EU Cyber Resilience Act · Effective 11 September 2026

Know which CVEs trigger mandatory ENISA notification — before the 24h clock runs out.

BicPort Report cross-references your firmware SBOM against global vulnerability databases. Automatically identifies Art. 14 obligations, generates ENISA draft reports, and tracks every deadline. Free.

No credit card required · Free tier · Full SBOM analysis

⚡ Public Beta — Free during beta period
6
Vulnerability Feeds
24h
ENISA Window
4
Compliance tiers
100%
Free tier available
Regulatory contextEU Cyber Resilience Act (2024/2847)ENISA Art. 14 ReportingCISA KEVNVD / NIST

WHO THIS IS FOR

Built for EU hardware manufacturers who ship connected products.

Industrial hardware manufacturers

PLCs, sensors, gateways, robotics controllers — any connected device sold in the EU after September 2026.

Embedded firmware teams

If your firmware includes third-party libraries, you have an SBOM obligation. BicPort Report makes that obligation manageable.

SMEs without a security team

BicPort Report automates the reporting workflow that CRA requires — from detection to ENISA submission.

If your product connects to a network and is sold in the EU, CRA Article 14 applies to you from 11 September 2026.

THE DEADLINE IS FIXED

One actively exploited CVE. Three mandatory notifications. €15M in fines.

1

CVE appears in CISA KEV

An actively exploited vulnerability is found in a component your firmware uses. The clock starts the moment you become aware.

2
Early Warning

T+0 to T+24h

Notify ENISA. Brief alert that you are aware and investigating.

3
Vulnerability Notification

T+0 to T+72h

CVE details, nature of exploit, mitigations taken, and measures users can take.

4
Final Report

T+14 days after patch ships

Full technical description, CVSS details, and security update information.

Non-compliance penalties: up to €15,000,000 or 2.5% of global annual turnover — whichever is higher.

FEATURES

Everything you need to comply with CRA Article 14.

ART. 14

Automated Obligation Detection

KEV match = Art. 14 event created instantly. Countdown timers for 24h, 72h and post-patch final report deadlines. No manual monitoring.

MONITORING

Continuous KEV Monitoring

Hourly KEV sync. If a new CVE is added that affects your product, you are alerted immediately — not after your next manual scan.

CI/CD

Pipeline Integration

GitHub Actions, GitLab CI, Jenkins. SBOM generated and scanned automatically on every firmware build.

PRIVACYEnterprise & AI Compliance

On-Premise Available

For manufacturers with strict data sovereignty requirements: BicPort Report deploys on your own infrastructure. Your SBOM data never leaves your environment.

SBOM

SBOM Upload & Analysis

CycloneDX 1.4/1.5 or SPDX 2.3. Drag-and-drop or API. Auto-generates completeness score. No SBOM yet? BicPort Report generates one.

VULNERABILITY FEEDS

Unified Advisory View

Mandatory CRA regulatory sources and supplementary vulnerability feeds cross-referenced automatically.

REPORTING

ENISA Draft Reports

Pre-filled early warning, notification, and final reports — for both CVE vulnerabilities and severe incidents. Every draft includes a field-by-field SRP map so your compliance team copies values straight into the ENISA portal.

MULTI-TENANT

Team & Organisation Access

Role-based access (Admin, Analyst, Read-only). Database-level row isolation. API keys for programmatic access.

DATA SOVEREIGNTY

Your SBOM data never has to leave your infrastructure.

Industrial SBOM data reveals your complete software supply chain. For manufacturers with strict data sovereignty requirements — or those operating in regulated sectors — BicPort Report deploys entirely on your own infrastructure.

Same features. Same compliance workflow. Zero external data transmission.

  • Self-hosted on your servers or private cloud
  • No data transmitted to BicPort infrastructure
  • Air-gapped deployment available
  • Audit-ready — you control the logs
  • Available on Enterprise and AI Compliance tiers
Ask about On-Premise
100% Air-Gapped On-Premise Shield

HOW IT WORKS

From upload to ENISA report in 5 steps.

1

Connect your CD/CI OR upload your SBOM

Drag-and-drop CycloneDX or SPDX. Or generate one automatically from your build artifacts.

2

Automatic Analysis

Every component cross-referenced against 6 feeds simultaneously. Completes in seconds.

3

Review Findings

CVEs sorted by priority: KEV first, then EPSS, then CVSS. Filter by product, severity, or status.

4

Art. 14 Events Created

KEV matches trigger automatic Art. 14 events with live countdown timers. Nothing falls through the cracks.

5

Generate ENISA Reports

Pre-filled draft reports for each phase. Review, approve, submit. ENISA SRP-ready for Sep 2026.

FAQ

Common questions.

We have until December 2027 for full CRA compliance. Why act now?

CRA Article 14 (incident reporting) activates on 11 September 2026 — over a year before the full compliance deadline. From that date, any actively exploited CVE in your product requires ENISA notification within 24 hours, regardless of your overall compliance status.

What exactly is an SBOM and do we have one?

An SBOM (Software Bill of Materials) is a structured list of every software component in your firmware. If you use Yocto, Buildroot, or any standard build system, BicPort Report can generate one automatically from your build artifacts — you don't need to create it manually.

We don't have a dedicated security team. Is this too complex?

BicPort Report is designed for manufacturers without security specialists. The Art. 14 workflow guides you step by step: detection is automatic, drafts are pre-filled, and deadlines are tracked in real time.

What about our SBOM data confidentiality?

BicPort Report is available as an on-premise deployment for organisations with strict data sovereignty requirements. Your SBOM data stays entirely within your own infrastructure.

Does the free tier have any limitations?

During beta, the free tier includes full SBOM analysis, all 6 vulnerability feeds, Art. 14 detection, and ENISA draft generation. Volume and support SLA are the main differences in paid tiers.

Your CRA Art. 14 deadline is fixed.

11 September 2026. Free to start. No credit card.