VARVICO ADVISORY · SAMPLE DELIVERABLESWhat you actually receive
Three excerpts, each from a different engagement type, written exactly as a client would get them. The organisations are invented; the method, the scoring and the article references are the real ones.
Not legal advice. Fictional entities; any resemblance to a real organisation is unintended.
EXCERPT 1 · SCOPE & OBLIGATION SNAPSHOT (CRA)
Scope memo — Veldmark Devices B.V. FICTIONAL
Prepared for: Managing Director · Basis: two calls (4 and 7 October), product data sheet, supply agreement, packaging artwork · Indicative, for review by your counsel
Question asked
Veldmark buys Wi-Fi-connected room thermostats from a manufacturer outside the EU and sells them in the Netherlands and Germany under the manufacturer's brand, with its own name and address added to the packaging. Does the Cyber Resilience Act apply, in what role, and what does that role owe by when?
Answer in one paragraph
Yes. The thermostat is a product with digital elements (Art. 3(1): it has a software component and a direct data connection to a network). Veldmark places it on the EU market under the manufacturer's name, which makes Veldmark the importer (Art. 3(16)), not the manufacturer — as long as the product is not sold under Veldmark's own name or trademark and Veldmark does not substantially modify it (Art. 21). As we read Annex III, a room thermostat is not among the listed important products, so the product falls in the default category and the manufacturer can assess conformity itself under the procedures in Art. 32. That reading should be confirmed by counsel, because classification decides the manufacturer's whole route.
What the importer role owes
- Place on the market only products that meet the essential requirements and for which the manufacturer has done its part (Art. 19(1)–(2)): conformity assessment carried out, technical documentation drawn up, CE marking affixed, manufacturer's identification and contact details present. Veldmark has none of these in writing from the manufacturer today — this is the first request to make.
- Put Veldmark's name, registered trade name or trademark, postal address, an email address or other digital contact and, where applicable, the website on the product, on its packaging or in a document accompanying it (Art. 19(4)). The current packaging artwork carries the name and address only — add the email address and the website before the next print run.
- Before placing a product on the market: if Veldmark has reason to believe it or the manufacturer's processes do not conform, hold it back until they do, and where it presents a significant cybersecurity risk, tell the manufacturer and the market-surveillance authorities (Art. 19(3)). After placing it: on learning of non-conformity, take corrective measures or withdraw or recall; on learning of a vulnerability, inform the manufacturer without undue delay; where there is a significant risk, inform the authorities (Art. 19(5)). Both need an internal rule for who decides and a contact record for the Dutch and German authorities.
- Keep a copy of the EU declaration of conformity at the disposal of the market-surveillance authorities for at least ten years after placing the product on the market or for the support period, whichever is longer, and make the technical documentation available to them on request (Art. 19(6)–(7)). Keep a register of the products placed on the market with batch and firmware version.
- Confirm the manufacturer's support period (Art. 13(8): at least five years unless the product's expected use time is shorter) and that security updates will be available for it; Veldmark's customers will ask Veldmark, not the manufacturer.
Dates that matter
- 11 September 2026 — the manufacturer's reporting duties under Art. 14 already apply. Veldmark is not the reporting party, but should know how the manufacturer reports and how Veldmark will be told, because a reported vulnerability in these thermostats reaches Veldmark's customers first.
- 11 December 2027 — the importer obligations above apply to products placed on the market from that date. Products placed on the market before it fall under the requirements only if they are substantially modified afterwards (Art. 69(2)); the Art. 14 reporting duties apply to them regardless (Art. 69(3)).
Three things to do first
- Write to the manufacturer this month asking for the five items in the first bullet above, with a deadline; the kit's importer checklist is the letter.
- Decide the own-brand question now. If Veldmark ever sells under its own name or trademark, or substantially modifies the product, it is treated as the manufacturer with the full set of obligations (Art. 21); that is a commercial decision with a regulatory price.
- Open a product register (model, batch, firmware, declaration on file) — one spreadsheet, maintained by purchasing.
For your counsel
- Annex III classification of a connected thermostat (default category as read here).
- Which current batches count as placed on the market before 11 December 2027, and what counts as a substantial modification for firmware updates (Art. 69(2)).
