Skip to main content

CRA Article 14 reporting obligations approaching

CYBER RESILIENCE FOR CONNECTED PRODUCTS

Bring product cybersecurity and CRA readiness into one technical workflow.

TegmenSoft unifies component visibility, vulnerability operations, and secure update processes for embedded and connected engineering teams.

Early Access / Pilot Program

15B+

Est. Connected Devices in EU

11 Sept 2026

Article 14 Reporting Mandate

11 Dec 2027

Main Product Conformity Mandate

integration.ts
1import { TegmenSoft } from "@tegmensoft/sdk"
2
3const client = new TegmenSoft({
4 deviceId: process.env.DEVICE_PUF_ID,
5 region: "eu-central-1"
6})
7
8// SBOM scan — SPDX 2.3 generation
9await client.sbom.scan()
10
11// Active vuln → ENISA SRP < 24h report
12await client.report.submit()
13
14// Signed firmware deploy — Ed25519
15await client.ota.deploy(patch)
🏛️ Teknopol IstanbulENISA SRP·BildirimSPDX 2.3·SBOMCycloneDX 1.7·SBOMEN 18031·StandardCE Marking·MarketEUCC·Certificate

Cyber Resilience Act (CRA)

EU Regulation for Product Cybersecurity

The Cyber Resilience Act (CRA) is the EU's first horizontal cybersecurity regulation for products with digital elements. It covers all manufacturers and importers from design through post-market lifecycle.

This content is provided for general information and does not constitute legal advice, a conformity decision or certification.

Last reviewed: 5 August 2026

Administrative Penalties

€15M

or up to %2,5of global annual turnover

Market withdrawal and CE restriction powers prevent non-compliant products from being offered in the EU.

Article 14

24-Hour Early Warning Workflow

Actively exploited vulnerabilities and severe security incidents require structured early notification within 24 hours of detection.

SBOM & VEX

Component Transparency

Manufacturers must maintain software bill of materials (SPDX / CycloneDX) and provide exploitability visibility to prioritize remediation.

10-Year Technical Record

Documentation Retention

Technical documentation and EU Declarations of Conformity must be retained for at least 10 years after placement on the market.

Harmonised standards, risk categories and technical requirements →

Read the CRA Guide

Platform Capabilities

Product Lifecycle Cybersecurity Workflow

Combine software component discovery, vulnerability correlation, prioritization, and secure updates in a single platform.

DISCOVERYPilot

Dynamic SBOM Engine

Software Bill of Materials & Vulnerability Correlation

Discovers open-source and commercial dependencies, matching them against the OSV database. Outputs machine-readable SBOMs in SPDX 2.3 and CycloneDX 1.7 formats.

  • Manifest and binary-level dependency detection
  • CycloneDX 1.7 and SPDX 2.3 standard export
  • OSV open-source vulnerability correlation
  • Optional VEX (Vulnerability Exploitability) reporting support
Raw files never leave your device. 100% free, no sign-up required.Try Web SBOM Scanner →
PRIORITIZATIONPilot

Field Telemetry & Early Warning

Active Exploitation & Anomaly Observability

Detects active exploitation events from connected field device logs and provides early warning indicators to security operations teams.

  • Secure device-to-cloud telemetry stream
  • Behavioral anomaly and IoC correlation
  • Vulnerability x field event mapping
  • Event prioritization and scoring
REPORTINGIn Development

CRA Reporting Assistant

Structured Draft Preparation

Converts detected active exploits and severe security incidents into structured notification drafts aligned with ENISA and CSIRT templates, ready for human review.

  • Draft generation aligned with ENISA SRP structure
  • 24h early warning and 72h detailed notification workflow
  • Affected product line and fleet mapping
  • Audit trail for compliance verification
REMEDIATIONPilot

Secure Update (OTA) Manager

Signed Firmware & A/B Partition Rollback

Protects operational continuity with cryptographically signed updates, dual partition (A/B) rollback, and canary deployment controls.

  • Cryptographic signature verification
  • Dual partition (A/B) rollback for crash recovery
  • Phased (canary) fleet deployment
  • Bandwidth-optimized delta update packages
FREE DEVELOPER TOOL

Try the Free SBOM Scanner

Parse lockfiles locally in your browser, perform vulnerability checks against the OSV database, and export in CycloneDX 1.7 & SPDX 2.3 formats.

