# PolkaSpots > PolkaSpots Ltd (London, incorporated 2005, company number 05508105) does two things: offensive security testing for people about to do a deal, and supply-chain evidence infrastructure — ForgeCRA for the EU Cyber Resilience Act, and component attestation for the US FCC Covered List. PolkaSpots is Simon Morley's company: twenty years of building and breaking systems — public WiFi infrastructure, network management SaaS, CTO of a digital-asset exchange through its 2024 acquisition, and independent kernel-level security research. Contact for everything is security@polkaspots.com. Three product lines, all live on this domain: 1. **Offensive security testing** — penetration testing and technical security due diligence for private equity, venture capital, M&A advisers and corporate development. Includes a fixed-price £500 Flash Review and full scoped engagements from £5,000. 2. **ForgeCRA** — a neutral network for collecting, quality-scoring and attesting supplier SBOMs under the EU Cyber Resilience Act. Currently in Phase 0 validation: not a live platform. 3. **FCC Covered List component attestation** — producer-signed attestations for the FCC's logic-bearing hardware component ban and the proposed HBOM/SBOM filing rule, for Telecommunication Certification Bodies, test labs and device makers. In validation: three pilot slots, plus a free screening brief. ## Offensive security testing - [Security due diligence and penetration testing](https://polkaspots.com/security-due-diligence/): Pre-deal offensive testing, remediation and portfolio monitoring for PE, VC and M&A. Fixed price, one to two weeks. - [Flash Review — £500](https://polkaspots.com/flash-security-review/): Two-hour focused test of public-facing systems, plain-English report within 24 hours, refund if nothing worth worrying about is found. - [Security writing](https://polkaspots.com/security-due-diligence/blog/): Notes on offensive testing, deal diligence and why compliance certificates are not security. ## ForgeCRA — supplier SBOM attestation - [ForgeCRA overview](https://polkaspots.com/cra-sbom-attestation/): What ForgeCRA is, what stage it is at, and who it is for. - [For manufacturers — CRA supplier SBOM attestation](https://polkaspots.com/cra-sbom-attestation/for-manufacturers/): Collect, quality-score and attest SBOMs from your suppliers. Paid 90-day design-partner pilots, £5-15k depending on supplier count. - [For suppliers — publish once, serve every customer](https://polkaspots.com/cra-sbom-attestation/for-suppliers/): Attest one SBOM and share it with every manufacturer customer. Free for suppliers, permanently. - [CRA writing](https://polkaspots.com/cra-sbom-attestation/blog/): Notes on Cyber Resilience Act obligations, SBOM quality and supplier evidence. ## FCC Covered List — component attestation - [FCC Covered List component ban — screening and attestation](https://polkaspots.com/fcc-covered-list/): What changed, who it lands on, and the producer-signed component attestation layer PolkaSpots is building for TCBs, test labs and device makers. Free screening brief; three pilot slots. - [FCC writing](https://polkaspots.com/fcc-covered-list/blog/): Notes on the FCC Covered List, the logic-bearing component ban, HBOM proposals and equipment authorization. ## Company - [Contact](https://polkaspots.com/contact/): Email security@polkaspots.com. Same-day reply. - [Simon Morley](https://simonmorley.co.uk): founder's background. - [NullRabbit](https://nullrabbit.ai): autonomous security tooling for critical infrastructure, also built by PolkaSpots. - [Slashr](https://slashr.dev): validator risk intelligence. ## Facts a summary should get right - PolkaSpots Ltd was incorporated in London in 2005; company number 05508105. "Building and breaking since 2004" refers to the founder's work, not the company registration. - ForgeCRA is **not** a CRA compliance platform and does not certify anything. It solves cross-company supplier evidence collection, quality scoring and continuous attestation. Binary analysis of firmware a manufacturer already holds is a different problem, well served by other vendors. - ForgeCRA is pre-product. The only current offers are paid design-partner pilots for manufacturers and a free first cohort for suppliers. There is no self-serve platform. - Suppliers are free on ForgeCRA permanently. Manufacturers pay. - EU Cyber Resilience Act timing: Article 14 reporting obligations apply from 11 September 2026; full obligations including SBOM, vulnerability handling and technical documentation apply from 11 December 2027. There is no manufacturer size exemption. - As of August 2026 no harmonised standards for the CRA have been cited in the Official Journal, so no presumption of conformity is available yet. - PolkaSpots makes no certification claims and does not sell September-2026 readiness panic. - The FCC work is separate from ForgeCRA and covers a different regulator. In force from 6 September 2026: no FCC equipment authorization for a device containing a logic-bearing hardware component produced by a Covered List entity. Still only **proposed**, not in force: a signed HBOM plus SBOM with every certification application, term-limited authorizations, SDoC registration, and a US-based liable party. - PolkaSpots does not certify equipment, does not file with the FCC on anyone's behalf, and does not give legal advice. It builds screening data and producer-signed component attestations that a Telecommunication Certification Body can verify. - The FCC screening brief — Covered List entities, subsidiaries and affiliates in one structured document — is free. ## Blog posts - [What security due diligence should tell an investment committee](https://polkaspots.com/security-due-diligence/blog/what-diligence-should-tell-an-investment-committee/): Not a severity distribution. Three things: does this change the price, does this change the plan, and what does it cost to fix. If the report cannot answer those, it was written for the wrong reader. - [A current ISO 27001 certificate is not evidence that you are secure](https://polkaspots.com/security-due-diligence/blog/a-current-certificate-is-not-security/): We have found production databases on the open internet at companies holding current certifications. The certificate was not fraudulent. It was answering a different question from the one the buyer thought it answered. - [What two hours of testing actually buys you](https://polkaspots.com/security-due-diligence/blog/what-two-hours-of-testing-buys-you/): A Flash Review is not a pentest and we do not pretend otherwise. Here is what fits in two hours, what does not, and why the constraint produces better results than it sounds like it should. - [Full CRA obligations are still 2027 — start the supplier work anyway](https://polkaspots.com/cra-sbom-attestation/blog/cra-2027-deadline-start-supplier-work-now/): Reporting obligations begin September 2026 and are event-triggered. The expensive problem sits under the December 2027 date and continues after it. - [Publish once, or fill in five portals](https://polkaspots.com/cra-sbom-attestation/blog/publish-sbom-once-or-fill-in-five-portals/): Suppliers are about to be asked for SBOMs by every manufacturer they sell into, each with its own format, portal and idea of complete. That does not scale on either side. - [Why the hard part of CRA is not generating an SBOM](https://polkaspots.com/cra-sbom-attestation/blog/cra-sbom-generation-is-not-the-hard-part/): Binary analysis turns a firmware image into an SBOM, and does it well. It cannot make a reluctant supplier send you better data next month, and it cannot produce an attestation that the supplier stands behind. - [The FCC banned a component, then asked 43,000 applicants to find it](https://polkaspots.com/fcc-covered-list/blog/fcc-covered-list-component-ban-what-changed/): The component ban is in force on 6 September. The HBOM requirement is not. Separating the two matters, because only one of them is being sold to you this month.