- Whether adding Veldmark's logo to the app changes the own-brand analysis under Art. 21.
EXCERPT 2 · READINESS REVIEW (NIS2) — THREE OF FOURTEEN FINDINGS
Gap register — Harrowgate Cold Chain Ltd FICTIONAL
Important entity on the Directive's criteria (medium-sized, food distribution — Annex II) · Three sites, 180 staff, outsourced IT · Directive-level illustration: a real report applies and names the national transposition of the entity's member state · Scoring: 0 absent · 1 partial · 2 largely in place · 3 in place and evidenced · The register covers governance (Art. 20), the ten risk-management measure areas (Art. 21(2)) and reporting (Art. 23). The assessment table is shown in full; three of the fourteen findings follow it — the ones the six-month plan starts with.
Assessment table
| AREA | PROVISION | SCORE | BASIS |
|---|
| Governance | Art. 20 | 1 · partial | Policy approved by the IT manager, not the management body; no training offered (F-01). |
| Policies and risk analysis | Art. 21(2)(a) | 1 · partial | A policy set exists; no risk analysis behind it; not reviewed since 2024. |
| Incident handling | Art. 21(2)(b) | 1 · partial | Provider-run procedure; no internal decision-owner; no severity rule. |
| Business continuity | Art. 21(2)(c) | 1 · partial | Backups nightly and restored in a June test; no continuity or crisis plan, no recovery objectives, no exercise. |
| Supply chain | Art. 21(2)(d) | 1 · partial | Two largest IT suppliers under contract with security terms; the monitoring provider is not (F-07). |
| Acquisition, development, vulnerability handling | Art. 21(2)(e) | 2 · largely in place | Patching within 14 days evidenced; vulnerability disclosure handled by the provider. |
| Assessing effectiveness | Art. 21(2)(f) | 0 · absent | No procedure to check whether the measures work; nothing reported to management. |
| Cyber hygiene and training | Art. 21(2)(g) | 1 · partial | Induction only; no annual training; phishing exercises never run. |
| Cryptography | Art. 21(2)(h) | 2 · largely in place | Laptops encrypted; TLS everywhere external; key handling documented. |
| HR security, access control, assets | Art. 21(2)(i) | 2 · largely in place | Joiner/leaver process evidenced; asset list current for two of three sites. |
| MFA and secured communications | Art. 21(2)(j) | 2 · largely in place | MFA on all remote access and email; voice and video on managed services. |
| Reporting to the authority | Art. 23 | 0 · absent | No owner, no CSIRT channel recorded, provider SLA five business days (F-03). |
F-030 · absent
No path to the authority within the Article 23 clocks
Requirement
NIS2 Art. 23(1) and (4): early warning within 24 hours of becoming aware of a significant incident, incident notification within 72 hours, final report within one month.
What we saw
Incident handling is delegated to the outsourced IT provider under a contract with a five-business-day response SLA. Nobody inside Harrowgate is named as the person who decides whether an incident is 'significant' or who contacts the CSIRT. The CSIRT's contact channel is not recorded anywhere; two interviewees assumed 'IT would know'.
Why it matters
The 24-hour clock starts when Harrowgate becomes aware, not when its provider does. The observed weakness is that nobody inside Harrowgate owns the decision and no channel to the CSIRT is recorded. The consequence we predict is a late or missed early warning, because the only party engaged on incidents is contracted to respond in five business days.
What to do
- Name the incident decision-owner and a deputy (operations director and warehouse systems lead were proposed on the call); write the two-line decision rule into the incident procedure.
- Record the national CSIRT's notification channel and test it once, out of hours, within 30 days.
- Change the provider SLA for suspected significant incidents to a 2-hour acknowledgement; the kit's supply-chain clause schedule carries the wording.
Effort: Two days of internal work; one contract amendment.
Evidence to keep: Signed procedure page; the test record; the amended SLA clause.
F-011 · partial
Management body has not approved the measures or been trained
Requirement
NIS2 Art. 20(1): the management bodies approve the cybersecurity risk-management measures and oversee their implementation, and can be held liable. Art. 20(2): members are required to follow training.
What we saw
The information-security policy is approved by the IT manager. Board minutes for the last four meetings contain no security item. No training has been offered to the board.
