Signal CYBERFORT: A Compliance-Chain Platform Operationalising the Cyber Resilience Act for SMEs
Summary
Researchers introduced CYBERFORT, an open-source compliance platform designed to help small and medium-sized enterprises meet the EU's Cyber Resilience Act (CRA), which imposes lifecycle-long cybersecurity compliance obligations on manufacturers, importers, distributors and integrators of digital products. The platform was developed under the EU Digital Europe Programme as one of twelve projects in the EU's CRA cluster, aiming to fill the governance, risk and compliance capacity gap that most SMEs lack. CYBERFORT offers a guided self-assessment, a question bank tied to CRA Annex I and vulnerability-handling obligations, and a compliance-checking engine that links every answer to controls, policies and machine-attested evidence, reusing ISO/IEC 27001, NIS2 and GDPR controls where they overlap with CRA requirements. Its central contribution is a traceable 'compliance chain' connecting product risks through controls and policies to the specific CRA obligations satisfied, and onward to technical documentation and the EU declaration of conformity. The platform has been deployed at access.cyber-fort.eu for an initial cohort of 43 organizations, with a completed end-to-end case study on a SIEM/XDR product including AI-driven remediation. The work illustrates how regulatory compliance itself is becoming an engineered, software-driven industry in response to the EU's expanding product cybersecurity rules.
Classification
Evidence 1
- CYBERFORT: A Compliance-Chain Platform Operationalising the Cyber Resilience Act for SMEs arXiv 2026-10-07 accessed 2026-10-08T04:25:29+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-ad39a00488a8
