CRA Vulnerability Management Platform
Designed for EU Cyber Resilience Act (CRA) readiness.
Manage SBOM, HBOM, Vulnerability tracking, CRA Article 14 reporting preparation and audit trail evidence in one structured platform.
From design, testing and certification to vulnerability reporting, all in one.
Mandatory CRA vulnerability reporting is fast approaching.
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The obligation covers not only new products, but also products already available on the EU market.
CRA penalty thresholds
Actual penalties are determined by competent authorities in each Member State based on the circumstances.
Connect products, vulnerabilities, workflows and evidence in one view.
Bring product portfolios, vulnerability cases and CRA reporting into one consistent workspace, so every role can see status and next actions at a glance.



Manufacturers do not need another vulnerability list.
The real challenge is organizing products, teams, technical data and regulatory deadlines into a sustainable operating process.
Too many products and versions to determine impact
The same component may appear across models, versions and markets; manual comparison leaves gaps.
Link products, versions, SBOMs and CVEs.Scattered data creates endless cross-team follow-up
R&D, PSIRT, regulatory and quality teams work across spreadsheets, email, tickets and folders.
Create one source of truth for cases and evidence.Searching for evidence only after the clock starts
Risk decisions, product impact, remediation progress and evidence are not continuously retained.
Maintain a reporting-ready evidence chain.Need the right tool, but worry about sensitive product data
SBOMs, undisclosed vulnerabilities and product information are highly sensitive and must follow enterprise IT and data policies.
Choose isolated cloud tenancy or dedicated on-premises deployment.
Complete, intuitive, and secure by architecture.
OneCRA does not simply digitize forms—it embeds real product security operations into the platform.
Complete Management
Centrally manage products, models, versions, SBOM/HBOM, vulnerabilities, PSIRT cases, evidence and CRA reporting readiness.
One platform connecting the complete workflow.Intuitive Experience
Designed around how product, R&D, PSIRT and regulatory teams actually work, turning complex requirements into clear steps.
See the next action at a glance.Secure Isolation
Choose cloud tenant isolation or dedicated on-premises deployment, with role-based access, login and transport protection.
Customers retain control of data and access.Beyond testing, CRA requires complete product lifecycle management.
CRA does not end when the test report is complete. The One and OneCRA support products from development through market launch and ongoing vulnerability management.
Secure by Design
Consultants help establish risk analysis, security requirements, technical documentation and development processes.
Product Cybersecurity Testing
The One testing team verifies product cybersecurity requirements and technical measures.
Global Market Certification
Integrate regulatory and certification routes to support entry into global markets.
Vulnerability Management & Reporting
OneCRA continuously monitors vulnerabilities, manages PSIRT cases, preserves evidence and prepares notifications.
Customers control their data; OneCRA provides the system and workflow.
Whether deployed in the cloud or on premises, OneCRA protects enterprise product information through clear data boundaries, roles and access procedures.
OneCRA Cloud
Deploy quickly with less operational overhead.
- AWS-managed environment
- Multi-tenant data and permission isolation
- RBAC, login and data-in-transit protection
OneCRA On-Premises
For enterprises prioritizing data sovereignty and internal deployment policies.
- Deployed on a dedicated customer-designated server
- Data remains in the customer-managed environment
- Customer controls networks, accounts and access permissions
Professional support at every stage of the CRA lifecycle.
From product design and process establishment through laboratory testing and market certification to ongoing post-market maintenance, The One and OneCRA connect the entire service lifecycle.
Core Consulting Team
Establish Secure by Design, risk analysis, security requirements, technical documentation and product security procedures.
Product Design & Process EstablishmentProduct Cybersecurity Testing
A laboratory team experienced in products and regulation verifies cybersecurity requirements and technical measures.
Pre-market TestingGlobal Certification
Integrate regulatory and certification routes across markets, helping products demonstrate conformity and enter global markets.
Pre-market CertificationOneCRA Software Platform
Continuously manage products, SBOMs, vulnerabilities, PSIRT cases, remediation evidence and Article 14 reporting.
Continuous Post-market MaintenanceDifferent company sizes and product types require different implementation paths.
The following anonymized scenarios show how OneCRA provides a common platform while The One configures services around product complexity, organizational workflows and data policies.
Long-lifecycle Professional Equipment Manufacturer
10–20 year support life · Industrial/medical equipment · Long-term maintenance
Products remain on the market while critical security data may disappear over time
- Product versions, SBOMs and technical documentation are stored separately
- Staff and system changes create gaps in historical records
- Vulnerability decisions and remediation evidence are difficult to reconstruct years later
Preserve complete product security records through the end of the support period
- Centrally retain products, versions, SBOMs and documents for the long term
- Continuously retain cases, decisions, remediation and communication history
- Retrieve audit and reporting evidence quickly, even years later
Large Multi-product Electronics Brand
Multiple BUs · Many models and versions · Group governance
Every team is working, but management lacks the full picture
- Different spreadsheets and rules across BUs
- The same vulnerability is analyzed repeatedly
- Headquarters lacks portfolio-wide risk visibility
Preserve BU flexibility while creating group-wide visibility
- Multi-tenant architecture and RBAC isolate BU data
- Unified vulnerability, evidence and reporting framework
- Portfolio risk visibility for management
Global Smart Product Brand
Integrated hardware/software · Global markets · Multi-tier supply chain
Disconnected supplier, component and product data makes impact difficult to trace
- Upstream suppliers and third-party components lack a unified registry
- Components are difficult to link to products, versions and sales markets
- Downstream customer notifications and vulnerability handling are fragmented
Trace and control the supply chain from upstream production to downstream customers
- Create a supplier registry with component responsibility records
- Connect suppliers, components, products, versions and markets
- Support downstream customer notification, PSIRT collaboration and CRA evidence
The complete CRA lifecycle,
handled by The One.
From Secure by Design, product cybersecurity testing and global certification to OneCRA vulnerability management and reporting readiness—we help you build the complete solution.
Book a OneCRA DemoNot Sure Where to Start?
Request a free initial consultation or product assessment.
Our experts are here to help.
