Regulation (EU) 2024/2847 — Cyber Resilience Act

CRA-compliant,
with no blind spots.

Probenta takes on your CRA vulnerability-management and notification obligations — SBOM, the 24 h / 72 h / 14 d clock, audit-ready records — maintained continuously, ready to show.

Start the CRA self-assessment

Free, about 5 minutes. Your answers stay in your browser until you request your report — privacy.

Regulatory calendar — Regulation (EU) 2024/2847

Today

There are days left before the first deadline.

11 Sept 2026

Mandatory reporting of exploited vulnerabilities

24 h / 72 h / 14 d notification as soon as a vulnerability is actively exploited.

— Art. 14

11 Dec 2027

Full CRA compliance

Sanctions regime: up to €15M or 2.5% of worldwide turnover.

— Art. 64

“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements […]”

Feeds and sources monitored

CISA KEV  ·  CERT-FR  ·  ENISA (EUVD)  ·  NVD

The deadline

December 2027 is closing in. Are your software and connected products really ready?

The CRA is not just another formality. Without compliant marking, a digital product can no longer be placed on the European market — and breaches run into the millions.

€15M
Maximum fines

Up to €15M or 2.5% of worldwide turnover for failing to meet the essential requirements.

24 h
Alert window

Early warning to the coordinating CSIRT and ENISA within 24 hours of an actively exploited vulnerability.

Removal
From the market

A non-compliant product can be denied CE marking — and with it, access to the 27 markets of the Union.

The CRA is 81 dense pages in the Official Journal. Probenta turns them into a clear action plan for your products.
Discover the solution →
The problem

What the CRA requires of you, now.

01

The clock is ticking, you'll be notified in time

An exploited vulnerability triggers a legal countdown (24 h / 72 h / 14 days). Miss it, and it is a sanction.

02

The technical file is a time sink.

Up-to-date SBOM, risk analysis, support period, disclosure: hours of ongoing engineering work.

03

Proving you notified on time.

Without a tamper-proof audit log, demonstrating compliance to the authority is impossible.

The solution

One single data set. Multiple regulatory deliverables.

Evidence baseActive
SBOM
1 247 components tracked
Vulnerability feeds
18 correlated to your fleet
1 actively exploited — Art. 14 notification in progress
CISA KEV · CERT-FR · EUVD · NVDCorrelated 2 min ago

A single entry feeds every deliverable

01 / 04

Article 14 notification

As soon as an exploited vulnerability touches your SBOM, the clock starts. Notification pre-filled, within the deadline.

02 / 04

Annex VII technical file

Generated from the same data, kept up to date, ready for audit.

03 / 04

Disclosure portal

security.txt, intake, triage, public page — hosted.

04 / 04

Audit report

An append-only, tamper-proof log, ready to present to the supervisory authority.

The method

Two layers of assurance. No surprises on audit day.

Probenta layers an exhaustive mapping of your obligations with a living evidence register. If one gives way, the other holds.

01 — MAPPING

Your obligations, translated

No more wading through the regulation: every CRA requirement becomes a traceable obligation, mapped to your products.

02 — EVIDENCE

A file that is always ready

SBOM, risk analyses, tests, technical documentation: everything is centralized, versioned and exportable. The audit file is generated in one click.

03 — MONITORING

The regulation moves, you keep up

Delegated acts, harmonized standards, ENISA guidance: Probenta alerts you as soon as a change affects your scope.

04 — STEERING

One deadline, one owner

A dashboard per product and per milestone. Every stakeholder knows what to deliver, and when. Management sees progress in real time.

Core of the product

Article 14 alarm

The full chain, from detection to proof of notification.

01 · CORRELATION

SBOM ↔ actively exploited vulnerabilities (CISA KEV, CERT-FR)

02 · CLOCK

24 h / 72 h / 14 d, triggered automatically

03 · NOTIFICATION

Pre-filled in the format expected by the coordinating CSIRT and ENISA

04 · PROOF

Append-only audit log — notification within the deadline, demonstrable

Included

Continuous SBOM + CVE correlation

We orchestrate proven open-source tools; continuous monitoring of your product portfolio.

Coming soon

Annex VII technical file

Generated and kept up to date automatically, audit-ready.

Coming soon

Hosted disclosure portal

security.txt, intake, triage, public page.

Security

We never ingest your source code.

Only your SBOM and metadata. Reduced attack surface. Security is part of the product.

SBOM + metadata only

Hosted in the EU

Append-only audit log

GDPR compliant

Compliance

Compliance starts with our own.

Our entire chain — hosting, emailing, processors — is French or European, and GDPR compliant.

01 · HostingFrance

Scaleway

Our solutions are hosted on Scaleway, a French cloud provider, ISO 27001 certified and committed to GDPR.

Scaleway security & certifications →
02 · EmailingFrance

Brevo

Our e-mails are sent through Brevo (Sendinblue SAS), a French company — your data stays hosted in the EU.

Brevo & the GDPR →
03 · ProcessingEU · 2016/679

GDPR end to end

We and all of our processors comply with the GDPR: data minimisation, EU hosting, rights you can exercise at any time.

Read Regulation (EU) 2016/679 →

The details of our processing activities are in our privacy policy.

The team

Two profiles, one obsession: your compliance.

We combine regulatory expertise and software engineering to make the CRA manageable.

Ayoub Tougani

Software engineer and regulatory expert

Passionate about automated processes and sharp on standards and how our world evolves, Ayoub has years of experience in regulatory and medical fields, which he has put to use building cutting-edge applications.

Alexandre Berthiot

Software and cybersecurity engineer

Having worked for over 7 years in the healthcare sector (pharmacy and sleep apnea treatment), Alexandre knows the legal stakes of offering products close to a patient. He is also deeply committed to cybersecurity and has taken part in numerous security-hardening (blue teaming) efforts across various companies.

Contact

Let's talk about your deadline.

A 30-minute demo is enough to see where you stand. We get back to you within 72 business hours.

Based in
Nancy - France
Waitlist

* Required fields

No spam. We'll write when we open. By subscribing you agree we keep your information for this sole purpose — privacy.