Product security and CRA workflows for software and connected products sold in the EU

Product security. Evidence ready.

Know what’s exposed, what to report, and what evidence you can produce.

Vellaci connects products, SBOMs, vulnerability decisions, incidents and CRA reporting for software and connected-product manufacturers — including US teams preparing to sell into the EU.

Free preliminary assessment · 16 questions · no account, no credit card · then a personalised gap map

24h then 72h

Article 14 clocks, computed from a confirmed awareness time — in force since 11 September 2026

app.vellaci · OverviewCRA case — 17h 42m remaining
Products requiring attention
ProductSBOMOpenExploited
EdgeGate RouterYes141
DeviceHub DesktopYes60
SensorLink FirmwareMissing——
Early warning deadline
17h 42m
CRA-0007 · CVE-2026-xxxxx · awareness 09:15 CEST
Vulnerability · CVE-2026-xxxxxPotentially reportable
Component
lodash 4.17.20
CVSS · EPSS
9.8 · 94%
Exploitation signal
CISA KEV
Fixed in
4.17.21
Illustrative workspace. Values shown are examples, not customer data.

CycloneDX, SPDX, OSV, CISA KEV, EPSS, GitHub Advisories, ENISA SRP, EU CRA 2024/2847, NIS2, IEC 62443

What you get

Three answers your board, your auditor and your CSIRT will ask for.

The Cyber Resilience Act turns product security into questions with deadlines. Vellaci is built so each one has an answer with a name, a timestamp and evidence behind it.

What is exposed?

Every supported product version has an SBOM; every component is matched continuously against OSV, GitHub advisories, CISA KEV and EPSS, so exposure is a query, not a project.

What must we report?

A named reviewer confirms awareness and reportability with a rationale; the 24-hour, 72-hour and final-report clocks start from that decision and never from a ticket timestamp.

What evidence can we produce?

Decisions, submissions, drills and documents are recorded in a checksummed evidence vault and a hash-chained audit log, exportable at any time.

What happens after the assessment

One path from gap map to a running compliance workflow.

No mystery steps. Each stage has a named deliverable and a decision point where you can stop.

  1. Step 1 · today
    Assessment

    Sixteen questions. You get a preliminary scope, a gap map by area, urgency and the evidence you would need — banded, not scored.

    Start the assessment
  2. Step 2 · this week
    Readiness review

    A 20-minute call with a Vellaci operator: which two or three gaps matter most, and whether Vellaci fits. If it does not, you leave with the map.

    Book the review
  3. Step 3 · weeks 1–6
    Implementation

    Vellaci Readiness (from €4,900) or Implementation (from €9,500): scope, products, SBOMs, workflows, runbook, drill and evidence baseline configured in your own workspace.

    See deliverables and exclusions
  4. Step 4 · from handoff
    Subscription

    The same workspace continues on the Readiness, Growth or Enterprise plan: continuous matching, deadlines, evidence and audit log keep running.

    Compare plans
  5. Step 5 · ongoing
    Compliance workflow

    SBOM per release, triage with reasons, reportability reviews, quarterly drills, documentation maintained per product — evidenced as you go.

    See the running workflow

Regulatory status

The reporting clock is measured in hours, not quarters.

CRA Article 14 reporting obligations apply from 11 September 2026. The CRA’s general application date is 11 December 2027. For qualifying events, manufacturers send an early warning within 24 hours of awareness, a notification within 72 hours, and a final report under the applicable event-specific trigger. Spreadsheets, chat threads and shared drives do not survive that timeline.

24h

Early warning

Awareness starts the clock. Vellaci computes the deadline server-side from a human-confirmed awareness time, in your timezone.

72h

Notification

Structured fields with required, recommended and missing indicators, prefilled from facts you already recorded.

14d

Final report

For an exploited vulnerability, 14 days after a corrective measure is available; for a severe incident, one month after the notification. Two triggers, never a blind 30 days.

Summary of Article 14(2)–(5) and Article 71 of Regulation (EU) 2024/2847. Read the full reporting timeline with sources.

