Cyber Resilience Act & EU Data Act

A new vulnerability lands. Which of your devices are affected?

Regontis reads the answer from your software bills of materials: which releases contain the component, how many devices are in the field, which customers you need to inform. Minutes instead of three days by hand.

A brand of Explicatis GmbH · Enterprise software from Germany

Illustrative example of the Regontis interface – no real customer data.

EC-500 Pro · CRA

Audit-ready

84%

Evidence complete

Declaration of conformity ready to draft

  • SBOM imported · 214 components
  • CVE-2025-31188 · 3 customers affected
  • 12 requirements linked to evidence
  • 2 open tasks prioritised

Illustrative example with demo data

  • Reporting obligations, including the 24-hour early warning for actively exploited vulnerabilities

  • Full application of the Cyber Resilience Act

Deadlines under the Cyber Resilience Act. These dates are given for orientation and are not legal advice.

A product is no longer finished when it ships.

For as long as a device is in the field, you have to know what runs inside it — and be able to prove it.

Cyber Resilience Act

Security across the lifecycle – and provable.

Products with digital elements are subject to continuous obligations – from the software bill of materials to responding to vulnerabilities.

  • SBOM and component transparency for every release
  • Vulnerability monitoring and reporting deadlines
  • Evidence of conformity and technical documentation

EU Data Act

Data access you can control and evidence.

Users and third parties gain rights to access and port the data generated by using a product – transparently and in line with the rules.

  • Record and classify data flows
  • Assign access and portability rules
  • Requests from the customer portal, legal review and audit log

Everything hangs on the same product data.

In Regontis all of it hangs on one chain. Pull at one end and you see what happens at the other.

Product & release

Products, releases and data flows are imported — via CSV, repeatably and without duplicates.

  • EdgeControl Gateway EC-500
  • Variants EC-500 Pro and EC-500 Rugged
  • Releases 2.1.0 and 2.1.0-r
  • 18,500 devices in the field

Everything that follows hangs on this assignment.

SBOM & component

Every release has a software bill of materials, imported via CycloneDX.

  • Imported as CycloneDX
  • 214 components
  • including openssl 3.0.11, BusyBox 1.34.1, Linux kernel 5.15.118

Without a bill of materials, every vulnerability report stays guesswork.

Vulnerability

New vulnerabilities are matched automatically against the bills of materials.

  • CVE-2025-31188
  • CVSS 9.8
  • listed as actively exploited
  • affects openssl 3.0.11 in EC-500 Pro and Rugged

Around 6,100 devices affected, 1,022 of them confirmed through recorded deployments — together with the customers behind them.

Requirement & evidence

Regulatory requirements are linked to specific evidence.

  • Reporting obligation under CRA Art. 14
  • Configuration hardening under CRA Annex I
  • 12 of 17 requirements evidenced
  • Evidence coverage 61%

What is missing becomes as visible as what is done.

Task

Every gap becomes an assigned task with a deadline.

  • T-2025-218 “Update OpenSSL to 3.0.17”
  • Priority critical
  • Due in 8 days
  • Prepare report INC-2025-013

Nothing is left sitting in spreadsheets and inboxes.

Audit readiness

At the end there is a declaration of conformity and an evidence bundle — available at any time.

  • Audit date 12 September 2026
  • Notified body 0xxx
  • Module B+D
  • 58% complete, declaration of conformity in draft

Auditors view the evidence read-only in the Evidence Room.

Core features

Everything CRA and Data Act operations need.

SBOM & components

CycloneDX import with dedup and re-matching, per release.

Vulnerabilities

NVD/KEV feeds and automatic matching — affected customers visible at once.

Data flows & Data Act

Data catalogue, rule assignment, legal review and a complete audit log.

Requirements & evidence

Every requirement tied to concrete evidence, completeness per product.

Tasks & workflows

What needs doing becomes an assigned, trackable task.

Evidence Room

Read-only access for auditors — view and filter, change nothing.

A dedicated access point for operators and users.

The EU Data Act gives users rights to the data from their devices. Your customers raise their requests in the portal themselves.

  • Submit data access requests

    A request becomes a case on your side, with review and an audit trail.

  • Export and share data

    Export in common formats, sharing with a third party of their choosing.

  • Retrieve security information

    Exposure, security advisories and update information for their product.

AI-assisted recommendations

Regontis prioritises what to do next — explained and tied to your products. The decision stays with your teams.

Built for running in an enterprise.

Multi-tenant

Roles and permissions per tenant.

SaaS or on-premises

Hosted or in your own data centre.

Security

Role-based access, auditor mode, audit logs.

