Compliance evidence that's generated, not gathered.
CRA and NIS2 demand due-diligence evidence for the software you ship and the components inside it. Our attestations produce that evidence as a by-product of engineering.
The Challenge
The EU Cyber Resilience Act and NIS2 require due-diligence for third-party components. NIS2 obligations already apply, and the main CRA obligations land in late 2027. Today that evidence is assembled by hand: spreadsheets, vendor questionnaires, screenshots of dashboards. For hundreds of fast-moving dependencies, it simply cannot be produced that way.
A central piece of that evidence is the SBOM, the Software Bill of Materials: a machine-readable inventory of the components inside your product. The CRA requires you to maintain one, but it does not require you to publish it. That distinction matters: handing over a full SBOM exposes internal architecture, IP, and liability surface, so suppliers hold back, and their customers are left unable to react to new threats.
Why It Matters
- Withheld SBOMs slow incident response down: when a new vulnerability drops, customers wait on their suppliers instead of checking their own inventory.
- Non-compliance carries real financial and reputational risk, and the deadline is predictable, so auditors will expect preparation.
- Checkbox evidence is losing value: auditors and enterprise customers increasingly want verifiable artifacts, not attestation letters.
Why It Matters For Your Role
Compliance Manager
- Export attested audit trails and SBOM evidence mapped to CRA / NIS2 obligations.
- Evidence is generated by the pipeline on every update, not gathered in spreadsheets each audit cycle.
CISO / Security Lead
- Hand auditors and customers portable, signed proof that is verifiable without trusting us or you.
- Turn a compliance deadline into an actual security upgrade, not a paperwork exercise.
AppSec / DevSecOps
- The evidence falls out of CI, with no extra process for engineering teams.
- Use the same attestations in CI that you later report: one mechanism, two jobs.
How We Solve This
Confidential SBOMs
Meet SBOM obligations without handing over your SBOM: in high-risk events, customers get attested answers to specific queries they can verify themselves. In development.
Learn More →Dependency Canary
Attested AI audit trails for your third-party dependencies: the due-diligence evidence CRA and NIS2 ask for, generated on every update.
Learn More →Attestable Builds
Hardware-attested provenance certificates, ready for SLSA Build L3, that anchor your evidence chain to the artifacts you actually ship.
Learn More →Let us know how we can help you!
Book a call with our co-founders.

