Comparison Overview

CR&A Custom Inc.

VS

The Kennedy Group, an Inovar company

CR&A Custom Inc.

312 West Pico Blvd, Los Angeles, CA, 90015, US
Last Update: 2025-12-11
Between 750 and 799

http://www.cracustom.com Phone: 213. 749. 4440 CR&A is a full-service digital printer with over 20 years of experience producing and installing all types of signage from retractable banners to wall murals to vehicle wraps to billboards. A combination of an award-winning, in-house design team and owning the latest state-of-the-art equipment available, allows CR&A to assist customers from concept to manufacturing to installation. CR&A’s service capabilities reach all 50 U.S. states, Canada, South & Central America, plus the Caribbean. Over the last 2 decades, CR&A has grown to 43 employees and now operates out of 34,000 square foot headquarters in the heart of LA that exceeds all City of LA environmental requirements. From small businesses to non-profits to Fortune 500 Corporations, CR&A has served nearly 2,000 clients. KEY PRODUCTS // Full range of earth-friendly printable media available Large Format • Indoor/Outdoor Banners • Building Wraps • Walls/Windows/Floors • Billboards • Bus Shelters • Benches • Vehicle Wraps Events/Trade Shows • Indoor/Outdoor Banners • Retractables / Pop-ups • Promotional Items • Exhibit Booths • Table Cloths • Step & Repeats • POS/POP Displays Special Occasions • Wall Murals • Posters • Large Head Cut-Outs ADDITIONAL SERVICES Installation: We operate & own all vans, crane trucks, and hydraulic lifts. Graphic Design: In-house, award-winning team. From conceptual designs to logos to event programs. Consulting: Event branding & logistics, Original concepts, Creative feedback.

NAICS: 323
NAICS Definition:
Employees: 23
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

The Kennedy Group, an Inovar company

38601 Kennedy Pkwy, Willoughby, 44094, US
Last Update: 2025-12-10
Between 750 and 799

Since 1974, The Kennedy Group, an Inovar company, has been a leader in providing market-tested and innovative global labeling solutions to help customers package, promote, identify, and track products throughout their life cycle. We are large enough to service complex organizations with many requirements and multiple plant sites but small enough to maintain the personal touch and service that companies need, want, and appreciate. The Kennedy Group is a leading provider for a variety of industries that include consumer goods products, industrial, automotive, material handling, biomedical, healthcare, agricultural, and chemical. Made up of four divisions, the Labeling and Packaging division offers a wide variety of pressure-sensitive, promotional, and roll-fed film packaging solutions that create unique shelf appeal and powerful branding solutions. The Kennedy Group’s Material Handling Identification division provides specific identification solutions and label holders for reusable containers, racks, and pallet storage areas. In addition, the company's Promotional Response Products division offers high-visibility & impactful messaging with front-page newspaper advertising. The RFID Solutions division provides custom RFID tags for all industries. The Kennedy Group is one of the most experienced producers of custom RFID tags in the country, and we’ve developed RFID tracking technology to help companies with every step of their supply chain. From warehouse tracking to shipping, all the way through in-store inventory on the retail rack.

NAICS: 323
NAICS Definition: Printing and Related Support Activities
Employees: 103
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/cr&a-custom-printing.jpeg
CR&A Custom Inc.
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/the-kennedy-group.jpeg
The Kennedy Group, an Inovar company
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
CR&A Custom Inc.
100%
Compliance Rate
0/4 Standards Verified
The Kennedy Group, an Inovar company
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Printing Services Industry Average (This Year)

No incidents recorded for CR&A Custom Inc. in 2025.

Incidents vs Printing Services Industry Average (This Year)

No incidents recorded for The Kennedy Group, an Inovar company in 2025.

Incident History — CR&A Custom Inc. (X = Date, Y = Severity)

CR&A Custom Inc. cyber incidents detection timeline including parent company and subsidiaries

Incident History — The Kennedy Group, an Inovar company (X = Date, Y = Severity)

The Kennedy Group, an Inovar company cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/cr&a-custom-printing.jpeg
CR&A Custom Inc.
Incidents

No Incident

https://images.rankiteo.com/companyimages/the-kennedy-group.jpeg
The Kennedy Group, an Inovar company
Incidents

No Incident

FAQ

The Kennedy Group, an Inovar company company demonstrates a stronger AI Cybersecurity Score compared to CR&A Custom Inc. company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, The Kennedy Group, an Inovar company company has disclosed a higher number of cyber incidents compared to CR&A Custom Inc. company.

In the current year, The Kennedy Group, an Inovar company company and CR&A Custom Inc. company have not reported any cyber incidents.

Neither The Kennedy Group, an Inovar company company nor CR&A Custom Inc. company has reported experiencing a ransomware attack publicly.

Neither The Kennedy Group, an Inovar company company nor CR&A Custom Inc. company has reported experiencing a data breach publicly.

Neither The Kennedy Group, an Inovar company company nor CR&A Custom Inc. company has reported experiencing targeted cyberattacks publicly.

Neither CR&A Custom Inc. company nor The Kennedy Group, an Inovar company company has reported experiencing or disclosing vulnerabilities publicly.

Neither CR&A Custom Inc. nor The Kennedy Group, an Inovar company holds any compliance certifications.

Neither company holds any compliance certifications.

Neither CR&A Custom Inc. company nor The Kennedy Group, an Inovar company company has publicly disclosed detailed information about the number of their subsidiaries.

The Kennedy Group, an Inovar company company employs more people globally than CR&A Custom Inc. company, reflecting its scale as a Printing Services.

Neither CR&A Custom Inc. nor The Kennedy Group, an Inovar company holds SOC 2 Type 1 certification.

Neither CR&A Custom Inc. nor The Kennedy Group, an Inovar company holds SOC 2 Type 2 certification.

Neither CR&A Custom Inc. nor The Kennedy Group, an Inovar company holds ISO 27001 certification.

Neither CR&A Custom Inc. nor The Kennedy Group, an Inovar company holds PCI DSS certification.

Neither CR&A Custom Inc. nor The Kennedy Group, an Inovar company holds HIPAA certification.

Neither CR&A Custom Inc. nor The Kennedy Group, an Inovar company holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a lower‑privileged user. A local attacker with access to the application account can modify this file to introduce malicious code, which is then executed with elevated privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.

Risk Information
cvss4
Base: 8.6
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Description

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Description

SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alpha-1, a nil pointer dereference vulnerability is in the SIPGO library's `NewResponseFromRequest` function that affects all normal SIP operations. The vulnerability allows remote attackers to crash any SIP application by sending a single malformed SIP request without a To header. The vulnerability occurs when SIP message parsing succeeds for a request missing the To header, but the response creation code assumes the To header exists without proper nil checks. This affects routine operations like call setup, authentication, and message handling - not just error cases. This vulnerability affects all SIP applications using the sipgo library, not just specific configurations or edge cases, as long as they make use of the `NewResponseFromRequest` function. Version 1.0.0-alpha-1 contains a patch for the issue.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unauthorized user with an API access can read all knowledge base entries. Users should upgrade to 10.0.21 to receive a patch.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N