Agent
CRA Compliance & Secure SDLC
EU Cyber Resilience Act: SBOM lifecycle, CVE-to-product mapping with VEX/CSAF, 24-hour ENISA reporting, and conformity documentation from CI/CD — plus Secure SDLC as a process.
What is the Cyber Resilience Act (CRA)?
The EU Cyber Resilience Act applies to all manufacturers of software and products with digital elements sold in the EU.
- Reporting obligations from September 2026
- Full compliance required from December 2027
- Penalties up to EUR 15M or 2.5% of global annual revenue
- About 90% of SMEs are not yet prepared
What our CRA compliance agent does
- SBOM lifecycle management: generation, updates, diff, monitoring of software bills of materials
- CVE-to-product mapping with automatic VEX statement generation
- CRA product classification (Class I, Class II, unclassified)
- Vulnerability disclosure workflow with 24-hour ENISA reporting
- CRA conformity documentation directly from the CI/CD pipeline
What we deliver beyond the agent
- Building a Secure SDLC as a process (not just a tool)
- Integration into existing CI/CD pipelines
- Development team training
- Ongoing monitoring and updates
Technical basis
Syft for SBOM generation, Grype for CVE scanning, CSAF for security advisories, custom agent logic for orchestration.
For whom
Software vendors, IoT manufacturers, and companies with connected products sold in the EU.
Contact
Question about your specific case? Talk to our agent above or get in touch directly.