CYBERFORT and SEUXDR pilot target EU Cyber Resilience Act duties
Open-source CYBERFORT, one of twelve EU CRA cluster projects, and a SEUXDR pilot help SMEs trace product risks to Cyber Resilience Act evidence and conformity.
Two arXiv reports describe how SMEs can prepare products with digital elements for the EU Cyber Resilience Act, Regulation 2024/2847, which requires risk assessment, vulnerability handling, conformity documentation, and Article 14 incident and vulnerability reporting before market access. CYBERFORT is an open-source platform developed under the EU Digital Europe Programme as one of twelve CRA cluster projects; it offers a guided scope self-assessment, a question bank covering Annex I and vulnerability handling, and an engine that links answers to controls, policies, and machine-attested evidence, reusing ISO/IEC 27001, NIS2, and GDPR controls only where they overlap the CRA. Its compliance chain traces each product risk through controls and policies to CRA obligations, the technical-documentation file, and the EU declaration of conformity. A practitioner case study applies the platform to SEUXDR, an AI-augmented security-monitoring product with a large-language-model active-response component, through a six-step recipe: Scope and Classify, Asset Registration, Produce Evidence, Map to CRA, Gap and Actions, and Audit Pack. The newer report says the platform is deployed to a first cohort of 43 organisations, with a completed SIEM/XDR case study and a controlled effort study still in progress; the sources do not conflict, though only the earlier report names SEUXDR.
- The EU Cyber Resilience Act is Regulation 2024/2847 and requires risk assessment, vulnerability handling, conformity documentation, and Article 14 incident and vulnerability reporting before products with digital elements reach the EU…
- CYBERFORT is an open-source platform developed under the EU Digital Europe Programme as one of twelve CRA cluster projects, aimed at SMEs.
- It provides a guided scope self-assessment, a question bank covering Annex I and vulnerability handling, and an engine linking answers to controls, policies, and machine-attested evidence.
- ISO/IEC 27001, NIS2, and GDPR controls are reused only where they overlap the CRA.
- Its compliance chain traces each product risk through controls and policies to CRA obligations, the technical-documentation file, and the EU declaration of conformity.
- A practitioner pilot covers SEUXDR, an AI-augmented monitoring product with an LLM active-response component, using six steps: Scope and Classify, Asset Registration, Produce Evidence, Map to CRA, Gap and Actions, and Audit Pack.
- CYBERFORT is deployed to a first cohort of 43 organisations; a SIEM/XDR case study is completed and a controlled effort study is still in progress.
Coverage timelineoldest first · each row is one article
- · 3d agoPreparing an AI-Augmented SIEM for the EU Cyber Resilience Act: A Practitioner Case Study
arXiv cs.CR· 44
A practitioner case study maps AI-augmented SIEM SEUXDR to EU Cyber Resilience Act lifecycle and reporting duties.
- · 1d agoCYBERFORT: A Compliance-Chain Platform Operationalising the Cyber Resilience Act for SMEs
arXiv cs.CR· 36
CYBERFORT, an open-source platform, helps SMEs trace product risks to EU Cyber Resilience Act obligations and evidence.