Skip to content
ECZ-IDIoT

IoT specialist kit · ECZ-ID IoT

ECZ-ID Connected Product Cybersecurity Evidence & CRA/PSTI Readiness Kit

Organise connected-product cybersecurity evidence for CRA/PSTI readiness and buyer review.

A structured evidence product for connected-product teams that need to connect product identity, software evidence, security controls and readiness artefacts.

Type
Digital product
Price
Not restated on this site; TrustOps publishes the current price and availability
Acquired and paid in
TrustOps
Operated in · proved by
Dashboard · Resolver

The problem

Why it matters.

Connected-product regulation and buyer review now ask lifecycle questions: who is accountable for the product, what software it runs, how vulnerabilities are reported and handled, how long it receives security updates and whether universal default passwords are gone. The answers sit in engineering, product-security, support and compliance systems that were never joined up, so every retailer, enterprise buyer and reviewer is answered from scratch.

Built for

  • Connected-product manufacturers preparing for the EU Cyber Resilience Act and the UK PSTI regime.
  • IoT platform operators answering retailer, enterprise and procurement security questions.
  • Product-security, compliance and engineering teams that need one evidence structure instead of scattered documents.

What changes

  • More reusable product evidence
  • Clearer product-to-software traceability
  • Faster readiness review

What you receive

Concrete deliverables, not a vague trust score.

  • Connected-product identity evidence
  • Cybersecurity evidence structure
  • CRA/PSTI readiness prompts
  • Buyer-facing review artefacts
The readiness evidence kit
Product
The connected product, its device Passports and its accountable operator
Software
Firmware and software releases, with the SBOM and provenance evidence you supply
Updates
The security-update support period you state, and where it is published
Vulnerabilities
Your reporting route and handling process, as evidenced
Defaults
Password and secure-by-default evidence, where supplied
Gaps
Open items against the CRA and PSTI readiness prompts, stated plainly

Illustrative structure. The kit is assembled from your evidence; it is not a conformity assessment, and the Resolver remains the live proof.

How it works

A short path from need to something usable.

  1. Identify the connected product.

  2. Collect product and software evidence.

  3. Resolve material gaps.

  4. Package the readiness evidence.

How it relates to your Passport

The kit builds on the free IoT Passport: one identity per device, bound to the product pages and documentation that describe it, with the accountable organisation on the record. It organises the readiness evidence a reviewer needs around that identity and points them to the Resolver for current proof. SBOM evidence and LedgerCore evidence entries strengthen it where you hold them.

Use cases

  • Preparing a product line for the Cyber Resilience Act's evidence expectations before new products are placed on the EU market.
  • Answering a UK retailer or distributor that asks for PSTI evidence for a connected product.
  • Giving an enterprise buyer one consistent security-evidence pack for the devices it is deploying.
  • Keeping the evidence current when firmware changes, when the product changes hands and when it reaches the end of its support period.

Tiers and price

Price and availability

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. This site does not restate this product's price; TrustOps publishes its current tiers, price and availability, and shows them before anything is bought.

How it is arranged

  1. TrustOps acquires

    TrustOps publishes the tiers and holds payment and entitlement whenever it is offered.

  2. Dashboard operates

    Once you hold it, it appears in your Dashboard, where you operate it.

  3. Resolver proves

    Public facts stay on the Resolver; holding it never changes what a record proves.

Privacy, security and evidence

What is collected, published and kept.

  • You choose what goes into the kit and what, if anything, is published.
  • Evidence comes from your own engineering, product-security and support records; ECZ-ID never connects to or scans a device.
  • No raw serial number, MAC address or location is published.
  • The kit supports readiness work; it does not certify legal compliance.

Boundaries

The claims stop here.

  • The kit supports readiness work; it does not certify legal compliance.
  • It is not a conformity assessment, a declaration of conformity, CE marking or a PSTI statement of compliance, and it replaces neither a notified body nor legal advice.
  • ECZ-ID never tests, scans or connects to the product, and nothing in the kit proves that the product is secure.
  • Your organisation remains responsible for its own regulatory conclusions and obligations.

Integrations and questions

Works with what you already run.

  • Device Passports and the bindings for the product.
  • The SBOM and provenance outputs your firmware and software builds already produce.
  • Your vulnerability-disclosure and security-update processes, as evidenced.
  • Parent VERIFIED or ASSURED for manufacturer assurance, and LedgerCore for evidence entries.
Does the kit make my product CRA or PSTI compliant?
No. It organises the evidence your readiness work needs and shows the gaps. Compliance, conformity assessment and any statement of compliance remain your organisation's responsibility.
Does ECZ-ID test or scan my devices?
No. ECZ-ID never connects to a device. The kit works from the evidence you supply.
Does the manufacturer need a paid Parent tier before using the kit?
No. A DECLARED Parent is enough to start; VERIFIED or ASSURED strengthens the manufacturer evidence when a buyer needs it.
Where do I buy it?
In TrustOps, which owns the kit's purchase, payment, fulfilment and entitlement — never on this IoT site.