Agent

CRA Compliance & Secure SDLC

EU Cyber Resilience Act: SBOM lifecycle, CVE-to-product mapping with VEX/CSAF, 24-hour ENISA reporting, and conformity documentation from CI/CD — plus Secure SDLC as a process.

What is the Cyber Resilience Act (CRA)?

The EU Cyber Resilience Act applies to all manufacturers of software and products with digital elements sold in the EU.

  • Reporting obligations from September 2026
  • Full compliance required from December 2027
  • Penalties up to EUR 15M or 2.5% of global annual revenue
  • About 90% of SMEs are not yet prepared

What our CRA compliance agent does

  • SBOM lifecycle management: generation, updates, diff, monitoring of software bills of materials
  • CVE-to-product mapping with automatic VEX statement generation
  • CRA product classification (Class I, Class II, unclassified)
  • Vulnerability disclosure workflow with 24-hour ENISA reporting
  • CRA conformity documentation directly from the CI/CD pipeline

What we deliver beyond the agent

  • Building a Secure SDLC as a process (not just a tool)
  • Integration into existing CI/CD pipelines
  • Development team training
  • Ongoing monitoring and updates

Technical basis

Syft for SBOM generation, Grype for CVE scanning, CSAF for security advisories, custom agent logic for orchestration.

For whom

Software vendors, IoT manufacturers, and companies with connected products sold in the EU.

Contact

Question about your specific case? Talk to our agent above or get in touch directly.