Hardware Security and applied Cryptography, and I build the evidence you need to demonstrate Cyber Resilience Act conformity.
DK

I turn your existing architecture, security controls and engineering documentation into a structured Cyber Resilience Act (CRA) evidence package.

What does demonstrating CRA conformity actually require?

Your product
  • Product architecture
  • Cybersecurity risk assessment
  • SBOM & component evidence
  • Vulnerability & update processes
  • Test & conformity evidence
CRA technical documentation

I build the evidence package with you

  • Product scope & architecture

    Define exactly what product is being assessed, including software, hardware, remote processing and third-party services.

  • Cybersecurity risk assessment

    Identify and analyze the threats and risks specific to your product, evaluate their impact and likelihood, and assess how they are mitigated against the CRA essential requirements.

  • SBOM & component assurance

    Generate or review the machine-readable SBOM and document the security assumptions and due diligence for important dependencies.

  • Vulnerability lifecycle

    Document vulnerability intake, triage, remediation, coordinated disclosure, secure updates and CRA reporting.

  • Verification & conformity file

    Organize test evidence, support-period rationale, applicable standards, user security information and the final technical-documentation structure.

A simple, low-overhead process

Get from scattered engineering information to a structured CRA evidence package without turning compliance into a second project for your team.

1

Share what already exists

Complete a structured intake and provide the relevant product, architecture, security and development documentation. There is no need to prepare a perfect compliance package beforehand.

2

I assess the product and identify the gaps

I determine what applies to your product, review the evidence you already have and identify what is missing, inconsistent or needs further technical work.

3

We close the evidence gaps

I create the documentation that can be derived from your existing material and provide concrete, prioritized actions where engineering input, testing or additional evidence is required.

4

You receive a maintainable CRA evidence package

The final package brings the risk assessment, SBOM and component evidence, lifecycle procedures, requirement mappings and supporting documentation into one structured repository your team can maintain as the product evolves.

  • Remote
  • Asynchronous by default
  • Fixed scope
  • Clear deliverables

Your sensitive product information stays protected

  • NDA before sharing technical information

    Use your NDA or mine.

  • Minimum necessary access

    Repository access is preferred where practical, but not required. Only the information needed for the assessment is requested.

  • Work in your environment when needed

    Sensitive documentation and source code can remain in customer-controlled systems.

  • No unapproved third-party processing

    Customer IP is not submitted to external AI or other third-party services without explicit approval.

You keep control of your IP, repositories and sensitive engineering data throughout the engagement.

Who you are working with

  • Dr.-Ing. in hardware security and applied cryptography

    Research background in embedded-system security, hardware security and applied cryptography.

  • Hands-on product security experience

    Experience analysing real systems across hardware, firmware, software, cloud infrastructure and cryptographic protocols.

  • Technical documentation experience

    Used to translating complex security architectures and engineering decisions into precise documentation that others can review.

  • Independent, specialist delivery

    You work directly with the person performing the assessment. No junior-consultant handoffs or large consulting team.

The same three threads run through every role: designing security architecture, meeting regulatory requirements, and writing the documentation that demonstrates both.

  1. Solution Architect · Edgeless Systems

    Customer Integration, Solution engineering, Pre-sales, technical documentation, C5 attestation

  2. Freelance security research & technical writing · Independent

    Author security white papers, specifications and engineering documentation on confidential AI, 5G security and post-quantum cryptography, for both technical and decision-making audiences.

  3. Enterprise Security Architect · CYMOTIVE Technologies

    Systematic, function-based risk analysis of embedded systems for OEMs and Tier 1 suppliers, and the architectural decisions and written rationale that keep products compliant with automotive security regulations.

  4. Dr.-Ing., summa cum laude · Ruhr University Bochum

    Formal verification and automated masking of cryptographic hardware: proving security properties of designs and documenting the argument in peer-reviewed publications.

  5. M.Sc. IT-Security / Information Technology · Ruhr University Bochum

    Graded 96% (excellent). Embedded-system security, applied cryptography and secure system design — the foundation the later architecture and verification work builds on.

DK
Dr.-Ing. David KnichelSecurity & Solution ArchitectEmbedded systems · applied cryptography · Confidential AI · product security
Get in touch

See exactly what you receive

No generic compliance report. You receive structured, traceable evidence that connects CRA requirements to your actual product.

  • Requirement-to-evidence mapping

    See which CRA requirements apply, how they are addressed, and where the supporting evidence lives.

  • Cybersecurity risk assessment

    A product-specific assessment covering intended purpose, foreseeable use, attack scenarios, mitigations and residual risks.

  • SBOM & component assurance

    A machine-readable SBOM plus documentation of security-relevant dependencies, assumptions and third-party due diligence.

  • Product & architecture evidence

    Clear documentation of the product boundary, interfaces, software and hardware components, remote data processing and external dependencies.

  • Vulnerability & lifecycle procedures

    Documented processes for vulnerability intake, remediation, coordinated disclosure, CRA reporting, security updates and ongoing security review.

  • Evidence gap register

    Anything that cannot yet be demonstrated is made explicit, together with the concrete engineering or documentation action needed to close the gap.

Know the scope, cost and deliverables upfront

No hourly consulting project. Each engagement starts with a defined product, defined deliverables and a fixed scope.

CRA Evidence Package

From €2,900

For manufacturers preparing the evidence needed to demonstrate CRA conformity for one product or product family.

Includes:
  • Product and architecture documentation
  • Cybersecurity risk assessment
  • CRA requirements-to-evidence mapping
  • SBOM and component assurance
  • Third-party dependency assessment
  • Vulnerability and update processes
  • Support-period justification
  • Security verification evidence structure
  • Technical documentation
  • Prioritized evidence and engineering gaps

Fixed scope and price agreed after the Scope Assessment.

Assess my product

Why “from €2,900”?

Product complexity varies significantly. A single embedded device with a small software stack is fundamentally different from a product family with multiple applications, cloud components and external dependencies. The Scope Assessment establishes the boundary before any larger engagement begins.

Need only CRA reporting readiness before 11 September 2026?A standalone reporting-readiness package is also available.
Get in Touch

Know what the CRA requires for your product

You do not need to commit to a full compliance project to get started.

The CRA Scope Assessment gives you a clear picture of your product boundary, classification, conformity route, evidence requirements and current gaps.

You receive a fixed-scope assessment for €950, delivered remotely and asynchronously.

Assess my product
  • Fixed price
  • No sales call required
  • NDA available
  • No ongoing commitment