A European consortium, which includes the Digital Innovation Hub "Trakia" (DIH Trakia), today unveiled its new open-source platform named Open Source Cybersecurity Resilience Act Tools (OSCRAT). The solution was created as a free resource for small and medium-sized enterprises (SMEs) in Europe, aiming to help them meet the new regulatory requirements introduced by the EU Cyber Resilience Act (CRA). According to official information provided by the consortium, the goal is to help businesses tackle cybersecurity challenges and transform complex legal obligations into everyday, manageable workflows, without the need for the extensive resources available to large organizations.
The Cyber Resilience Act entered into force on December 10, 2024. Although its main obligations will not be fully applicable until December 11, 2027, companies have ongoing commitments starting today. These include reporting vulnerabilities and significant incidents affecting products with digital elements—a definition that covers both software and hardware developments. Furthermore, starting September 11, 2026, a strict reporting schedule comes into effect: companies will be required to submit an early warning notification within 24 hours of becoming aware of a serious incident or an actively exploited vulnerability, followed by a detailed notification within 72 hours.
The OSCRAT platform is designed as a modern environment that consolidates all cybersecurity and compliance activities in one place. Since the new legislation fundamentally changes the lifecycle of products with digital elements—from the design phase through development to maintenance and protection—the system provides comprehensive version tracking. The tool was developed to help organizations structure information about their products throughout their entire lifecycle, meeting the strict requirements of the European regulation.
Among the key functionalities that OSCRAT offers to businesses are:
- Assessment of applicability and strict adherence to legislative requirements;
- Software Bill of Materials (SBOM) management and built-in security scanning, providing visibility into components and their vulnerabilities;
- Specialized tools for vulnerability and incident management, through which security issues are recorded, assessed, and tracked, along with subsequent corrective actions;
- Workflows for cybersecurity risk assessment and treatment, supporting the identification of threats;
- Configuration and compliance task management, ensuring traceability of all security assurance activities;
- Workflows for preparing technical documentation and declarations of conformity, helping organizations gather the necessary evidence during the certification process;
- Registration and full traceability of conducted audits, as well as activities aimed at raising awareness and training staff on security-related topics.
The project for the platform's development is funded by the European Commission under the "Digital Europe" program. In addition to DIH "Trakia", the consortium includes experts and organizations from various countries: the Italian company PMF Research, the Polish Łukasiewicz Research Network, the Romanian companies Oves Enterprise and Enersec, as well as the Estonian developer Unicis.Tech.
Коментари (1)
OSCRAT – какво точно представлява?