
CRA Evidence
Profile set up by Edverise AISet Up By Edverise AI
Edverise AI built this profile by analyzing thousands of data points across the web. If you own this business, become an Edverise partner to manage and update your profile.
Overview
2 - 9
Employees
2026
Year Founded
ABOUT CRA EVIDENCE
EU Cyber Resilience Act (CRA) Compliance Platform
CRA Evidence is a compliance platform designed for manufacturers, importers, and distributors to adhere to the EU Cyber Resilience Act (CRA), which will be fully implemented by December 2027. All products with digital components sold in the EU must include a technical file as per Annex VII, an EU Declaration of Conformity, a decade's worth of documentation in line with Article 13, and incident reporting as specified in Article 14 to ENISA. Fines for non-compliance can reach up to €15 million or 2.5% of global revenue.
Key features include:
🔹 **SBOM Management**: Supports CycloneDX 1.4+ and SPDX 2.3+, evaluated against BSI TR-03183, along with HBOM for embedded systems.
🔹 **Vulnerability Knowledge Base**: Maintains a Vulnerability Knowledge Base (VKB) updated every 15 minutes utilizing data from NVD, OSV.dev, GitHub Advisories, and CISA KEV, supplemented by an independent scanner for further detection.
🔹 **Exploit-Driven Prioritization**: Enhances findings with EPSS from FIRST.org and CISA KEV, ensuring remediation is based on actual exploitation risk rather than just CVSS scores.
🔹 **VEX Automation**: Automatically generates VEX statements for each finding, documenting and sharing non-exploitable CVEs with downstream users in a machine-readable format.
🔹 **Technical File Generation**: Produces Annex VII packages, EU Declarations of Conformity, Annex II Security Data Sheets, and CE marking records as signed PDFs.
🔹 **ENISA Reporting Workflow**: Implements structured timelines for notifications (24h/72h/14d) with tracking for deadlines and submission confirmations.
🔹 **Supplier & Importer Portal**: Gathers SBOMs and conformity declarations from suppliers to ensure importers and distributors can confirm compliance prior to releasing products in the EU market.
🔹 **CI/CD Integration**: An open-source CLI that publishes SBOMs and release metadata directly from build pipelines.
🔹 **Digital Product Passports**: QR-linked passports for labeling physical products, trusted by manufacturers, importers, and distributors to fulfill CRA requirements while ensuring alignment with NIS2, RED, and the Machinery Regulation.
LANGUAGES SPOKEN
EnglishSpanish
HIGHLIGHTS
2 - 9
Employees
2026
Year Founded
Services
Focus
Industries
Clients
Services Provided
80% Cybersecurity Assessments & Hardening
20% Managed IT Services
100% Operational Process Consulting