From 11 September 2026, an actively exploited vulnerability gives you 24 hours to report. Also for products already in the field.
TrustEngine is the detection and evidence engine for CRA compliance. It wires your per-product SBOMs to live vulnerability and exploitation data, matches every new signal to the exact components and versions you ship, and maintains the living technical file the CRA expects, with controlled sharing so customers get proof, not blueprints.
December 2027 is the date on the roadmap. 11 September 2026 is the date obligations start. And it isn't a milestone you pass: it's a clock that can start any day after it, for any product you've shipped that is still out there.
Paste a component list. It gets matched against exploitation signals, the noise is struck through with the judgement recorded, and what actually needs action comes out on top. This demo uses a small illustrative rule set; the product runs on live feeds.
A certificate covers the organisation and gets renewed periodically. The CRA expects a technical file per product, and that file only helps if it reflects reality on the day something happens. Components change, new CVEs land daily, suppliers push updates.
Most teams are preparing documents: an SBOM, a process on paper. TrustEngine turns the document into a tool.
CVE streams, vendor advisories, CISA KEV, EPSS, OSV, ExploitDB. Awareness is the duty behind the duty: you cannot report in 24 hours what nothing told you happened.
Not "log4j exists" but "log4j-core 2.14 ships in your v3.2, and the path is reachable". The match is what tells you the clock has started.
Per product, maintained through the support period, signed on every change. The file you build for the regulator is the file that defends you in court.
Every CVE gets a VEX judgement in the context of your build: reachable or not, affected or not. The noise is struck through with the reasoning recorded.
Views on the same SBOM: deep internally, shareable externally. Hand over SBOM plus VEX and you set the signal, instead of cleaning up other people's false positives.
A match drafts the early warning from the dossier: component, version, judgement, timeline. The 24 hours go into deciding, not into searching.
Your SBOM comes in. Every component, every version, per product.
Live signals matched to what you actually ship. Noise struck through, judgement written down.
The file is signed and stays current. Evidence ready when someone asks, or when the clock starts.
They have the document. They couldn't act on it.