Cyber Resilience Act (CRA) · Product security evidence
Map scattered security evidence to the Product Versions you ship.
Stop reconstructing security and compliance history from spreadsheets, tickets and disconnected tools. CRA Ledger keeps SBOMs, vulnerability reviews, remediation decisions and release evidence connected to each Product Version.
Build the record as your team works - so the evidence is there when a release, customer, auditor or CRA assessment requires it.
Product Version record
Industrial Gateway 2.4.1
184
Components
12
Findings
9
Reviewed
3
Decisions
Recent evidence activity
SBOM linked
Component inventory attached
Finding reviewed
Release context assessed
Decision recorded
Owner and rationale retained
Release evidence updated
History kept with the version
SBOM + Findings
Product-Version Evidence Record
Reviewable Release History
The problem
The evidence exists. The connected record does not.
Security evidence often lives in useful systems, but reconstructing what happened for one shipped Product Version is difficult.
A new CVE appears. Which shipped Product Versions are affected — and can you show what your team decided?
Scattered inputs
SBOMs
Component inventories
Vulnerability findings
Scanner and review output
Tickets
Remediation follow-up
Review notes
Assessment context
Remediation evidence
Supporting records
Release records
Sign-off and history
These records may remain in different systems.
CRA Ledger
Industrial Gateway 2.4.1
SBOM scope
Components connected to the version
Vulnerability review
Findings assessed in context
Human decisions
Rationale, owner and timestamp
Remediation context
Work and supporting evidence
Evidence Pack
Version-specific sign-off context
Reporting history
Assessment milestones retained
Evidence stays connected to the Product Version instead of being reconstructed later from files, tickets and handoffs.
How it works
Build the evidence record as the Product Version moves toward release.
01 · Connect
Link an SBOM and security evidence to the Product Version.
02 · Review
Assess findings in release context.
03 · Decide
Record the decision, owner, and rationale.
04 · Retain
Connect remediation work, accepted-risk context, and supporting evidence to a review-ready Evidence Pack.
Product proof
See the security decisions behind every Product Version.
Review findings in Product-Version context and retain the decisions, owners and evidence behind each release.
CRA Ledger Product View · Demo data
Vulnerability review · Industrial Gateway 2.4.1
OpenSSL 3.0.13
SBOM component
libxml2 2.11.7
SBOM component
curl 8.6.0
SBOM component
CRA Article 14 workflow
Keep reporting decisions connected to the affected Product Version.
When a vulnerability or severe security incident requires assessment, CRA Ledger retains the awareness context, human reportability decision and reporting milestones alongside the affected Product Version. Known exploited vulnerability signals and recorded severe security incidents can flag affected Product Versions for human CRA Reporting assessment.
Manufacturer awareness
Human determination
Reporting milestones
Evidence retained
CRA Ledger records the reporting workflow; it does not submit to an authority.
Guided pilot
Validate the workflow with your own Product Version.
Start with 1–3 Product Versions or SBOMs and validate the workflow using your own product-security evidence.
30-day no-cost guided pilot for selected teams
- One existing Product Version
- SBOM/component mapping
- Vulnerability review workflow
- Product-Version evidence record
- CRA Reporting workflow walkthrough
- Guided setup
- No local installation required