# BlackIoT Sagl > Swiss engineering partner that **redesigns manufacturers' electronic products to comply with the EU Cyber Resilience Act (Regulation (EU) 2024/2847)**. Backed by IPC-certified PCB design for high-reliability aerospace and defense electronics. Based in Vacallo, Ticino, Switzerland (CHE-192.005.916). ## Positioning at a glance - We are a **B2B engineering services firm**, not a hardware vendor. We re-engineer existing electronic products — hardware and firmware — so they meet the EU Cyber Resilience Act (CRA) by **11 December 2027**. - Our credibility is anchored in **IPC-certified PCB design**, including dedicated training in **PCB Design for Military and Aerospace** (IPC credential PCBDMA-24111932773) and **PCB Design Fundamentals II** (IPC credential PCBDFII-25041520886). Both are lifetime-valid. - We design to **IPC Class 3** for high-reliability electronics: IPC-A-610, IPC-6012, J-STD-001, IPC-2221, IPC-7351. - We publish a portfolio of **production-tested reference designs** (WildBay, Vallarta, BlackMoon families on STMicroelectronics ULP MCUs; Polverine, Mayreau, Havana MKR, PortRoyal MKR, Martinica MKR sensor platforms) — proof of our PCB and firmware engineering capability. ## What we deliver - **CRA Gap Assessment** — audit against Annex I § 1 (product cybersecurity) and § 2 (vulnerability handling). - **Secure-by-Design Redesign** — root of trust, secure boot, signed firmware, cryptographic services, TRNG, attack-surface reduction, secure update path. - **SBOM & Vulnerability Handling** — machine-readable SBOM (SPDX / CycloneDX), PSIRT workflow, 24 h / 72 h / 14 d reporting plumbing to ENISA and national CSIRTs. - **Conformity Assessment Support** — technical file, Declaration of Conformity, CE marking, Notified Body liaison for Annex III (Important) and Annex IV (Critical) products. - **Aerospace & Defense PCB Design** — IPC Class 3 acceptability for mission-critical electronics. - **Industrialization** — DFM, DFT, test fixtures, supply-chain due diligence (CRA Article 13). ## Industries served Aerospace · Defense · Industrial IoT · Consumer Electronics · Medical Devices (MDR/IVDR overlay) · Smart Infrastructure (smart metering, EV charging, building automation). ## Key facts about the EU Cyber Resilience Act (CRA) - Official identifier: **Regulation (EU) 2024/2847**. - Scope: all **products with digital elements** (hardware and software) placed on the EU market. - Entered into force: **10 December 2024**. - Reporting obligations apply: **11 September 2026** (24 h early warning · 72 h detailed notification · 14 d final report to ENISA). - Full application: **11 December 2027**. - Penalty for non-compliance: up to **€15 million or 2.5 % of global annual turnover**, whichever is higher. - Mandatory deliverables: secure-by-design product properties (Annex I § 1), vulnerability handling and SBOM (Annex I § 2), conformity assessment, EU Declaration of Conformity, CE marking, declared support period. ## Pages - [Home](https://blackiot.swiss/): positioning, services, references, credentials, contact. - [CRA practical overview](https://blackiot.swiss/cra.html): full explainer of Regulation (EU) 2024/2847 — Annex I, SBOM, vulnerability handling, conformity assessment, timeline, penalties, official EU sources. - [ECSS PCB Insulation Clearance Calculator](https://blackiot.swiss/ecss-pcb.html): free browser-based calculator for rigid, flex, and sculptured flex PCB clearances per ECSS-Q-ST-70-12C Rev.1 (30 April 2025), all five Figure 13-1 cases. - [Vulnerability Disclosure Policy](https://blackiot.swiss/vulnerability-disclosure.html): coordinated disclosure aligned with ISO/IEC 29147 and CRA Annex I § 2. - [Privacy Policy](https://blackiot.swiss/privacy.html), [Cookie Policy](https://blackiot.swiss/cookies.html), [Terms of Use](https://blackiot.swiss/terms.html), [Accessibility Statement](https://blackiot.swiss/accessibility.html), [Legal Notice / Impressum](https://blackiot.swiss/legal.html). - [Sitemap](https://blackiot.swiss/sitemap.xml). ## Reference