CRA Vulnerability Management Platform

Designed for EU Cyber Resilience Act (CRA) readiness.

Manage SBOM, HBOM, Vulnerability tracking, CRA Article 14 reporting preparation and audit trail evidence in one structured platform.

Urgent: CRA Article 14 mandatory vulnerability reporting applies from 11 Sep 202624-hour Early Warning · 72-hour Notification · Final ReportArticle 14 violations: up to €15M or 2.5% of worldwide annual turnover, whichever is higher
Urgent Alert

Mandatory CRA vulnerability reporting is fast approaching.

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The obligation covers not only new products, but also products already available on the EU market.

Time remaining:
Until Article 14 reporting becomes mandatory
DAYS
HOURS
MINUTES
SECONDS
2026 / 09 / 11 · Article 14
24 hoursSubmit an Early Warning
72 hoursSubmit a complete Notification
Final ReportSubmit the final report within the applicable remediation or incident deadline

CRA penalty thresholds

Actual penalties are determined by competent authorities in each Member State based on the circumstances.

Articles 13/14 and essential cybersecurity requirementsUp to €15M or 2.5% of worldwide turnoverWhichever is higher; Article 14 reporting violations fall under this tier.
Other specified CRA obligationsUp to €10M or 2%Based on the preceding financial year, whichever is higher.
Incorrect, incomplete or misleading informationUp to €5M or 1%Applies to information provided to notified bodies or market surveillance authorities.
OneCRA Platform

Connect products, vulnerabilities, workflows and evidence in one view.

Bring product portfolios, vulnerability cases and CRA reporting into one consistent workspace, so every role can see status and next actions at a glance.

OneCRA product security management dashboard
OneCRA vulnerability case handling and Article 14 workflow
OneCRA CRA Article 14 notification and reporting interface
Actual OneCRA interface; data shown is for demonstration.
Manufacturer pain points

Manufacturers do not need another vulnerability list.

The real challenge is organizing products, teams, technical data and regulatory deadlines into a sustainable operating process.

01

Too many products and versions to determine impact

The same component may appear across models, versions and markets; manual comparison leaves gaps.

Link products, versions, SBOMs and CVEs.
02

Scattered data creates endless cross-team follow-up

R&D, PSIRT, regulatory and quality teams work across spreadsheets, email, tickets and folders.

Create one source of truth for cases and evidence.
03

Searching for evidence only after the clock starts

Risk decisions, product impact, remediation progress and evidence are not continuously retained.

Maintain a reporting-ready evidence chain.
04

Need the right tool, but worry about sensitive product data

SBOMs, undisclosed vulnerabilities and product information are highly sensitive and must follow enterprise IT and data policies.

Choose isolated cloud tenancy or dedicated on-premises deployment.
WhyOneCRA

Complete, intuitive, and secure by architecture.

OneCRA does not simply digitize forms—it embeds real product security operations into the platform.

01 · COMPLETE

Complete Management

Centrally manage products, models, versions, SBOM/HBOM, vulnerabilities, PSIRT cases, evidence and CRA reporting readiness.

One platform connecting the complete workflow.
02 · INTUITIVE

Intuitive Experience

Designed around how product, R&D, PSIRT and regulatory teams actually work, turning complex requirements into clear steps.

See the next action at a glance.
03 · SECURE

Secure Isolation

Choose cloud tenant isolation or dedicated on-premises deployment, with role-based access, login and transport protection.

Customers retain control of data and access.
One-stop CRA lifecycle

Beyond testing, CRA requires complete product lifecycle management.

CRA does not end when the test report is complete. The One and OneCRA support products from development through market launch and ongoing vulnerability management.

1

Secure by Design

Consultants help establish risk analysis, security requirements, technical documentation and development processes.

2

Product Cybersecurity Testing

The One testing team verifies product cybersecurity requirements and technical measures.

3

Global Market Certification

Integrate regulatory and certification routes to support entry into global markets.

4

Vulnerability Management & Reporting

OneCRA continuously monitors vulnerabilities, manages PSIRT cases, preserves evidence and prepares notifications.

From development to post-market operations—all in one.
Security by architecture

Customers control their data; OneCRA provides the system and workflow.

