Cyber Resilience Act (CRA) · Product security evidence

Map scattered security evidence to the Product Versions you ship.

Stop reconstructing security and compliance history from spreadsheets, tickets and disconnected tools. CRA Ledger keeps SBOMs, vulnerability reviews, remediation decisions and release evidence connected to each Product Version.

Build the record as your team works - so the evidence is there when a release, customer, auditor or CRA assessment requires it.

The problem

The evidence exists. The connected record does not.

Security evidence often lives in useful systems, but reconstructing what happened for one shipped Product Version is difficult.

A new CVE appears. Which shipped Product Versions are affected — and can you show what your team decided?

Scattered inputs

SBOMs

Component inventories

Vulnerability findings

Scanner and review output

Tickets

Remediation follow-up

Review notes

Assessment context

Remediation evidence

Supporting records

Release records

Sign-off and history

These records may remain in different systems.

CRA Ledger

Industrial Gateway 2.4.1

SBOM scope

Components connected to the version

Vulnerability review

Findings assessed in context

Human decisions

Rationale, owner and timestamp

Remediation context

Work and supporting evidence

Evidence Pack

Version-specific sign-off context

Reporting history

Assessment milestones retained

Evidence stays connected to the Product Version instead of being reconstructed later from files, tickets and handoffs.

How it works

Build the evidence record as the Product Version moves toward release.

Product Version
SBOM
Findings
Human Review
Decision
Remediation
Evidence Pack

01 · Connect

Link an SBOM and security evidence to the Product Version.

02 · Review

Assess findings in release context.

03 · Decide

Record the decision, owner, and rationale.

04 · Retain

Connect remediation work, accepted-risk context, and supporting evidence to a review-ready Evidence Pack.

Product proof

See the security decisions behind every Product Version.

Review findings in Product-Version context and retain the decisions, owners and evidence behind each release.

CRA Article 14 workflow

Keep reporting decisions connected to the affected Product Version.

When a vulnerability or severe security incident requires assessment, CRA Ledger retains the awareness context, human reportability decision and reporting milestones alongside the affected Product Version. Known exploited vulnerability signals and recorded severe security incidents can flag affected Product Versions for human CRA Reporting assessment.

Attention
Assess
Report
Finalize
Close

Manufacturer awareness

Human determination

Reporting milestones

Evidence retained

CRA Ledger records the reporting workflow; it does not submit to an authority.

Guided pilot

Validate the workflow with your own Product Version.

Start with 1–3 Product Versions or SBOMs and validate the workflow using your own product-security evidence.

30-day no-cost guided pilot for selected teams

  • One existing Product Version
  • SBOM/component mapping
  • Vulnerability review workflow
  • Product-Version evidence record
  • CRA Reporting workflow walkthrough
  • Guided setup
  • No local installation required