All specialist topics

Software & security

CRA: software inventory and vulnerability workflows

Assess components, vulnerability handling and technical evidence for one software product. Prepare an SBOM and a verifiable process.

For: Manufacturers of software and products with digital elements

THE IMPLEMENTATION GOAL

A result you can verify.

The component inventory is traceable for one defined release; a test advisory is followed through to a documented decision.

YOUR STARTING POINT

Three packages. A clear scope.

Choose the step you need. An existing assessment can provide the basis for implementation.

01

Assessment & roadmap

€699.00 one-off

One product, one repository or build artefact and one existing release process; assessment and a technical action plan.

  • Technical review based on the documentation you provide
  • Written findings with prioritised next steps and clearly identified open questions
  • One online follow-up session to discuss the results

Fixed price for the stated assessment scope, including 19% VAT. Implementation and third-party fees are separate. An enquiry does not place an order.

Enquire about this package
02

Implementation & handover

Individual project quote

A jointly scoped pilot with agreed systems, examples and acceptance criteria.

  • Set up component inventory and SBOM generation for one build
  • Make technical intake, assessment and handling of vulnerabilities traceable
  • Test release evidence and an agreed reporting workflow using one scenario

Scope, project price, schedule and required provider services are agreed before commissioning. Handover includes the agreed technical documentation and introduction.

Enquire about this package
03

Support & development

Individual monthly quote

Maintain component advisories and technical evidence for one product; agree response times and specialist responsibilities separately.

  • Technical takeover of the agreed existing solution
  • Agreed monitoring, troubleshooting and change maintenance
  • Documented handover of open issues and completed changes

Monthly price, allowance, service hours, term and cancellation are agreed separately. Infrastructure, licences and on-call support are included only when explicitly offered.

Enquire about this package

What we need to get started

  • Product description, distribution model and clarified responsible role
  • Build process, dependencies and current handling of security reports

A description is enough for your first enquiry. We will then agree suitable ways to exchange files and arrange access.

What the scope covers

Technical preparation for the agreed product scope. No conformity assessment, CE approval, legal advice or promise of complete CRA compliance. Applicability, including open-source and service cases, must be clarified separately.

We check the package against your project. Your enquiry is non-binding; commissioning and scheduling are agreed afterwards.

UNDERSTAND THE TOPIC

Preparing for the CRA: an SBOM needs a working process.

The Cyber Resilience Act concerns products with digital elements within its scope. The European Commission identifies 11 September 2026 for certain reporting obligations and 11 December 2027 for the main obligations. Particular roles and product situations have specific provisions; classification must precede an implementation plan.

Read the full article
Primary sources and review date

Reviewed on: . We check the versions and requirements relevant to your project before work begins.

A good place to start.

neurofunken knowledge assistant

Hello! What would you like to improve? I can explain our services and help you find a useful next step.

Replies from our editorial knowledge base.

Please do not enter confidential information. Privacy