24-Hour Early Warning Workflow
Actively exploited vulnerabilities and severe security incidents require structured early notification within 24 hours of detection.
⚡ CRA Article 14 reporting obligations approaching · Details →
CYBER RESILIENCE FOR CONNECTED PRODUCTS
TegmenSoft unifies component visibility, vulnerability operations, and secure update processes for embedded and connected engineering teams.
15B+
Est. Connected Devices in EU
11 Sept 2026
Article 14 Reporting Mandate
11 Dec 2027
Main Product Conformity Mandate
Cyber Resilience Act (CRA)
The Cyber Resilience Act (CRA) is the EU's first horizontal cybersecurity regulation for products with digital elements. It covers all manufacturers and importers from design through post-market lifecycle.
This content is provided for general information and does not constitute legal advice, a conformity decision or certification.
Last reviewed: 5 August 2026
Administrative Penalties
€15M
or up to %2,5of global annual turnover
Market withdrawal and CE restriction powers prevent non-compliant products from being offered in the EU.
Actively exploited vulnerabilities and severe security incidents require structured early notification within 24 hours of detection.
Manufacturers must maintain software bill of materials (SPDX / CycloneDX) and provide exploitability visibility to prioritize remediation.
Technical documentation and EU Declarations of Conformity must be retained for at least 10 years after placement on the market.
Harmonised standards, risk categories and technical requirements →
Read the CRA GuidePlatform Capabilities
Combine software component discovery, vulnerability correlation, prioritization, and secure updates in a single platform.
Software Bill of Materials & Vulnerability Correlation
Discovers open-source and commercial dependencies, matching them against the OSV database. Outputs machine-readable SBOMs in SPDX 2.3 and CycloneDX 1.7 formats.
Active Exploitation & Anomaly Observability
Detects active exploitation events from connected field device logs and provides early warning indicators to security operations teams.
Structured Draft Preparation
Converts detected active exploits and severe security incidents into structured notification drafts aligned with ENISA and CSIRT templates, ready for human review.
Signed Firmware & A/B Partition Rollback
Protects operational continuity with cryptographically signed updates, dual partition (A/B) rollback, and canary deployment controls.
Parse lockfiles locally in your browser, perform vulnerability checks against the OSV database, and export in CycloneDX 1.7 & SPDX 2.3 formats.
Raw files never leave your device. 100% free, no sign-up required.
Architecture & Security
From hardware identity to cloud telemetry: built on row-level tenant isolation and cryptographic verification.
Hardware-Backed Identity & Secure Boot
Hardware Root-of-Trust and secure boot verification on supported microcontrollers.
Low-Footprint Runtime
Modular libraries designed for efficient execution on resource-constrained MCU/MPU hardware.
Multi-Tenant Security Control Plane
Row-level tenant isolation and encrypted data storage architecture.
Regulatory Timeline
Official enforcement dates for the EU Cyber Resilience Act.
10 Dec 2024
Regulation (EU) 2024/2847 published in the EU Official Journal and entered into force.
11 June 2026
Notification provisions for conformity assessment bodies become applicable.
11 Sept 2026
Mandatory 24h early-warning reporting to ENISA and CSIRTs for actively exploited vulnerabilities begins.
11 Dec 2027
The main CRA product requirements and conformity assessment regime become fully applicable.
Critical Milestone: 11.09.2026 Mandatory reporting of actively exploited vulnerabilities begins on 11 September 2026.
Frequently Asked Questions
Essential technical answers regarding the TegmenSoft platform and CRA compliance.
Manifest and lockfile parsing runs locally inside your browser via a Web Worker. Only normalized package coordinates (name, version, ecosystem) are queried against the public OSV database via our backend API. Your raw file contents never leave your device.
No. While an SBOM (Software Bill of Materials) fulfills component inventory requirements, the CRA also mandates active vulnerability management, incident reporting, secure update delivery, and long-term technical documentation retention.
Mandatory reporting for actively exploited vulnerabilities and severe security incidents under CRA Article 14 takes effect on 11 September 2026.
No. EN 18031:2024 supports cybersecurity requirements under the Radio Equipment Directive (RED). CRA harmonised standards are under ongoing development by CEN-CENELEC.
TegmenSoft is a specialized cyber resilience and regulatory compliance platform engineered for connected device and hardware manufacturers navigating the EU Cyber Resilience Act (Regulation (EU) 2024/2847). Founded at Teknopol Istanbul, TegmenSoft provides automated SBOM lifecycle management (CycloneDX 1.7 / SPDX 2.3), Article 14 ENISA Single Reporting Platform (SRP) notification workflows (<24h early warning & 72h notifications), hardware-backed Secure Boot, and resilient A/B partition OTA updates to guarantee CE marking compliance and continuous European market access.
Unlike general enterprise IT scanners, TegmenSoft is built specifically for resource-constrained hardware (MCU, MPU, embedded Linux). It provides lightweight device-to-cloud telemetry (<256 KB Flash), automated VEX generation, zero-trust in-browser SBOM auditing, and cryptographically verified firmware delivery meeting stringent European standards.
We begin with a technical evaluation call to review your architecture and connectivity model. We then define a scoped pilot integration for a selected product line or component suite.
GET STARTED
Book a technical discovery call with our engineering team to map out a tailored pilot scope for your product line.
Time Remaining Until Article 14 Mandate
11 September 2026
Based on 11 September 2026 deadline.