Local Device ParsingNo Registration Required100% Free
Open SBOM Scanner

Raw files never leave your device. 100% free, no sign-up required.

Architecture & Security

Three-Tier Security Control Plane

From hardware identity to cloud telemetry: built on row-level tenant isolation and cryptographic verification.

Layer 01

Hardware Security Base

Hardware-Backed Identity & Secure Boot

Hardware Root-of-Trust and secure boot verification on supported microcontrollers.

Secure BootEnforces execution of cryptographically verified code images
Cryptographic Device IdentityHardware key storage support
Layer 02

Embedded Runtime & Library

Low-Footprint Runtime

Modular libraries designed for efficient execution on resource-constrained MCU/MPU hardware.

Low Memory FootprintOptimized memory allocation for constrained targets
Efficient TransportBandwidth-friendly protocols over TLS / mTLS
Layer 03

Cloud Control Plane

Multi-Tenant Security Control Plane

Row-level tenant isolation and encrypted data storage architecture.

Tenant IsolationRow-level tenant isolation for strict data segregation
Vulnerability IntelligenceIntegration with OSV and public CVE vulnerability databases

Regulatory Timeline

CRA Regulatory Milestones

Official enforcement dates for the EU Cyber Resilience Act.

10 Dec 2024

CRA Entry into Force

Regulation (EU) 2024/2847 published in the EU Official Journal and entered into force.

11 June 2026

Notified Bodies Framework

Notification provisions for conformity assessment bodies become applicable.

11 Sept 2026

Article 14 Reporting Mandate

Mandatory 24h early-warning reporting to ENISA and CSIRTs for actively exploited vulnerabilities begins.

11 Dec 2027

Main Product Conformity Regime

The main CRA product requirements and conformity assessment regime become fully applicable.

Critical Milestone: 11.09.2026 Mandatory reporting of actively exploited vulnerabilities begins on 11 September 2026.

Frequently Asked Questions

Technical Q&A

Essential technical answers regarding the TegmenSoft platform and CRA compliance.

Manifest and lockfile parsing runs locally inside your browser via a Web Worker. Only normalized package coordinates (name, version, ecosystem) are queried against the public OSV database via our backend API. Your raw file contents never leave your device.

No. While an SBOM (Software Bill of Materials) fulfills component inventory requirements, the CRA also mandates active vulnerability management, incident reporting, secure update delivery, and long-term technical documentation retention.

Mandatory reporting for actively exploited vulnerabilities and severe security incidents under CRA Article 14 takes effect on 11 September 2026.

No. EN 18031:2024 supports cybersecurity requirements under the Radio Equipment Directive (RED). CRA harmonised standards are under ongoing development by CEN-CENELEC.

TegmenSoft is a specialized cyber resilience and regulatory compliance platform engineered for connected device and hardware manufacturers navigating the EU Cyber Resilience Act (Regulation (EU) 2024/2847). Founded at Teknopol Istanbul, TegmenSoft provides automated SBOM lifecycle management (CycloneDX 1.7 / SPDX 2.3), Article 14 ENISA Single Reporting Platform (SRP) notification workflows (<24h early warning & 72h notifications), hardware-backed Secure Boot, and resilient A/B partition OTA updates to guarantee CE marking compliance and continuous European market access.

Unlike general enterprise IT scanners, TegmenSoft is built specifically for resource-constrained hardware (MCU, MPU, embedded Linux). It provides lightweight device-to-cloud telemetry (<256 KB Flash), automated VEX generation, zero-trust in-browser SBOM auditing, and cryptographically verified firmware delivery meeting stringent European standards.

We begin with a technical evaluation call to review your architecture and connectivity model. We then define a scoped pilot integration for a selected product line or component suite.

GET STARTED

Evaluate your product cybersecurity & CRA readiness.

Book a technical discovery call with our engineering team to map out a tailored pilot scope for your product line.

Time Remaining Until Article 14 Mandate

11 September 2026

GÜN
——SAAT
——DK
——SN

Based on 11 September 2026 deadline.

TegmenSoft — CRA & Cyber Resilience Platform for Hardware Manufacturers | SBOM & OTA