CRA-compliant,
with no blind spots.
Probenta takes on your CRA vulnerability-management and notification obligations — SBOM, the 24 h / 72 h / 14 d clock, audit-ready records — maintained continuously, ready to show.
Free, about 5 minutes. Your answers stay in your browser until you request your report — privacy.
Regulatory calendar — Regulation (EU) 2024/2847
Today
There are days left before the first deadline.
11 Sept 2026
Mandatory reporting of exploited vulnerabilities
24 h / 72 h / 14 d notification as soon as a vulnerability is actively exploited.
— Art. 14
11 Dec 2027
Full CRA compliance
Sanctions regime: up to €15M or 2.5% of worldwide turnover.
— Art. 64
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements […]”
Feeds and sources monitored
CISA KEV · CERT-FR · ENISA (EUVD) · NVD
December 2027 is closing in. Are your software and connected products really ready?
The CRA is not just another formality. Without compliant marking, a digital product can no longer be placed on the European market — and breaches run into the millions.
Up to €15M or 2.5% of worldwide turnover for failing to meet the essential requirements.
Early warning to the coordinating CSIRT and ENISA within 24 hours of an actively exploited vulnerability.
A non-compliant product can be denied CE marking — and with it, access to the 27 markets of the Union.
What the CRA requires of you, now.
01
The clock is ticking, you'll be notified in time
An exploited vulnerability triggers a legal countdown (24 h / 72 h / 14 days). Miss it, and it is a sanction.
02
The technical file is a time sink.
Up-to-date SBOM, risk analysis, support period, disclosure: hours of ongoing engineering work.
03
Proving you notified on time.
Without a tamper-proof audit log, demonstrating compliance to the authority is impossible.
One single data set. Multiple regulatory deliverables.
A single entry feeds every deliverable
01 / 04
Article 14 notification
As soon as an exploited vulnerability touches your SBOM, the clock starts. Notification pre-filled, within the deadline.
02 / 04
Annex VII technical file
Generated from the same data, kept up to date, ready for audit.
03 / 04
Disclosure portal
security.txt, intake, triage, public page — hosted.
04 / 04
Audit report
An append-only, tamper-proof log, ready to present to the supervisory authority.
Two layers of assurance. No surprises on audit day.
Probenta layers an exhaustive mapping of your obligations with a living evidence register. If one gives way, the other holds.
Your obligations, translated
No more wading through the regulation: every CRA requirement becomes a traceable obligation, mapped to your products.
A file that is always ready
SBOM, risk analyses, tests, technical documentation: everything is centralized, versioned and exportable. The audit file is generated in one click.
The regulation moves, you keep up
Delegated acts, harmonized standards, ENISA guidance: Probenta alerts you as soon as a change affects your scope.
One deadline, one owner
A dashboard per product and per milestone. Every stakeholder knows what to deliver, and when. Management sees progress in real time.
Article 14 alarm
The full chain, from detection to proof of notification.
01 · CORRELATION
SBOM ↔ actively exploited vulnerabilities (CISA KEV, CERT-FR)
02 · CLOCK
24 h / 72 h / 14 d, triggered automatically
03 · NOTIFICATION
Pre-filled in the format expected by the coordinating CSIRT and ENISA
04 · PROOF
Append-only audit log — notification within the deadline, demonstrable
Included
Continuous SBOM + CVE correlation
We orchestrate proven open-source tools; continuous monitoring of your product portfolio.
Coming soon
Annex VII technical file
Generated and kept up to date automatically, audit-ready.
Coming soon
Hosted disclosure portal
security.txt, intake, triage, public page.
We never ingest your source code.
Only your SBOM and metadata. Reduced attack surface. Security is part of the product.
SBOM + metadata only
Hosted in the EU
Append-only audit log
GDPR compliant
Compliance starts with our own.
Our entire chain — hosting, emailing, processors — is French or European, and GDPR compliant.
Scaleway
Our solutions are hosted on Scaleway, a French cloud provider, ISO 27001 certified and committed to GDPR.
Scaleway security & certifications →Brevo
Our e-mails are sent through Brevo (Sendinblue SAS), a French company — your data stays hosted in the EU.
Brevo & the GDPR →GDPR end to end
We and all of our processors comply with the GDPR: data minimisation, EU hosting, rights you can exercise at any time.
Read Regulation (EU) 2016/679 →The details of our processing activities are in our privacy policy.
Two profiles, one obsession: your compliance.
We combine regulatory expertise and software engineering to make the CRA manageable.
Ayoub Tougani
Passionate about automated processes and sharp on standards and how our world evolves, Ayoub has years of experience in regulatory and medical fields, which he has put to use building cutting-edge applications.
Alexandre Berthiot
Having worked for over 7 years in the healthcare sector (pharmacy and sleep apnea treatment), Alexandre knows the legal stakes of offering products close to a patient. He is also deeply committed to cybersecurity and has taken part in numerous security-hardening (blue teaming) efforts across various companies.
Let's talk about your deadline.
A 30-minute demo is enough to see where you stand. We get back to you within 72 business hours.
No spam. We'll write when we open. By subscribing you agree we keep your information for this sole purpose — privacy.