Skip to content
deveca GRC
EU Regulation 2024/2847

EU Cyber Resilience Act – CRA ready

The CRA requires manufacturers of connected products to apply security by design, vulnerability management, SBOMs and vulnerability disclosure. deveca brings CRA conformity into your software lifecycle — including SBOM management (CycloneDX/SPDX) and CVSS/CWE scoring.

What deveca delivers for EU Regulation 2024/2847

  • SBOM management according to CycloneDX and SPDX
  • Vulnerability matching against the NVD
  • Scoring based on CVSS and CWE
  • Vulnerability disclosure workflow
  • Conformity documentation for CE marking

Related topics

Cyber Resilience ActCRA complianceSBOMCVSSCWECycloneDX