ProductEvidenceTop 10ComplianceDocsStar on GitHubQuickstart
Regulation (EU) 2024/2847

EU Cyber Resilience Act 2024/2847

The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements. For Provael the relevant story is its own software-security posture — SBOM, coordinated vulnerability handling, secure-by-default, and a defined support period — not the policy-attack result.

Reporting obligations (Art. 14) apply 11 September 2026; full application 11 December 2027.Evidence, not certification.
What it is

The framework

  • Regulation (EU) 2024/2847 imposes security-by-design, vulnerability handling and reporting duties on products with digital elements placed on the EU market.
  • It mandates an SBOM, coordinated vulnerability disclosure, and security updates over a defined support period.
  • Reporting duties phase in ahead of full application.
The hook

Where a red-team result fits

Vulnerability handling

A coordinated vulnerability-disclosure process and an SBOM are baseline expectations — Provael ships both, and publishes a security.txt.

What Provael maps to it

Evidence produced

  • An SBOM published with each release.
  • A coordinated vulnerability-disclosure policy and RFC 9116 security.txt.
  • Secure-by-default posture: no telemetry and no network egress by default.
Timing

Dates (verified 6 Jul 2026)

Reporting obligations (Art. 14) apply
11 September 2026
Full application
11 December 2027
How to read this mapping

What it is — and isn’t

  • adversarial-only — Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.
  • evidence-not-certification — The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case — Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.