EU CRA
The Cyber Resilience Act asks makers of products with digital elements for secure development, vulnerability handling, SBOMs and fast reporting of exploited vulnerabilities.
Where you are
If you sell software or connected products in the EU, the CRA applies to you. Reporting of actively exploited vulnerabilities applies from September 2026; most other obligations from December 2027.
Sounds familiar?
- No SBOM for the products you ship
- No public way to report a vulnerability
- No clock for telling the authorities
What you need
Each need, why it matters, and what covers it: the services that set it up, and the tower modules that will keep watching it.
- Secure by design
Risk assessment and secure development, documented per product.
Atalaia tower · Soon
- Know your components
A machine-readable SBOM for each release.
Atalaia tower · Soon
- Handle vulnerabilities
A disclosure policy, triage and security updates.
Atalaia tower · Soon
- Report on time
Early warning within 24 hours of an actively exploited vulnerability.
Services
Atalaia tower · Soon
What it asks, and where the evidence comes from
A simplified reading. Your legal team decides how it applies to your products.
| The CRA asks for | Evidence from the line | Who helps |
|---|---|---|
| Security by design and default | Threat models and requirements per release | Threat Modeling, Security Requirements |
| Components identified (SBOM) | An SBOM attached to each artefact | Registry & Signing, Code to Cloud |
| Vulnerability handling | Disclosure policy, triage records, fix times | Bug Bounty Program |
| Security updates | Which version runs where, and when it was patched | Code to Cloud |
| Reporting exploited vulnerabilities | Detection and a 24-hour reporting runbook | Detection Engineering |
We help you produce the evidence. We are not your auditor or your lawyer.
Services
Business, devs and cyber, one table
See the station →Station 02 · DesignSecurity RequirementsNon-functional needs and abuse cases
See the station →Station 09 · Release & testRegistry & SigningSBOM, provenance, signed builds
See the station →Station 07 · BuildSupply Chain SecurityPackages, extensions, registries
See the station →Station 15 · RunBug Bounty ProgramScope, triage, rewards, fixes
See the station →Station 17 · RunThreat IntelligenceNew threats checked against your stack
See the station →Station 17 · RunDetection EngineeringPentest findings become SOC use cases
See the station →Atalaia tower modules
In development. Early-access teams get them first.
A living model, layer by layer
What it watches →Module · SoonCode to CloudWhat was pushed, what is running, which version
What it watches →Module · SoonPackage firewallOne gate for every package install
What it watches →Module · SoonThe towerEvery station, findings and owners, one view
What it watches →What you end up with
- An SBOM for every release
- A disclosure and update process
- A reporting clock you can meet
Talk it through
A 30-minute call. No slides, no price list, and a next step either way.