How Vellaci works

One operational chain from dependency to evidence.

Every record connects back to a product and an organisation. Nothing lives in a disconnected checklist.

  1. 01Product registry
  2. 02Product versions
  3. 03SBOM ingestion
  4. 04Component catalogue
  5. 05Vulnerability intelligence
  6. 06Human triage & CRA review
  7. 07Incident & reporting case
  8. 08Deadlines, remediation, evidence

Who Vellaci is for

Manufacturers placing products with digital elements on the EU market.

Vellaci is built for the teams that own product security and CRA operations at software and connected-product manufacturers: security engineering, product management, compliance and the assigned representative for Article 14 reporting. Each segment has its own page with the obligations that matter most.

Software manufacturers

Applications, operating systems, developer tooling and on-premise software shipped to EU customers, with SBOMs generated per release.

Connected and IoT products

Devices with firmware, companion apps and cloud dependencies; support periods measured in device lifetimes.

Industrial and embedded products

Controllers, gateways and machinery with digital elements, often already aligned with IEC 62443.

Network and security products

Routers, VPNs, firewalls, identity and SIEM products — important products under Annex III with heightened obligations.

Product overview

Built for the team that has to answer “which products are exposed?” in under a minute.

CRA Reporting Command Center

Live 24h/72h/final-report clocks, staged forms, submission-ready summaries, recorded SRP submissions with evidence, and immutable revisions.

Product Registry

Lifecycle, classification with reasoning and approver, owners, support periods, versions, repositories and every linked record.

SBOM & vulnerability intelligence

CycloneDX and SPDX parsing, deduplicated components, matching against OSV and GitHub advisories, enriched with CISA KEV and EPSS.

Incident management

Separate incident records with explicit awareness timestamps, reportability review and a direct path into a reporting case.

Evidence vault & audit trail

Private, checksummed evidence with review dates; an append-only audit log recording who changed which decision and when.

Readiness framework

A configurable CRA requirement framework with weighted operational readiness — never presented as a legal certification.

The readiness review

What you hold in your hands after the review.

The free assessment produces a preliminary version of this map. The 20-minute readiness review turns it into a prioritised plan; Vellaci Readiness implements it with you.

CRA readiness review · gap mapIllustrative example — redacted, not a customer document
Preliminary scope
Likely manufacturer · 3 products on the EU market
Operational readiness
38%
  • CRA reporting readiness25%
    No awareness rule; representative not named
  • Vulnerability handling50%
    Scanner in place; no triage reasons or owners
  • SBOM coverage67%
    2 of 3 supported versions have an SBOM
  • Incident process33%
    Ad-hoc; no reportability review
  • Support period0%
    Not defined per product
  • Technical documentation40%
    Scattered across wiki and drive
Highest-risk missing capability
24-hour early warning cannot be produced

Nobody is assigned to confirm awareness; no ENISA platform access holder; no rehearsed template.

First three actions
  1. Name the assigned representative and define the awareness rule
  2. Generate an SBOM for the third supported version and match it
  3. Run a 24-hour reporting drill and file the drill report as evidence
Recommended path
Vellaci Readiness (from €4,900) → Readiness plan
Illustrative example. Percentages, products and findings are invented to show the format of the review output; the free assessment produces your own preliminary version of this map.

Implementation

Software-assisted implementation, not a self-serve gamble.

Vellaci operators configure your workspace with you — scope, products, SBOMs, workflows, contacts and evidence structure — so your team becomes autonomous quickly. The one-time engagement ends with a live workspace; the platform subscription keeps it running.

Vellaci Readiness

from €4,900
  • CRA scope assessment
  • Organisation configuration
  • Product inventory
  • SBOM ingestion
  • Vulnerability workflow
  • Incident workflow
  • Reporting readiness
  • Evidence structure
  • Team configuration
  • Initial readiness review

Vellaci Implementation

from €9,500
  • Everything in Readiness
  • Multiple products
  • Integrations
  • Product-security processes
  • Evidence migration
  • Remediation workflows
  • Policies and templates
  • Technical documentation workspace
  • Implementation support

Typical timeline for Vellaci Readiness

  1. Week 1
    Scope and inventory

    Preliminary scope assessment recorded with reasoning, products imported with owners, lifecycle and classification, repositories connected.

