Product tour · sample data
See the system of record before the call.
Nine screens with realistic sample data from a fictional manufacturer, Acme Connected Systems GmbH — the same records a security engineer, a product owner and the assigned representative work with every day. Nothing here is a customer, a benchmark or a claim: values are invented; CVE identifiers are real public advisories so the intelligence columns look the way they do in the product.
Product registry
Demo data · Acme Connected Systems GmbH is fictionalEvery obligation attaches to a product placed on the EU market. The registry holds lifecycle state, classification with reasoning and approver, owners, support period, versions and SBOM status — and shows gaps as gaps.
| Product | Type | Classification | Lifecycle | Support period | Owner / security owner | Versions | SBOM | Exposed |
|---|---|---|---|---|---|---|---|---|
| EdgeGate Router | Hybrid (hardware + firmware) | Important · Class I Router / modem (Annex III) | Active | 2024-03 → 2029-03 | L. Brandt / M. Keller | 3 | Matched 2 h ago | 4 |
| DeviceHub Desktop | Software | Default Desktop software | Active | 2023-06 → 2028-06 | S. Okafor / M. Keller | 5 | Matched 2 h ago | 2 |
| SensorLink Firmware | Hardware (embedded) | Default IoT device firmware | Active | 2025-01 → 2030-01 | L. Brandt / J. Weiss | 2 | Matched 2 h ago | 1 |
| FleetSync Cloud Agent | Software | Default Remote management agent | Development | Not yet placed on the market | S. Okafor / — (gap) | 1 | No SBOM (gap) | 0 |
Component inventory
Demo data · Acme Connected Systems GmbH is fictionalOne deduplicated catalogue across every SBOM, keyed by package URL: which products contain a component, whether it is a direct or transitive dependency, its licence and its current exposure.
| Package URL | Version | Licence | Used by | Dependency | Open findings |
|---|---|---|---|---|---|
| pkg:npm/lodash@4.17.20 | 4.17.20 | MIT | DeviceHub Desktop | transitive | 1 |
| pkg:golang/golang.org/x/net@0.15.0 | 0.15.0 | BSD-3-Clause | EdgeGate Router, FleetSync Cloud Agent | direct | 1 |
| pkg:generic/openssl@3.0.12 | 3.0.12 | Apache-2.0 | EdgeGate Router, SensorLink Firmware | direct | 1 |
| pkg:generic/busybox@1.36.1 | 1.36.1 | GPL-2.0-only | EdgeGate Router, SensorLink Firmware | direct | 0 |
| pkg:npm/electron@28.1.0 | 28.1.0 | MIT | DeviceHub Desktop | direct | 1 |
| pkg:pypi/requests@2.31.0 | 2.31.0 | Apache-2.0 | FleetSync Cloud Agent | direct | 0 |
SBOM ingestion
Demo data · Acme Connected Systems GmbH is fictionalAn SBOM arrives from CI, the API, the GitHub App or an upload. The original file is preserved with its checksum; components are parsed, deduplicated, diffed against the previous version and matched — every step timestamped.
- File
- edgegate-router-3.2.0.cdx.json
- Format
- CycloneDX 1.5 (JSON)
- Product · version
- EdgeGate Router · 3.2.0
- Source
- CI pipeline via API token (release job)
- Checksum · size
- sha256:7f3c…a91e · 412 KB
- Uploaded
- 2026-09-18 06:42 CEST
- Parsed
- 2026-09-18 06:42 CEST · parser 2.3.0
- Components
- 1,284 (96 direct · 1,188 transitive)
- Matched
- 2026-09-18 06:44 CEST · OSV + GitHub advisories · enriched with CISA KEV and EPSS
- Findings
- 7 new · 1 known exploited · 1 fix available
- Diff vs previous
- +14 components, −9 components, 3 version bumps vs 3.1.4
Vulnerability queue
Demo data · Acme Connected Systems GmbH is fictionalRanked by exploitation evidence, not alphabetically. Every row carries the product on the market it affects, the human triage state with its reason, the explicit CRA review answer and the remediation owner.
| Priority | Advisory | Component · product | Severity | KEV | EPSS | Triage state | CRA review | Owner · due |
|---|---|---|---|---|---|---|---|---|
| 94 | CVE-2023-44487 | golang.org/x/net 0.15.0 EdgeGate Router 3.2.0 | High 7.5 | exploited | 0.82 | Confirmed reportable HTTP/2 rapid-reset exhaustion reachable on the remote-management API; exploitation in the wild is documented. | Confirmed | M. Keller Fix in 3.2.1 (released) |
| 78 | CVE-2024-3094 | xz 5.6.0 SensorLink Firmware 1.4.2 | Critical 10.0 | — | 0.31 | In remediation Backdoored build present in the toolchain image; no evidence of exploitation on shipped devices, review open. | Potentially reportable | J. Weiss 2026-09-25 |
| 58 | CVE-2024-27980 | node 20.11.0 DeviceHub Desktop 2.0.1 | High 8.1 | — | 0.06 | Triaged · affected Windows batch injection needs local shell access; not remotely exploitable in this product. | Not reportable | S. Okafor 2026-10-15 |
| 29 | CVE-2021-23337 | lodash 4.17.20 DeviceHub Desktop 2.0.1 | High 7.2 | — | 0.02 | Not affected (VEX) Vulnerable function (_.template) not used; VEX statement published. | Not reportable | S. Okafor — |
| 22 | CVE-2023-5678 | openssl 3.0.12 EdgeGate Router 3.2.0 | Medium 5.3 | — | 0.01 | New Awaiting triage. | Not reviewed | — SLA: 10 days |
Prioritisation — why the top finding is on top
Demo data · Acme Connected Systems GmbH is fictionalPriority is explainable: each factor and its weight are shown on the finding, and organisations can tune the weights. Reachability is recorded by a reviewer; Vellaci never infers it.
