First Article Security

Your first 24-hour report shouldn’t be your first attempt.

If you hold a CE mark for the EU, the Cyber Resilience Act adds a new duty on top of it, and the reporting part starts first. We build it into the quality system you already certify against, and run each case through the corrective action process your team already knows.

Reporting starts 11 Sep 2026
 
What it covers
Products already in the field. No grandfathering (Art. 69(3))
How we do it
Inside your ISO 9001 system, as a corrective action
24 h early warning · 72 h notification · 14 d final report
No grandfathering for reporting. Art. 69(3)
Notified bodies designated today: zero
CE marking under the CRA: Dec 2027. Reporting comes first

Verified 24 Jul 2026. Regulations change; we re-verify before every engagement.

01

The offers: fixed prices, decision dates tied to 11 Sep

Tier 0 · Free

Article 14 exposure check

$0 · 20 min

Twenty minutes on your product line and what you ship into the EU. You get a one-page memo within 48 hours telling you where you stand. We do not pitch you on the call.

Tier 2 · 2 weeks

PSIRT-in-QMS Sprint

$14k to $18k

The whole thing built into your QMS: charter, intake, triage, disclosure policy, advisory templates, and the evidence pack an auditor will ask for. Mapped to IEC 62443-4-1 Practices 6 and 7.

After a sprint, most clients keep the process running on a part-time retainer. That conversation happens inside the sprint, not before.

02

An Article 14 report, run as a corrective action

One process, two audiences
Shown as an 8D because that is the corrective action method most quality departments already use. If yours runs 5-why, DMAIC, or your own CAPA form, the clocks and the evidence land the same way. Clause references point to our process map. They are not reproductions of the standard.
8D step (corrective action) CRA obligation Clock 62443-4-1 What gets produced
D0 Plan & intake You learn a vulnerability is being exploited. The reporting duty starts (Art. 14(1)) 24 h P6 · DM-1 Intake record; early-warning submission to the SRP; clock log opened
D1 Team A named reporter and deputy who can act inside the window standing P6 · DM-1 RACI, on-call rota, escalation path
D2 Describe Vulnerability notification: nature, severity, affected products (Art. 14(2)(b)) 72 h P6 · DM-2/3 Characterized defect: what, where, since when, exploitation status
D3 Contain Interim measures users can apply now; users informed ASAP P6 · DM-4 Mitigation advisory: workaround, configuration change, or restriction
D4 Root cause Why it got in, and why nothing caught it n/a P6 · DM-3 Systemic root-cause record, twice over
D5 Corrective action A security update that addresses the verified cause n/a P7 · SUM The fix, qualified for the fielded fleet
D6 Validate Evidence the fix closes the path it claims to close n/a P7 · SUM Regression run plus targeted re-test of the patched path
D7 Prevent recurrence The process fix behind the product fix n/a P6 · DM-5/6 Updated coding standard, new CI detection, amended threat model
D8 Close & recognize Final report: description, severity, measures taken (Art. 14(2)(c)) 14 d P6 · DM-5 Final report filed; reporter credited; the 8D record archived as audit evidence
03

Straight answers

We already hold a CE mark. Doesn’t that cover us?

Not for this. The CRA brings its own CE requirement in Dec 2027, but the reporting duty lands more than a year earlier, on 11 Sep 2026. That one has no grandfathering.

We’re ISO 9001 certified. Where does this actually live?

In the corrective action process you already have. Article 14 gives you a new trigger and three deadlines. The containment, root cause, and verification work is the same work your team does on any customer complaint. We are not asking you to stand up a second system beside your QMS.

Are you a notified body?

No. We are advisory only. You stay the manufacturer of record. We get you ready for whoever assesses you.

We’re a component supplier. Isn’t our customer the manufacturer?

If you put it on the EU market under your own brand, you are the manufacturer for that product. And your customers will push the requirement down to you either way.

Our products shipped years ago.

Product requirements are grandfathered to Dec 2027. Article 14 is not (Art. 69(3)).

Why fixed prices?

Because scoping surprises are a process failure.

04

Who runs this

Portrait: Matthew Macri
Principal

Matthew Macri built a CRA and IEC 62443 programme inside a BC industrial manufacturer, from nothing to a signed charter: intake, triage, disclosure, and the evidence trail behind them. He runs the process he sells. Currently completing ISA/IEC 62443 certification. Based in British Columbia, works in client time zones.

Book the 20-minute exposure check

Twenty minutes, a straight read on where you stand, and a one-page memo within 48 hours. We do not pitch you on the call.

Booking

Prefer email. matt@firstarticle.ca. Include your product line and where it ships; you’ll get times within one business day.

Email instead