Light Squares
Compliance Evidence (CRA / NIS2)

Compliance evidence that's generated, not gathered.

CRA and NIS2 demand due-diligence evidence for the software you ship and the components inside it. Our attestations produce that evidence as a by-product of engineering.

The Challenge

The EU Cyber Resilience Act and NIS2 require due-diligence for third-party components, with the main CRA obligations landing in late 2027. Today that evidence is assembled by hand: spreadsheets, vendor questionnaires, screenshots of dashboards. For hundreds of fast-moving dependencies, it simply cannot be produced that way.

SBOMs face the same tension from the other side: the CRA requires you to maintain one, but publishing it exposes internal architecture, IP, and liability surface, so suppliers hold back, and their customers are left unable to react to new threats.

Why It Matters

  • Non-compliance carries real financial and reputational risk, and the deadline is predictable, so auditors will expect preparation.
  • Checkbox evidence is losing value: auditors and enterprise customers increasingly want verifiable artifacts, not attestation letters.
  • Withheld SBOMs slow everyone down: when a new vulnerability drops, customers wait on their suppliers instead of checking their own inventory.

Why It Matters For Your Role

Compliance Manager

  • Export attested audit trails and SBOM evidence mapped to CRA / NIS2 obligations.
  • Evidence is generated by the pipeline on every update, not gathered in spreadsheets each audit cycle.

CISO / Security Lead

  • Hand auditors and customers portable, signed proof that is verifiable without trusting us or you.
  • Turn a compliance deadline into an actual security upgrade, not a paperwork exercise.

AppSec / DevSecOps

  • The evidence falls out of CI, with no extra process for engineering teams.
  • Gate merges on the same attestations you later report: one mechanism, two jobs.

How We Solve This

Confidential SBOMs

Meet SBOM obligations without handing over your SBOM: in high-risk events, customers get attested answers to specific queries they can verify themselves. In development.

Learn More →

Dependency Canary

Attested AI audit trails for your third-party dependencies: the due-diligence evidence CRA and NIS2 ask for, generated on every update.

Learn More →

Attestable Builds

Hardware-attested provenance certificates that meet the highest SLSA levels and anchor your evidence chain to the artefacts you actually ship.

Learn More →

Let us know how we can help you!

Join the early access program or book a call with our co-founders.