Skip to main content

CRA Article 14 reporting obligations approaching

Platform Overview

Component visibility, vulnerability operations, and secure updates for connected products.

TegmenSoft brings software component visibility, vulnerability operations, and secure update workflows into a unified control plane built specifically for embedded and connected product lines.

MCU Minimum Profile

256 KB Flash · 64 KB RAM

MPU / OS Architecture

ARM64 · x86_64 · Embedded Linux

Transport Security

TLS 1.3 / mTLS, AES-256-GCM

Cryptographic Signatures

Ed25519 / RSA-PSS

Platform Capability Availability Matrix

Transparent status of all platform capabilities and deployment models.

Capability / FeatureStatus BadgeDeployment Scope
Web SBOM Scanner & OSV MatchingAvailableFree Web Tool (In-Browser Parsing)
CycloneDX 1.7 & SPDX 2.3 ExportAvailableBrowser & API Specification Export
Dynamic SBOM Engine (Binary Analysis)PilotEnterprise Pilot Program
Field Telemetry & Exploit WarningPilotEnterprise Pilot Program
Secure OTA (Signed & A/B Rollback)PilotEnterprise Pilot Program
ENISA SRP Reporting AssistanceIn DevelopmentStructured Notification Drafting
PUF / Hardware-Backed IdentityRoadmapSelected Microcontroller Hardware

Architecture & Security

Three-Tier Security Control Plane

From hardware identity to cloud telemetry: built on row-level tenant isolation and cryptographic verification.

Layer 01

Hardware Security Base

Hardware-Backed Identity & Secure Boot

Hardware Root-of-Trust and secure boot verification on supported microcontrollers.

Secure BootEnforces execution of cryptographically verified code images
Cryptographic Device IdentityHardware key storage support
Layer 02

Embedded Runtime & Library

Low-Footprint Runtime

Modular libraries designed for efficient execution on resource-constrained MCU/MPU hardware.

Low Memory FootprintOptimized memory allocation for constrained targets
Efficient TransportBandwidth-friendly protocols over TLS / mTLS
Layer 03

Cloud Control Plane

Multi-Tenant Security Control Plane

Row-level tenant isolation and encrypted data storage architecture.

Tenant IsolationRow-level tenant isolation for strict data segregation
Vulnerability IntelligenceIntegration with OSV and public CVE vulnerability databases

Platform Capabilities

Product Lifecycle Cybersecurity Workflow

Combine software component discovery, vulnerability correlation, prioritization, and secure updates in a single platform.

DISCOVERYPilot

Dynamic SBOM Engine

Software Bill of Materials & Vulnerability Correlation

Discovers open-source and commercial dependencies, matching them against the OSV database. Outputs machine-readable SBOMs in SPDX 2.3 and CycloneDX 1.7 formats.

  • Manifest and binary-level dependency detection
  • CycloneDX 1.7 and SPDX 2.3 standard export
  • OSV open-source vulnerability correlation
  • Optional VEX (Vulnerability Exploitability) reporting support
Raw files never leave your device. 100% free, no sign-up required.Try Web SBOM Scanner →
PRIORITIZATIONPilot

Field Telemetry & Early Warning

Active Exploitation & Anomaly Observability

Detects active exploitation events from connected field device logs and provides early warning indicators to security operations teams.

  • Secure device-to-cloud telemetry stream
  • Behavioral anomaly and IoC correlation
  • Vulnerability x field event mapping
  • Event prioritization and scoring
REPORTINGIn Development

CRA Reporting Assistant

Structured Draft Preparation

Converts detected active exploits and severe security incidents into structured notification drafts aligned with ENISA and CSIRT templates, ready for human review.

  • Draft generation aligned with ENISA SRP structure
  • 24h early warning and 72h detailed notification workflow
  • Affected product line and fleet mapping
  • Audit trail for compliance verification
REMEDIATIONPilot

Secure Update (OTA) Manager

Signed Firmware & A/B Partition Rollback

Protects operational continuity with cryptographically signed updates, dual partition (A/B) rollback, and canary deployment controls.

  • Cryptographic signature verification
  • Dual partition (A/B) rollback for crash recovery
  • Phased (canary) fleet deployment
  • Bandwidth-optimized delta update packages

Secure Update Workflows

Signed & Fail-Safe OTA Infrastructure

Cryptographically signed updates with A/B partition rollback support to maintain device operational continuity.

Cryptographically Signed Firmware

Ed25519 or RSA-PSS signed update packages. Devices verify signatures against embedded root public keys before executing updates.

A/B Partition Rollback

Dual partition layout allows devices to automatically roll back to a known working image if an update fails during boot.

Delta Package Transport

Only modified binary blocks are transmitted, optimizing bandwidth for cellular, 2G, and NB-IoT deployments.

Hardware Regulatory Compliance

Streamline regulatory compliance for hardware manufacturers

How TegmenSoft replaces fragmented manual compliance spreadsheets with an automated, chip-to-cloud security control plane.

Compliance DomainTraditional Manual ApproachTegmenSoft Unified Control Plane
SBOM Management (CycloneDX / SPDX)Static Excel spreadsheets updated manually per release; outdated immediately upon deployment.Automated build-time & runtime lockfile parsing with zero server code upload and live OSV correlation.
CRA Article 14 Early Warning (<24h)Emergency manual email exchanges; high risk of missing statutory 24-hour notification deadline.Pre-structured ENISA Single Reporting Platform (SRP) schema drafting with human-in-the-loop sign-off.
Secure Firmware Updates (OTA)Unsigned HTTP downloads or manual technician on-site visits; vulnerability to bricking.Cryptographically signed (Ed25519) delta packages with dual-bank A/B partition automated rollback.
Technical Documentation (10-Year Retention)Scattered local drives; difficult audit trail retrieval during market surveillance inspections.Immutable audit trail with cryptographic component lineage and continuous verification.

Security Architecture

Defense-in-depth across every layer

Row-level tenant isolation, encrypted transit, and cryptographic code verification from device hardware to cloud control plane.

Device Security Base

  • Secure Boot verification
  • Hardware identity support
  • mTLS + AES-256-GCM transport

Runtime & Agent

  • SBOM (SPDX 2.3 · CycloneDX 1.7)
  • Low-memory footprint C/C++ libraries
  • Event correlation triggers

Cloud Control Plane

  • Row-level tenant isolation
  • OSV vulnerability feeds
  • ENISA SRP reporting draft assistance

Schedule a technical discussion for your product.

Schedule a 30-minute technical review call with our engineering team to assess your product architecture and potential pilot scope.

Book a Technical Call
Hardware & IoT Cyber Resilience & Regulatory Compliance Cloud | TegmenSoft · TegmenSoft