Light Squares
Compliance Evidence (CRA / NIS2)

Compliance evidence that's generated, not gathered.

CRA and NIS2 demand due-diligence evidence for the software you ship and the components inside it. Our attestations produce that evidence as a by-product of engineering.

The Challenge

The EU Cyber Resilience Act and NIS2 require due-diligence for third-party components. NIS2 obligations already apply, and the main CRA obligations land in late 2027. Today that evidence is assembled by hand: spreadsheets, vendor questionnaires, screenshots of dashboards. For hundreds of fast-moving dependencies, it simply cannot be produced that way.

A central piece of that evidence is the SBOM, the Software Bill of Materials: a machine-readable inventory of the components inside your product. The CRA requires you to maintain one, but it does not require you to publish it. That distinction matters: handing over a full SBOM exposes internal architecture, IP, and liability surface, so suppliers hold back, and their customers are left unable to react to new threats.

Why It Matters

  • Withheld SBOMs slow incident response down: when a new vulnerability drops, customers wait on their suppliers instead of checking their own inventory.
  • Non-compliance carries real financial and reputational risk, and the deadline is predictable, so auditors will expect preparation.
  • Checkbox evidence is losing value: auditors and enterprise customers increasingly want verifiable artifacts, not attestation letters.

Why It Matters For Your Role

Compliance Manager

  • Export attested audit trails and SBOM evidence mapped to CRA / NIS2 obligations.
  • Evidence is generated by the pipeline on every update, not gathered in spreadsheets each audit cycle.

CISO / Security Lead

  • Hand auditors and customers portable, signed proof that is verifiable without trusting us or you.
  • Turn a compliance deadline into an actual security upgrade, not a paperwork exercise.

AppSec / DevSecOps

  • The evidence falls out of CI, with no extra process for engineering teams.
  • Use the same attestations in CI that you later report: one mechanism, two jobs.

How We Solve This

Confidential SBOMs

Meet SBOM obligations without handing over your SBOM: in high-risk events, customers get attested answers to specific queries they can verify themselves. In development.

Learn More →

Dependency Canary

Attested AI audit trails for your third-party dependencies: the due-diligence evidence CRA and NIS2 ask for, generated on every update.

Learn More →

Attestable Builds

Hardware-attested provenance certificates, ready for SLSA Build L3, that anchor your evidence chain to the artifacts you actually ship.

Learn More →

Let us know how we can help you!

Book a call with our co-founders.