The platform

Cyber Resilience Act (CRA)

Support for CRA-related vulnerability requirements.

The CRA with VulnDex

  • Continuous monitoring of our own products with digital elements.
  • Centralised processing of reported vulnerabilities.
  • Documented measures and a transparent process.

Operational vulnerability management in the CRA context

The Cyber Resilience Act specifies requirements for the monitoring and management of vulnerabilities in products with digital elements. VulnDex supports the operational implementation of these requirements in the area of vulnerability management.

Managing products and versions.
Products with digital elements are managed by version. Vulnerabilities can be attributed to specific versions, and activities over time can be tracked.
Single point of contact for reporting vulnerabilities
The single point of contact for receiving vulnerability reports displays the managed products and assigns the report directly to the relevant team.
View of a reported vulnerability.
Reviews, actions and status changes are recorded in a structured manner. Actions are documented in a way that allows them to be traced within the context of the product.

SBOM monitoring

SBOM monitoring continuously checks top-level software dependencies for known vulnerabilities. Any vulnerabilities detected in dependencies are displayed directly alongside the affected product.

Version-based tracking

Vulnerabilities are assigned to a specific product version. This ensures that it is transparent which version is affected and what measures have been implemented.

Documented activities

Action steps taken in response to identified vulnerabilities are stored centrally. This ensures that there is clear documentation for every product.

Publication of security advisories

Security advisories regarding vulnerabilities in a company’s own products can be published in the CSAF format.

Let’s achieve more together!

Support the operational vulnerability management of your products in the context of the Cyber Resilience Act.

Security made in Austria

  • Sovereign cloud architecture
    Operated on servers in Austria in collaboration with European partners
  • Privacy according to European standards
    Responsible handling of personal data
  • Certified cyber security from AustriaSecurity from Austria
    Certification in accordance with the Cyber Trust Austria® Standard Label

Request a demo

See how VulnDex can help you manage vulnerabilities.

Information on the processing of your personal data can be found in the Privacy Policy.