Cyber Resilience ActNIS2

Keep every product you shipped CRA‑ready, every day

Shield Lifecycle is a service for software developers, machine builders and system integrators. It guides you to get the EU certificate and keeps it throughout the whole product lifecycle.

Many CRA requirements, one solution.

Getting into the market

EU declaration of conformity for each product

Shield Lifecycle screen of one product version: the completeness checklist, the technical file of Annex VII with each part ready, and the EU declaration of conformity written from what was declared and verified.

The complete process to the CE marking of each product

  • Triage, mapping each essential requirement of Annex I to its evidence
  • SBOM creation with complete CVE, CVSS and KEV
  • Attack surface and automatic CVE assessment using VEX
  • Technical documentation for the CE declaration

You sign the declaration. Shield Lifecycle prepares the evidence.

After the sale

Vulnerability handling for each product, not just for each model

Forty CVEs found in the SBOM of one delivered product meet its reduced attack surface. Thirty-seven cannot reach it and are closed with VEX. Three pass the two open ways in and are exposed.

An automatic process that assesses new vulnerabilities for the whole support period

  1. New CVEs matched against the SBOM of each delivered product
  2. Exposure judged on the real attack surface, not only on the component list
  3. Automatic VEX preparation based on real external exposure
  4. Most CVEs are not exposed and closed silently

Shield Lifecycle keeps you informed on the things that matter.

Mandatory communication and updates

Reports to the CSIRT and notices to your customers

Shield Lifecycle drafts a message to the supplier of an affected component: the CVE, the product version, the assessment so far, and the request for a fixed version and its updated SBOM.
In the picture: a notice to the supplier of an affected component, drafted from the assessment.

Every CRA deadline, with the text already drafted

  • Early warning to the CSIRT and ENISA, within 24 hours
  • Vulnerability notification, within 72 hours
  • Final report, within 14 days of the fix
  • A notice for each affected customer

Article 14 applies to all products, including those already on the market.

The loop

CRA is a loop that runs every day. You need a tool that works for you every day.

  1. Day 0

    EU certificate

    Load the SBOM and the attack surface of each delivered product.

  2. Every day

    Check new CVEs

    New public CVEs are matched against every product.

  3. If not exposed

    Automatic evaluation

    The CVE cannot be reached. A new report is issued. Nobody has to act.

  4. If exposed

    Alert and notify

    The score drops. Your programmer is alerted. The customer notice is drafted.

  5. Compliance

    Prove

    The process is tracked and logged with documented evidence.

The SBOM says what can be attacked. The attack surface says how.

The Edge Shield models together.
Reduce the attack surface

Edge Shield helps you to reduce the risk

A smart SDN switch reduces network visibility. The traffic needed for production is deeply inspected and forwarded. Everything else stays closed.

  • Micro-segmented communication from layer 2 up
  • OT intrusion detection system checks the traffic
  • A switch is generally considered a passive component, and the exposed data plane does not extend the attack surface

Limiting the attack surface is an essential requirement of the CRA (Annex I, Part I, point 2(j)) and part of the risk-management measures that NIS2 (Article 21) asks of essential and important entities.

Discover Edge Shield

Compare

Other tools solve one piece. Shield Lifecycle follows each product you shipped.

Typical capabilities of each category, from public product information, September 2026. Individual products may differ.
CapabilitySBOM / SCA toolsVulnerability scannersGRC platformsOT monitoringConsultant + AI assistant + spreadsheetShield Lifecycle
Checks if the product is in CRA scope
Works per delivered product, not per model
SBOM with hardware and firmware
Component catalogue and supplier SBOMs
Integration with code repositories
Attack surface and reachability per product
CVEs with CVSS and KEV
Automatic assessment with VEX
Article 14 reports (24 h / 72 h)
Notices and portal for your customers
Notices and portal for your suppliers
Documentation for the EU declaration
Most do itSome, or in partRarely or neverTypical capabilities of each category, from public product information, September 2026. Individual products may differ.
Regulations and standards

Where it helps you

  • Built for it
    Cyber Resilience ActRegulation (EU) 2024/2847

    SBOM, vulnerability handling and VEX for every delivered product, Article 14 reports, customer notices and documentation. Article 13, Article 14, Annex I

  • Helps with a part
    Machinery RegulationRegulation (EU) 2023/1230

    Keeps the list of the software of each delivered machine. Annex III, 1.1.9

  • Helps with a part
    NIS2Directive (EU) 2022/2555

    Supply chain security: the plant receives SBOM, VEX and notices from its machine builders. Article 21(2)(d)

  • Helps with a part
    ISO/IEC 27001Standard

    ICT supply chain, on the supplier side.

  • Helps with a part
    NIST Cybersecurity Framework 2.0Framework

    Supply chain risk management.

FAQ

Some questions you might have

Is this a CVE scanner?

No. Matching CVEs to an SBOM is the easy part and many tools do it. Shield Lifecycle judges if each CVE can really be reached on each delivered product, through its ports, protocols and operating states. This judgment is what the VEX format records, and it is the part people cannot do by hand at scale.

What is a VEX?

VEX (Vulnerability Exploitability eXchange) is a short, machine-readable statement that says whether a known vulnerability affects a product: not affected, affected, fixed or under investigation, with the reason. Shield Lifecycle prepares it for each CVE and each delivered product, so you can show why most CVEs need no action.

We do not have an SBOM for our products. Can we start?

Yes. We help you build the first SBOM from the bill of materials of one product model: PLC and HMI firmware, drives, gateways, operating system and libraries. This is the first step of a pilot project.

Does Shield Lifecycle make my product CRA compliant?

No tool can promise that. Under the CRA the manufacturer makes the declaration of conformity. Shield Lifecycle gives you the daily monitoring, the judgments and the evidence you need to support it, and it keeps them up to date for the whole support period.

Do products we shipped years ago fall under the CRA?

The product requirements apply to products placed on the market from 11 December 2027, or substantially modified after that date. The reporting duty of Article 14 is different: it has applied since 11 September 2026 and it also covers products already on the market. So you need to know what is inside the products you already shipped.

Where is the data stored?

All data is stored on servers in the European Union. Today in our cloud, in pilot projects. A version that you install on your own server is coming, first for large manufacturers who keep product data in their own systems.

Who pays, the manufacturer or the end customer?

The manufacturer subscribes and gives each end customer access to their own products. Contact us for a quote based on your number of product models and customers.

Last updated

See a critical CVE hit a machine

We show you the moment that matters: a new vulnerability lands. One machine is exposed and the other is not. The customer notice is ready to send.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026