STALE MEASUREMENTNewest real-model measurement: 26 days old, measured with v0.32.0; 7 releases have shipped since, past this project’s own 7-day window. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart

STALE CLOCKThe regulatory entries on this page were last checked against their primary sources on 39 days before this build’s anchor of , past this project’s own 30-day window. Every date here was true when it was read and has not been re-read since. Verify against the primary source before relying on it. The clock, with every source

Regulation (EU) 2024/2847

EU Cyber Resilience Act 2024/2847

The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements. For Provael the relevant story is its own software-security posture - SBOM, coordinated vulnerability handling, secure-by-default, and a defined support period - not the policy-attack result.

Also on this instrument: CRA incident reporting: the first 24 hours → What a manufacturer owes, and when, once an exploited vulnerability is reported to them — the Article 14 clock, what has to be in place before it can be met, and why products already on the EU market are in scope for reporting even when they are out of scope for the requirements.

Reporting obligations (Art. 14) apply 11 September 2026; full application 11 December 2027.Evidence, not certification.
What it is

The framework

  • Regulation (EU) 2024/2847 imposes security-by-design, vulnerability handling and reporting duties on products with digital elements placed on the EU market.
  • It mandates an SBOM, coordinated vulnerability disclosure, and security updates over a defined support period.
  • Reporting duties phase in ahead of full application.
The hook

Where a red-team result fits

Vulnerability handling

A coordinated vulnerability-disclosure process and an SBOM are baseline expectations - Provael ships both, and publishes a security.txt.

What Provael maps to it

Evidence produced

  • An SBOM published with each release.
  • A coordinated vulnerability-disclosure policy and RFC 9116 security.txt.
  • Secure-by-default posture: no telemetry and no network egress by default.
Timing

Dates (verified 26 Jul 2026)

Reporting obligations (Art. 14) apply
11 September 2026
Full application
11 December 2027
How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.