STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
Regulation (EU) 2024/2847

EU Cyber Resilience Act 2024/2847

The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements. For Provael the relevant story is its own software-security posture - SBOM, coordinated vulnerability handling, secure-by-default, and a defined support period - not the policy-attack result.

Also on this instrument: CRA incident reporting: the first 24 hours → What a manufacturer owes, and when, once an exploited vulnerability is reported to them — the Article 14 clock, what has to be in place before it can be met, and why products already on the EU market are in scope for reporting even when they are out of scope for the requirements.

Reporting obligations (Art. 14) apply 11 September 2026; full application 11 December 2027.Evidence, not certification.
What it is

The framework

  • Regulation (EU) 2024/2847 imposes security-by-design, vulnerability handling and reporting duties on products with digital elements placed on the EU market.
  • It mandates an SBOM, coordinated vulnerability disclosure, and security updates over a defined support period.
  • Reporting duties phase in ahead of full application.
The hook

Where a red-team result fits

Vulnerability handling

A coordinated vulnerability-disclosure process and an SBOM are baseline expectations - Provael ships both, and publishes a security.txt.

What Provael maps to it

Evidence produced

  • An SBOM published with each release.
  • A coordinated vulnerability-disclosure policy and RFC 9116 security.txt.
  • Secure-by-default posture: no telemetry and no network egress by default.
Scope

Who this binds

Does this apply to Provael itself? We do not publish an answer, because we have not taken advice and a compliance page that guesses is worth less than one that says where the line is. Manufacturer obligations turn on whether a product with digital elements is made available on the EU market in the course of a commercial activity. Provael’s core is Apache-2.0 and free, paid assessments are offered against it at listed prices, none has sold, and there is no legal entity. Whether that combination is commercial activity for the purposes of the Regulation is genuinely arguable, and we would rather say so than pick the reading that suits us.

One part is not arguable. An open-source software steward under Article 3(14) must be a legal person. There is no entity here, so the Article 24 steward obligations, which start on the same 11 September 2026 date, do not attach on that basis. If an entity is incorporated, this changes with it.

Does it apply to you? If you integrate Provael into a product that is itself in CRA scope, the reporting duty is yours. Provael evidences one narrow thing — whether a learned policy behaves unsafely under adversarial instruction or observation, measured with a control arm — and it does not discharge any reporting obligation or produce a CRA notification.

Timing

Dates (verified 19 Aug 2026)

Reporting obligations (Art. 14) apply
11 September 2026
Full application
11 December 2027
How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.