CRA Evidence
Profile Overview
About CRA Evidence
CRA Evidence helps manufacturers, importers and distributors comply with the EU Cyber Resilience Act. The Act becomes fully applicable in December 2027. From then on, products with digital elements placed on the EU market must be supported by an Annex VII technical file and an EU Declaration of Conformity. Companies must retain documentation for ten years under Article 13 and report incidents to ENISA under Article 14. Breaches may result in fines of up to €15 million or 2.5% of worldwide turnover. 🔹 SBOM management. Import CycloneDX 1.4+ and SPDX 2.3+ files, assess them against BSI TR-03183, and manage HBOMs for embedded systems. 🔹 Vulnerability intelligence. Maintain your own vulnerability knowledge base, refreshed every 15 minutes with data from NVD, OSV.dev, GitHub Advisories and CISA KEV. An independent scanner adds another detection layer. 🔹 Prioritization based on exploitation. Enrich findings with EPSS data from FIRST.org and CISA KEV to focus remediation on the likelihood of real-world exploitation rather than CVSS scores alone. 🔹 Automated VEX. Create a VEX statement for each finding, documenting non-exploitable CVEs and sharing the information with downstream users in a machine-readable format. 🔹 Technical file creation. Generate Annex VII packages, EU Declarations of Conformity, Annex II Security Data Sheets and CE marking records as signed PDFs. 🔹 ENISA reporting workflow. Manage structured 24-hour, 72-hour and 14-day notification windows, track deadlines and retain submission receipts. 🔹 Supplier and importer portal. Gather SBOMs and declarations of conformity from upstream suppliers, enabling importers and distributors to check compliance before products enter the EU market. 🔹 CI/CD integration. Use the open-source CLI to publish SBOMs and release metadata straight from your build pipeline. 🔹 Digital Product Passports. Provide QR-linked passports for labelling physical products. Manufacturers, importers and distributors rely on CRA Evidence to fulfil CRA requirements and stay aligned with NIS2, RED and the Machinery Regulation.
Contact the vendor and get feedback on your queries in a timely manner.
Locations
Services
- Cyber Security: 35 %
- Managed IT Services: 35 %
- IT Consulting: 30 %
Contact the service provider and receive an appropriate offer in a timely manner.






