Whether deployed in the cloud or on premises, OneCRA protects enterprise product information through clear data boundaries, roles and access procedures.

The OneCRA team has no default access to customer business data. Any support access requires established procedures and explicit customer authorization.

OneCRA Cloud

Deploy quickly with less operational overhead.

  • AWS-managed environment
  • Multi-tenant data and permission isolation
  • RBAC, login and data-in-transit protection

OneCRA On-Premises

For enterprises prioritizing data sovereignty and internal deployment policies.

  • Deployed on a dedicated customer-designated server
  • Data remains in the customer-managed environment
  • Customer controls networks, accounts and access permissions
Why The One

Professional support at every stage of the CRA lifecycle.

From product design and process establishment through laboratory testing and market certification to ongoing post-market maintenance, The One and OneCRA connect the entire service lifecycle.

PRODUCT DEVELOPMENTProduct Design & Process Establishment
PRE-MARKETTesting & Market Certification
POST-MARKETPost-market Maintenance
01 · CONSULTANCY

Core Consulting Team

Establish Secure by Design, risk analysis, security requirements, technical documentation and product security procedures.

Product Design & Process Establishment
02 · TESTING

Product Cybersecurity Testing

A laboratory team experienced in products and regulation verifies cybersecurity requirements and technical measures.

Pre-market Testing
03 · GLOBAL CERTIFICATION

Global Certification

Integrate regulatory and certification routes across markets, helping products demonstrate conformity and enter global markets.

Pre-market Certification
04 · SOFTWARE

OneCRA Software Platform

Continuously manage products, SBOMs, vulnerabilities, PSIRT cases, remediation evidence and Article 14 reporting.

Continuous Post-market Maintenance
Different companies, different paths

Different company sizes and product types require different implementation paths.

The following anonymized scenarios show how OneCRA provides a common platform while The One configures services around product complexity, organizational workflows and data policies.

USE CASE 01

Long-lifecycle Professional Equipment Manufacturer

10–20 year support life · Industrial/medical equipment · Long-term maintenance

Before

Products remain on the market while critical security data may disappear over time

  • Product versions, SBOMs and technical documentation are stored separately
  • Staff and system changes create gaps in historical records
  • Vulnerability decisions and remediation evidence are difficult to reconstruct years later
After

Preserve complete product security records through the end of the support period

  • Centrally retain products, versions, SBOMs and documents for the long term
  • Continuously retain cases, decisions, remediation and communication history
  • Retrieve audit and reporting evidence quickly, even years later
Service package: OneCRA long-term data retention + SBOM/version management + vulnerability monitoring + PSIRT evidence chain
USE CASE 02

Large Multi-product Electronics Brand

Multiple BUs · Many models and versions · Group governance

Before

Every team is working, but management lacks the full picture

  • Different spreadsheets and rules across BUs
  • The same vulnerability is analyzed repeatedly
  • Headquarters lacks portfolio-wide risk visibility
After

Preserve BU flexibility while creating group-wide visibility

  • Multi-tenant architecture and RBAC isolate BU data
  • Unified vulnerability, evidence and reporting framework
  • Portfolio risk visibility for management
Service package: CRA Gap Assessment + enterprise access/data architecture + OneCRA Cloud/On-Premises + global certification support
USE CASE 03

Global Smart Product Brand

Integrated hardware/software · Global markets · Multi-tier supply chain

Before

Disconnected supplier, component and product data makes impact difficult to trace

  • Upstream suppliers and third-party components lack a unified registry
  • Components are difficult to link to products, versions and sales markets
  • Downstream customer notifications and vulnerability handling are fragmented
After

Trace and control the supply chain from upstream production to downstream customers

  • Create a supplier registry with component responsibility records
  • Connect suppliers, components, products, versions and markets
  • Support downstream customer notification, PSIRT collaboration and CRA evidence
Service package: Supplier registry + SBOM/HBOM implementation + supply-chain vulnerability monitoring + OneCRA + testing and consultancy

The complete CRA lifecycle,
handled by The One.

From Secure by Design, product cybersecurity testing and global certification to OneCRA vulnerability management and reporting readiness—we help you build the complete solution.

Book a OneCRA Demo