Cyber Resilience Act compliance workspace

The permanent product-security record for the EU market.

Permenta is where makers of software and connected products do what the Cyber Resilience Act asks of them, and keep the proof: product registry and scope, SBOMs and their vulnerabilities, Article 14 reports filed against the clock, the technical file, advisories, and a record you can hand to a customer or an authority ten years from now.

Permenta is opening to its first customers now. Free for one product; no card needed.

A stack of ruled paper sheets held down by one bronze seal.

Regulation (EU) 2024/2847

Two dates every maker of a product with digital elements now works to

The Cyber Resilience Act applies to products placed on the EU market wherever the maker sits. There is no size exemption.

  • Article 14 reporting applies: actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT within 24 hours, 72 hours and 14 days or one month. It covers products already on the market.

  • The Act applies in full: Annex I secure-by-design requirements, an SBOM, vulnerability handling, a support period, the technical documentation of Annex VII, the EU declaration of conformity and CE marking.

  • Technical documentation and the declaration are kept for ten years or the support period, and each security update stays available for ten years or the remainder of the support period.

What you get

Six modules in the order the work happens: register, know what is inside, watch, report, document, prove.

Product registry and scope wizard

Register each product once. The wizard walks the Act’s scope questions and product classes and records the answer with its reasoning, including an honest “uncertain, seek advice” outcome.

Default, important class I and II, and critical products; legacy products placed on the market before 11 December 2027.

SBOM and vulnerability operations

Upload SBOMs from CI. Components are matched against vulnerability feeds every day; a finding keeps its identity across releases, so triage and VEX statements survive the next upload.

CycloneDX 1.4 to 1.7 and SPDX 2.3; matched against OSV, KEV, EUVD and EPSS.

Article 14 reporting desk

When an actively exploited vulnerability or a severe incident surfaces, open a case and the clocks start. Guided forms mirror the Single Reporting Platform field by field, and every submission is recorded with its timestamps.

24 hours for the early warning, 72 hours for the notification, 14 days for the final report on a vulnerability (one month for an incident).

Technical file and declaration of conformity

An Annex VII-structured workspace with editable drafts, evidence coverage per section, approvals and versioned exports. Every generated document says it is a draft until you have reviewed it.

Annex VII structure, Annex V declaration; tagged PDF, Markdown and ZIP exports.

CSAF advisories

Publish machine-readable advisories with a human-readable page, an index that CSAF consumers can discover, and the contact files the Act and RFC 9116 expect.

CSAF 2.0 with provider-metadata.json, security.txt and a coordinated-disclosure policy.

Ten-year evidence ledger and public trust page

Every release, update, advisory, support period and filing is appended to a hash-chained ledger. A public trust page per product shows customers and authorities what you publish, and expiring share links open the record to auditors.

Append-only, kept for ten years: the retention period the Act sets for technical documentation.

Who it is for

Teams of five to two hundred who ship products with digital elements into the EU, use GitHub or GitLab, and have no compliance department.

  • Downloadable software
  • Mobile and desktop apps
  • Plugins and extensions
  • Self-hosted software
  • Firmware and connected devices

Based outside the EU? The Act applies to products placed on the EU market wherever the maker sits, and exporters are the least served by EU-local vendors. Permenta is built with you in mind: prices in euro or dollars, Article 14 guidance written for a first-time reporter, and a public trust page that answers your European customers before they ask.

Agencies and consultancies serving several such clients get separate workspaces per client on the Scale plan.

Pricing

A free workspace for one product, then Starter, Growth and Scale in euro or US dollars, monthly or annual. Prices exclude VAT; paid plans start with a 14-day trial.

Free

Your first product, on the record.

€0 or $0 forever

  • 1 product
  • 2 members
  • 1 SBOM upload per month
  • Public trust page and security.txt
  • Scope wizard and obligations checklist
  • Disclosure-policy generator
  • Article 14 dry run

Starter

A small catalogue with live monitoring.

€99 or $99 per month

€990 or $990 per year

  • 3 products
  • 5 members
  • Unlimited SBOM uploads
  • Continuous vulnerability monitoring
  • Article 14 reporting desk
  • Advisory and technical-file drafts
  • Security advisories (CSAF 2.0)
  • API keys and CLI

Scale

Whole portfolios and agencies.

€799 or $799 per month

€7,990 or $7,990 per year

  • Unlimited products
  • Unlimited members
  • Everything in Growth
  • Agency workspaces
  • Audit exports
  • Priority support

Prices exclude VAT, which is charged where the law requires it; businesses in the EU with a VAT number are invoiced under the reverse-charge mechanism. Paid plans start with a 14-day trial, renew automatically and can be cancelled for the end of the paid period from the workspace’s billing settings. Payment is by card through Stripe; invoices are issued electronically. See the cancellation and refund policy and the terms of service.

What Permenta is not

Permenta provides tooling and evidence management; it does not certify compliance. Whether a product meets the Act’s requirements is your assessment, or your notified body’s. Permenta makes the work easier to do and the evidence easier to keep and show. Nothing on this site is legal advice.

Contact

Permenta is operated by Patchgate, LLC, a United States company, doing business as Permenta. We answer within two business days.

General and sales
hello@permenta.com
Billing
hello@permenta.com, subject “Billing”
Security reports
security@permenta.com (see our disclosure policy)
Privacy requests
privacy@permenta.com
Operator
Patchgate, LLC, doing business as Permenta
United States
Website
permenta.com