CYBERFORT: A Compliance-Chain Platform Operationalising the Cyber Resilience Act for SMEs
CYBERFORT, an open-source platform, helps SMEs trace product risks to EU Cyber Resilience Act obligations and evidence.
CYBERFORT is an open-source platform, developed under the EU Digital Europe Programme as one of twelve Cyber Resilience Act cluster projects, aimed at SMEs that must meet CRA lifecycle obligations. It provides a guided scope self-assessment, a question bank tied to Annex I and vulnerability-handling duties, and an engine that links answers to controls, policies, and machine-attested evidence, reusing ISO/IEC 27001, NIS2, and GDPR controls only where they overlap the CRA. Its compliance chain traces each product risk through controls and policies to CRA obligations, the technical-documentation file, and the EU declaration of conformity. It is deployed for a first cohort of 43 organisations, with a completed SIEM/XDR case study and a controlled effort study still in progress.