  2. Weeks 2–3
    SBOMs and workflows

    An SBOM for every supported version, vulnerability matching running, triage and incident workflows configured with owners and reasons.

  3. Weeks 3–4
    Reporting readiness

    Assigned representative, awareness rule, runbook and continuity sheet in place; a 24-hour reporting drill run and filed as evidence.

  4. Week 4–6
    Evidence and handover

    Evidence baseline uploaded and linked, readiness review scored against the requirement framework, team trained; the workspace continues on a platform plan.

End state

Every supported product version has an SBOM under continuous matching; vulnerability and incident workflows have owners and recorded reasons; the Article 14 runbook, representative and awareness rule are set and drilled; the evidence baseline is filed; the readiness framework shows where you stand. Timelines depend on portfolio size and your team’s availability.

How it connects to the platform

Implementation is a one-time engagement delivered inside your own Vellaci workspace with time-bound, logged operator access. When it ends, the workspace continues on the Readiness plan (€490/month), Growth (€990/month) or an Enterprise contract — nothing is rebuilt or migrated.

What Vellaci is not

Clear boundaries, so the trust is earned.

We would rather lose a deal than let a slide imply something the product does not do.

Not a certification

Vellaci does not certify CRA conformity and is not a notified body. Conformity assessment and CE marking remain your process, with a notified body where the regulation requires one.

Not legal advice

Scope, classification and reportability are decisions your organisation and its advisers make. Vellaci records the reasoning and the person who decided; it does not decide for you.

Not ENISA or a CSIRT

Official notifications go through the ENISA Single Reporting Platform and reach your coordinator CSIRT. Vellaci prepares, times and evidences them; it does not submit on your behalf.

Not a scanner or a ticketing tool

Keep Dependabot, Snyk, Trivy, Jira or Linear. Vellaci is the system of record that connects their outputs to products on the market, decisions, deadlines and evidence.

Regulatory summaries on this site are operational guidance, not legal advice. Contact: hello@vellaci.ch.

Security

Treated as a security-sensitive system from day one.

Row-level tenant isolation enforced in the database, private storage with short-lived signed URLs, encrypted integration credentials, signature-verified webhooks with replay protection, and an append-only audit log. We do not claim certifications we do not hold.

FAQ

Straight answers.

Does Vellaci make our company CRA compliant?
No product can. Vellaci helps you operationalise CRA requirements: it structures products, SBOMs, vulnerability handling, incident response, reporting preparation and evidence so your team can demonstrate readiness. Legal determinations remain yours and your advisers'; conformity assessment is done by you or a notified body, not by Vellaci.
Does Vellaci submit reports to ENISA?
No. Official notifications are submitted by the manufacturer through the ENISA CRA Single Reporting Platform. Vellaci prepares submission-ready content, tracks the 24-hour, 72-hour and final-report deadlines, and records the submission with evidence and an immutable audit trail.
How does Vellaci decide what is reportable?
It does not. Vellaci surfaces signals such as CISA KEV listings and EPSS, and asks a named reviewer to confirm or reject reportability with a rationale and an explicit awareness timestamp. Deadlines only start after a human confirms.
Where is data stored?
In an EU-hosted Postgres database with row-level tenant isolation, private storage buckets with short-lived signed URLs, and encrypted integration credentials. See the Security page and the Trust Center for the full architecture and the subprocessor register.
Which SBOM formats are supported?
CycloneDX 1.2–1.6 (JSON and XML) and SPDX 2.2–2.3 (JSON and tag/value), including SBOMs exported by GitHub's dependency graph.

Start with a preliminary CRA readiness assessment.

Sixteen questions, about eight minutes. A preliminary scope, your biggest operational gaps and a recommended next step — before we ask for a sales conversation.