Skip to content
View Cyber-Resilience-Act's full-sized avatar

Block or report Cyber-Resilience-Act

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
.github/profile/README.md

Cyber Resilience Act

Independent open tools, examples, and implementation guidance for software teams preparing for the EU Cyber Resilience Act.

Published by CRA Direct.

This organization is not affiliated with, endorsed by, or operated by the European Union, ENISA, any CSIRT, or any market surveillance authority.

CRA Direct helps manufacturers of products with digital elements operate the regulated parts of CRA readiness:

  • SBOM evidence collection and validation
  • vulnerability intelligence and affectedness review
  • VEX and human-in-the-loop decision workflows
  • Article 14 vulnerability and severe-incident reporting
  • 24-hour, 72-hour, final-report, and intermediate-report deadline tracking
  • audit evidence and non-repudiation
  • service-key automation for CI/CD integrations

Start Here

  • Stateless SBOM Scanner Demo: try CRA Direct's stateless scanner against an SBOM or PURL list.
  • CRA SBOM Validator: validate CycloneDX and SPDX JSON SBOMs using bundled offline schemas.
  • CRA API Examples: integrate SBOM upload, stateless scanning, and workflow creation.
  • CRA Direct Docs: read the public product, workflow, evidence, and audit model.

What We Publish

This organization publishes practical developer and compliance resources derived from the CRA Direct platform:

  • public documentation
  • API examples
  • validation utilities
  • demo applications
  • CRA readiness templates
  • reference workflows

Commercial Support

CRA Direct is available as a hosted SaaS and consulting service for software manufacturers preparing for the EU Cyber Resilience Act.

Use it when you need:

  • persistent SBOM evidence and product-version records
  • continuous vulnerability monitoring
  • human review and approval workflows
  • Article 14 reporting operations
  • notifications and deadline management
  • verifiable audit trails
  • implementation support for product-security and compliance teams

Contact: contact@cra-direct.fr

Positioning

The public repositories help teams validate SBOMs, test stateless scanning, and understand CRA-oriented operating models. The hosted CRA Direct product adds the persistent system of record: products, versions, evidence, review cases, Article 14 workflows, notifications, and audit trails.

Popular repositories Loading

  1. .github .github Public

    Open Cyber Resilience Act tools and implementation guidance by CRA Direct.

    1

  2. cra-sbom-validator cra-sbom-validator Public

    Offline CycloneDX and SPDX SBOM validator for Cyber Resilience Act readiness.

    TypeScript 1

  3. cra-api-examples cra-api-examples Public

    API examples for CRA Direct SBOM upload, stateless scanning, and Article 14 workflow creation.

    1

  4. cra-direct-docs cra-direct-docs Public

    Public CRA Direct documentation for SBOM evidence, Article 14 workflows, HITL review, and audit trails.

    1

  5. Cyber-Resilience-Act.github.io Cyber-Resilience-Act.github.io Public

    CRA Direct helps software manufacturers operationalize Cyber Resilience Act readiness: SBOM evidence, vulnerability triage, Article 14 workflows, human review, notifications, and audit trails.

    HTML 1

  6. cra-stateless-scanner-demo cra-stateless-scanner-demo Public

    JavaScript 1