Finite State delivers the artifacts and workflows manufacturers need to support EU Cyber Resilience Act (CRA) self-assessment—generated from the designated product and maintained over time.
Finite State’s managed CRA services turn product inputs into maintained artifacts and workflows for CRA self-assessment.
Reviewable, product-specific deliverables that support CRA self-assessment and ongoing readiness.
| Deliverable | Description |
|---|---|
| Living SBOM | Binary-derived software inventory |
| Cybersecurity Risk Assessment | Threats, controls, gaps, and remediation guidance |
| Continuous Product Vulnerability Monitoring | Ongoing vulnerability correlation, notification, and VEX support |
| Managed Vulnerability Disclosure Support | Draft notifications, CVD policy, and reporting workflow support |
| Technical Documentation Package + DoC Template | Documentation assembled to support self-assessment and declaration execution |
Explore how Finite State’s managed services map each deliverable to CRA requirements and ongoing product obligations.
Generates and maintains a product SBOM from customer-provided binaries, with exportable output in standard formats.
Supports CRA software transparency and technical documentation requirements.
Built to support manufacturer self-assessment with maintained evidence—not replace manufacturer accountability.
From setup and initial analysis through documentation assembly and steady-state support, the service is structured to help manufacturers build and maintain the evidence, workflows, and deliverables required for CRA self-assessment.
Product inputs are collected, initial analysis begins, and the first core deliverables are generated.
Evidence is assembled into a reviewable documentation package, followed by readiness review and final revisions.
Deliverables are maintained over time as products, vulnerabilities, and reporting needs evolve.
CRA obligations phase in over time, but evidence, monitoring, and reporting workflows need to be established before those deadlines arrive.
Manufacturers need workflows for time-bound reporting.
Technical evidence and documentation must be in place.
Disconnected tools, manual coordination, late documentation
Maintained product evidence tied to what ships
Each CRA engagement covers one designated product for 12 months, including onboarding, maintained deliverables, and ongoing managed support.
We'll walk through the scope, deliverables, and what is required for your designated product.
© 2026 Finite State. All rights reserved.