Why it matters
Approval by IT does not meet Art. 20(1), and the liability in that article sits with the management body whether or not it has looked at the measures.
What to do
- Put the measure set from the kit on the next board agenda as a decision item, with the gap register attached; minute the approval.
- Run the kit's 90-minute management briefing before that meeting; keep the attendance record.
- Add security as a standing quarterly agenda item, using the one-page management pack.
Effort: Half a day of preparation; one board slot.
Evidence to keep: Board minute; attendance record; the quarterly pack.
F-071 · partial
The cold-chain monitoring provider has write access and no contractual obligations
Requirement
NIS2 Art. 21(2)(d): supply-chain security, including security-related aspects of the relationships with direct suppliers and service providers; Art. 21(3): take into account each provider's specific vulnerabilities and the overall quality of its practices.
What we saw
The temperature-monitoring SaaS has an integration account with write access to the warehouse management system, used to raise automatic holds. The contract is the provider's standard terms: no security requirements, no incident notification duty, no audit or assurance right. No assessment of the provider has been done.
Why it matters
This provider can alter stock status across all three sites. It is the single external party whose failure or compromise most directly affects the service Harrowgate is in scope for.
What to do
- Reduce the integration account to the specific API scope the holds require; the provider confirmed on the call that a scoped key is available.
- Issue the kit's supplier questionnaire and record the result in the supply-chain register.
- At renewal (February 2027), attach the clause schedule: incident notification within 24 hours, assurance report or questionnaire annually, termination assistance.
Effort: One day; renewal negotiation.
Evidence to keep: Access change ticket; completed questionnaire; signed schedule.
EXCERPT 3 · THE ONE-PAGE MANAGEMENT SUMMARY
For the board of Harrowgate Cold Chain Ltd FICTIONAL
Written to be read in five minutes before the meeting that approves the measures (Art. 20(1)).
Where you stand
On the Directive's criteria Harrowgate is an important entity, because of its size and its sector; the national law of your member state settles the categorisation and the registration details, and the full report names it. Of the ten measure areas in Art. 21(2), four are largely in place (secure acquisition and vulnerability handling; cryptography; human-resources security, access control and asset management; multi-factor authentication and secured communications), five are partial (policies and risk analysis; incident handling; business continuity — backups run and were restored in a test, but there is no continuity or crisis plan and no recovery objectives; supply chain; cyber hygiene and training), and one is absent: assessing whether the measures work (Art. 21(2)(f)). Two items sit outside Art. 21 and are scored separately: management approval and training (Art. 20) is partial — the policy exists but was approved by IT, not by the board — and the path to notify the authority within the Art. 23 clocks is absent. Nothing we saw suggests Harrowgate could not meet the measures; what is missing is ownership, not technology.
The three decisions this board is asked to take
- Approve the measure set attached (the kit's policy set, adapted to Harrowgate) and record the approval in the minutes. This is the step Art. 20(1) places on the board, not on IT.
- Name the incident decision-owner and deputy, and approve the provider SLA change for suspected significant incidents (finding F-03).
- Approve the supplier programme: scoped access for the cold-chain monitoring provider now, the clause schedule at the February renewal (finding F-07).
Six months, in order
- Month 1 — governance and reporting (Art. 20, Art. 23): incident owner and deputy named, CSIRT channel recorded and tested, board approval and briefing minuted.
- Months 2–3 — supply chain and continuity (Art. 21(2)(d), (c)): supplier questionnaire and scoped access for the monitoring provider; a continuity and crisis plan with recovery objectives, owned by the operations director, and a first restore-and-recover exercise with its record kept; registration data confirmed with the national authority.
- Months 4–6 — the remaining partial areas (Art. 21(2)(a), (b), (g)) closed: policy set approved, incident-handling procedure rewritten around the new owner, hygiene and training programme started; the first effectiveness review (Art. 21(2)(f)) feeding the quarterly management pack; a ransomware tabletop against the Art. 23 clocks.
What this review did not do
It did not test systems, review code or assess the IT provider's own controls beyond the contract and the questionnaire. It is a practitioner's written view of readiness against the Directive, with the national transposition applied where the report says so, based on the documents and the six interviews listed in the appendix. It is not an audit opinion and not legal advice; the two registration points flagged for counsel are listed on the last page.