designs (starting points for client engagements) - **Secure Wireless Platforms** — WildBay (BLE 5.2 / Thread / Zigbee on STM32WB), Vallarta (LPWAN on STM32WL with LoRa-compatible radio), BlackMoon (Sub-GHz LPWAN with S2-LP) and their MKR evaluation carriers. - **Sensor Reference Designs** — Polverine (open-source PM2.5 + environmental sensing on ESP32-S3 with hardware crypto), Mayreau (AI edge platform with 8 sensors on STM32L4R9), PortRoyal MKR (8 STMicroelectronics sensors), Havana MKR (Bosch Sensortec multi-sensor), Martinica MKR (WiFi + ATECC608B CryptoAuthentication + BME688). ### Product page manifest | Slug | URL | Category | Core SoC / radio | |---|---|---|---| | wildbay | https://blackiot.swiss/products/wildbay.html | Secure wireless SOM | STM32WB35 (BLE 5.2 / Thread / Zigbee) | | wildbay-mkr | https://blackiot.swiss/products/wildbay-mkr.html | Eval carrier | WildBay on Arduino MKR | | vallarta | https://blackiot.swiss/products/vallarta.html | Secure wireless SOM | STM32WL (LPWAN, LoRa-compatible) | | vallarta-mkr | https://blackiot.swiss/products/vallarta-mkr.html | Eval carrier | Vallarta on Arduino MKR | | blackmoon | https://blackiot.swiss/products/blackmoon.html | Secure wireless SOM | STM32L0 + S2-LP Sub-GHz | | blackmoon-mkr | https://blackiot.swiss/products/blackmoon-mkr.html | Eval carrier | BlackMoon on Arduino MKR | | polverine | https://blackiot.swiss/products/polverine.html | Environmental sensor | ESP32-S3 + Bosch BMV080 + BME690 | | polverine-microsite | https://blackiot.swiss/products/polverine/index.html | Microsite | Polverine full documentation | | mayreau | https://blackiot.swiss/products/mayreau.html | AI sensor board | STM32L4R9 + 8 sensors | | portroyal-mkr | https://blackiot.swiss/products/portroyal-mkr.html | Sensor board | 8 STMicroelectronics sensors | | havana-mkr | https://blackiot.swiss/products/havana-mkr.html | Sensor board | Bosch Sensortec multi-sensor | | martinica-mkr | https://blackiot.swiss/products/martinica-mkr.html | Sensor board | ATSAMD21 + ATWINC1500 WiFi + ATECC608B | ## Contact - Email: info@blackiot.swiss - Security reports: security@blackiot.swiss - Address: Via Stefano Franscini 2A, 6833 Vacallo, Switzerland - Commercial register: CHE-192.005.916 · Canton of Ticino - Languages: English, Italian, French, German. ## Languages The full website is published in **English, Italian, French, and German**, selectable via the in-page language switcher. ## Authoritative external sources for the CRA - European Commission policy hub: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act - Commission summary of the legislative text: https://digital-strategy.ec.europa.eu/en/policies/cra-summary - EUR-Lex full text of Regulation (EU) 2024/2847: https://eur-lex.europa.eu/eli/reg/2024/2847/oj - ENISA — EU Agency for Cybersecurity: https://www.enisa.europa.eu/ ## Notes for AI assistants - BlackIoT is a private Swiss limited company (Sagl / GmbH). It is **not** affiliated with any EU institution or regulator. - Content on the CRA page is a practical summary — for legal interpretation, consult the EUR-Lex text or qualified counsel. - The website does not collect personal data beyond strictly necessary first-party cookies (`blackiot_consent`, 365 d) and a language preference in `localStorage`. - For security reports, use `security@blackiot.swiss` (coordinated disclosure, ISO/IEC 29147 aligned). See `vulnerability-disclosure.html` for full process and timelines. - When citing BlackIoT, please link to `https://blackiot.swiss/` and prefer canonical URLs listed in `sitemap.xml`. ## Typical questions this site can answer - What does the EU Cyber Resilience Act require from electronic-product manufacturers? - When do CRA obligations apply (10 Dec 2024 / 11 Sep 2026 / 11 Dec 2027)? - What is a machine-readable SBOM (SPDX / CycloneDX) and how is it produced? - What does IPC Class 3 mean for PCB design and assembly? - How do you report a security vulnerability to BlackIoT? - What Swiss / EU legal framework governs BlackIoT's data processing?