GDPR-compliant

Data held to European requirements.

This is what Regontis looks like in daily use.

Not a concept paper: overviews for management, detail for security and compliance, evidence for the audit.

Overview for management

CRA and Data Act readiness, critical vulnerabilities and the AI recommendation of the week.

1 of 4

What this screenshot shows

  1. Readiness per regulationThe CRA and the EU Data Act assessed separately, with the trend against last month.
  2. Critical vulnerabilitiesHigh-severity findings, derived directly from the software bills of materials.
  3. Prioritised recommendationWhat matters this week, with the sources it follows from and the next steps.

What this screenshot shows

  1. Impact in numbersHow many devices are affected, and how many of those are confirmed through recorded installations.
  2. From component to customerComponent, variants, releases and customers are linked — the chain is not pieced together by hand.
  3. Affected customersThe basis for informing them, for deadlines and for reporting — instead of searching through delivery records.

What this screenshot shows

  1. Coverage as a figureHow much evidence is in place, how much is verified and how much is missing.
  2. What is missingSeven outstanding items of evidence stand as a figure of their own next to coverage, not as the remainder of a list.
  3. Evidence with its assignmentEvery document hangs on a requirement, not in a folder.

What this screenshot shows

  1. Completeness within the audit scopeOne figure for the state of the audit scope.
  2. Audit scope definedFramework, notified body, module and audit date belong to the scope, not to an email thread.
  3. Checklist per requirementStatus, evidence and owner in a single row.

Illustrative example with demo data

That was the overview. We will show the rest on your own product.

Request a demo

Who it's for

Every role asks a different question.

Executive management

Will we hold up in the audit?

One status per product and regulation, with the trend since last month.

Compliance manager

Which evidence is still missing?

Every requirement hangs on a document. What is missing shows as its own figure.

Product security manager

Does this CVE affect us?

Matched against your bills of materials down to release, device count and customer.

Auditor

Show me the evidence.

Read access to the Evidence Room. Auditors look and filter for themselves.

Frequently asked questions

What prospective customers ask us most often.

  • What is a regulatory operations hub?

    A central system in which product-related regulatory obligations are handled operationally. Instead of spreading requirements, evidence, vulnerabilities and tasks across spreadsheets and ticketing systems, they all hang on the same product data. Regontis combines the Cyber Resilience Act and the EU Data Act in one such hub.

  • Who is Regontis for?

    For manufacturers of connected products — mechanical engineering, industrial IoT, embedded devices, industrial electronics. Typical users are compliance, product security, product management and executive management; auditors get their own read-only access.

  • When do the obligations under the Cyber Resilience Act apply?

    The reporting obligations apply from 11 September 2026, including the early warning about actively exploited vulnerabilities within 24 hours. The regulation applies in full from 11 December 2027. Regontis covers both stages; the legal assessment in the individual case remains with you.

  • What is an SBOM and why do I need one?

    An SBOM is the bill of materials for the software components of a product. Without it, there is no reliable way to say whether a new vulnerability affects your own product. Regontis imports SBOMs in CycloneDX format and matches them continuously against vulnerability sources.

  • How does Regontis differ from a vulnerability scanner?

    A scanner finds vulnerabilities; Regontis carries them through to the evidence. From the finding to the affected releases and customers, and on to the requirement, the task and the audit evidence, everything stays connected — precisely the chain an audit asks for.

  • What does the EU Data Act require of manufacturers?

    Users gain rights to the data generated when they use their devices, including sharing it with third parties of their choice. Regontis records the data flows, assigns rules to them and comes with a portal through which users submit their requests.

  • Can Regontis run in our own data centre?

    Yes. Regontis is designed both as a hosted platform and for operation in your own infrastructure, multi-tenant and role-based.

  • What does a demo look like?

    A session along your own use case, with no preparation needed on your side. You outline your products briefly, and we show how CRA and Data Act operations map onto them.

Request a demo

Show us one of your products.

We map it in the demo: import the bill of materials, match it against vulnerabilities, attach the evidence.

No sales pressure and no preparation needed. Your enquiry goes straight to our team.

Required fields are marked with *. We use your details solely to handle this request. More on this in our privacy policy.

Regontis is a brand of Explicatis GmbH.

Software engineering from Cologne – with information security certified to ISO 27001 and more than two decades of experience in industrial and IoT projects.

  • ISO/IEC 27001 certified — Explicatis GmbH
  • ISO 9001 certified — Explicatis GmbH
  • 25+

    Years of experience

  • 100+

    Experts

  • 1,000+

    Projects

Certified to ISO/IEC 27001 and ISO 9001: Explicatis GmbH