Six modules in the order the work happens: register, know what is inside, watch, report, document, prove.
Product registry and scope wizard
Register each product once. The wizard walks the Act’s scope questions and product classes and records the answer with its reasoning, including an honest “uncertain, seek advice” outcome.
Default, important class I and II, and critical products; legacy products placed on the market before 11 December 2027.
SBOM and vulnerability operations
Upload SBOMs from CI. Components are matched against vulnerability feeds every day; a finding keeps its identity across releases, so triage and VEX statements survive the next upload.
CycloneDX 1.4 to 1.7 and SPDX 2.3; matched against OSV, KEV, EUVD and EPSS.
Article 14 reporting desk
When an actively exploited vulnerability or a severe incident surfaces, open a case and the clocks start. Guided forms mirror the Single Reporting Platform field by field, and every submission is recorded with its timestamps.
24 hours for the early warning, 72 hours for the notification, 14 days for the final report on a vulnerability (one month for an incident).
Technical file and declaration of conformity
An Annex VII-structured workspace with editable drafts, evidence coverage per section, approvals and versioned exports. Every generated document says it is a draft until you have reviewed it.
Annex VII structure, Annex V declaration; tagged PDF, Markdown and ZIP exports.
CSAF advisories
Publish machine-readable advisories with a human-readable page, an index that CSAF consumers can discover, and the contact files the Act and RFC 9116 expect.
CSAF 2.0 with provider-metadata.json, security.txt and a coordinated-disclosure policy.
Ten-year evidence ledger and public trust page
Every release, update, advisory, support period and filing is appended to a hash-chained ledger. A public trust page per product shows customers and authorities what you publish, and expiring share links open the record to auditors.
Append-only, kept for ten years: the retention period the Act sets for technical documentation.