CYBERFORT: A Compliance-Chain Platform Operationalising the Cyber Resilience Act for SMEs
CYBERFORT, an open-source platform, helps SMEs trace product risks to EU Cyber Resilience Act obligations and evidence.
CYBERFORT is an open-source platform, developed under the EU Digital Europe Programme as one of twelve Cyber Resilience Act cluster projects, aimed at SMEs that must meet CRA lifecycle obligations. It provides a guided scope self-assessment, a question bank tied to Annex I and vulnerability-handling duties, and an engine that links answers to controls, policies, and machine-attested evidence, reusing ISO/IEC 27001, NIS2, and GDPR controls only where they overlap the CRA. Its compliance chain traces each product risk through controls and policies to CRA obligations, the technical-documentation file, and the EU declaration of conformity. It is deployed for a first cohort of 43 organisations, with a completed SIEM/XDR case study and a controlled effort study still in progress.
- Open-source CRA platform from the EU Digital Europe Programme CRA cluster.
- Question bank covers Annex I and vulnerability handling, reusing overlapping 27001, NIS2, and GDPR controls.
- Compliance chain links risks, controls, evidence, documentation, and the EU declaration of conformity.
- Deployed to a first cohort of 43 organisations, with a completed SIEM/XDR case study.
Full article224 words · extracted from arxiv.org · click to collapse
The EU Cyber Resilience Act (CRA) turns product cybersecurity into a lifecycle compliance obligation for manufacturers, importers, distributors, and integrators of products with digital elements on the EU market, a load that falls largely on small and medium-sized enterprises (SMEs) that rarely have dedicated governance, risk, and compliance (GRC) capacity. We present CYBERFORT, an open-source CRA-first compliance platform developed under the EU Digital Europe Programme and one of twelve projects in the EU CRA cluster. CYBERFORT operationalises the CRA through a guided scope self-assessment, a question bank tied to Annex I and the vulnerability-handling obligations, and a compliance-checking engine that links every answer to controls, policies, and machine-attested evidence, reusing ISO/IEC 27001, NIS2, and GDPR controls only where they coincide with CRA obligations. Its central contribution is the compliance chain, a traceable structure linking each product risk through its controls and policies to the CRA obligations it satisfies, and onward through evidence to the technical-documentation file and EU declaration of conformity, so that every operational gap is traceable and can be closed before market placement. Deployed at https://access.cyber-fort.eu/ for a first cohort of 43 organisations, the platform is presented with the engineering behind the chain, measured results from a completed end-to-end case study on a SIEM/XDR product with AI-driven remediation spanning the CRA obligation chapters, and the controlled effort study that remains in progress.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2610.09918