golang.org/x/net 0.15.0 in EdgeGate Router 3.2.0. Sources: OSV, GitHub advisories, CISA KEV, FIRST EPSS — each with fetched, checked and modified times.
- +40Active exploitation (CISA KEV)Listed 2023-10-10; the strongest single signal for Article 14.
- +24EPSS 0.82 (30-day exploitation probability)Top 2 % of all CVEs scored that day.
- +14CVSS 7.5, network vector, no privilegesBase score contributes; exploitability matters more than severity alone.
- +10Product on the EU market · Important Class IRegulatory exposure of the affected product.
- +6Component reachable (HTTP/2 remote-management API)Recorded by the reviewer; Vellaci never infers reachability.
Incident timeline
Demo data · Acme Connected Systems GmbH is fictionalFrom a finding to a final report, every step has a person, a timestamp and a recorded reason. Awareness is confirmed by a named person under a written rule — that confirmation, not a ticket timestamp, starts the Article 14 clocks.
- 2026-09-18 06:44Vellaci (matching job)Finding created: CVE-2023-44487 in EdgeGate Router 3.2.0 — KEV listed, EPSS 0.82.
- 2026-09-18 08:05M. Keller (security owner)Triage: affected, exploitation evidence acknowledged, reachable on the HTTP/2 remote-management API. Remediation assigned.
- 2026-09-18 08:11M. KellerAwareness confirmed: 2026-09-18 08:05 CEST (revision 1). Rule: awareness = security owner confirms exploitation evidence applies to a shipped version.
- 2026-09-18 08:20A. Rossi (assigned representative)Reportability review: confirmed reportable — actively exploited vulnerability in a product placed on the EU market (Art. 14(1)).
- 2026-09-18 08:20VellaciReporting case CRA-2026-0007 opened. Deadlines computed in Europe/Berlin: early warning 2026-09-19 08:05, notification 2026-09-21 08:05.
- 2026-09-18 21:30A. RossiEarly warning submitted through the ENISA Single Reporting Platform; receipt reference recorded, PDF filed as evidence.
- 2026-09-20 15:10A. RossiNotification submitted: affected versions, mitigation (rate-limit HTTP/2 streams on the management API), corrective measure 3.2.1 planned.
- 2026-09-23 11:00L. Brandt (product owner)Corrective measure available: EdgeGate Router 3.2.1 released with golang.org/x/net 0.17.0. Final-report deadline set: 2026-10-07.
Reporting workflow — case command center
Demo data · Acme Connected Systems GmbH is fictionalDeadlines are computed server-side from the confirmed awareness time in the organisation's timezone. Forms are staged with required, recommended and missing indicators; the manufacturer submits through the ENISA platform and records the submission with evidence.
- Case
- CRA-2026-0007
- Type
- Actively exploited vulnerability
- Product
- EdgeGate Router 3.2.0
- Awareness
- 2026-09-18 08:05 CEST (rev. 1)
- Assigned representative
- A. Rossi
- Workflow state
- Notification submitted → final report preparing
| Stage | Due (Europe/Berlin) | Status | Fields | Submission evidence |
|---|---|---|---|---|
| Early warning | 2026-09-19 08:05 | Submitted 2026-09-18 21:30 | 6/6 required | SRP receipt · PDF snapshot · hash 3c1f… |
| Notification | 2026-09-21 08:05 | Submitted 2026-09-20 15:10 | 11/11 required · 3/4 recommended | SRP receipt · PDF snapshot · hash 9a4d… |
| Final report | 2026-10-07 (14 days after corrective measure) | Preparing · 8/12 required | root cause, mitigations, users informed pending | — |
Two final-report triggers, kept distinct: 14 days after a corrective measure for exploited vulnerabilities; one month after the notification for severe incidents.
Evidence vault
Demo data · Acme Connected Systems GmbH is fictionalPrivate, checksummed files and links tied to products, requirements, findings and cases — with classification, review dates, retention category and legal hold. This is what an auditor or an authority is shown.
| Evidence | Kind | Classification | Linked to | Checksum | Review | Retention |
|---|---|---|---|---|---|---|
| EdgeGate Router — security test report Q3 2026.pdf | Test report | Confidential | Annex I Part II(3) · EdgeGate Router | sha256:b81e… | 2027-03-31 | 10 years (regulatory) |
| Coordinated vulnerability disclosure policy v2.1 | Policy | Public | Annex I Part II(5) · organisation | sha256:0f9c… | 2027-01-15 | 10 years |
| CRA-2026-0007 — early warning receipt (ENISA SRP) | Submission evidence | Restricted | Art. 14(2)(a) · case CRA-2026-0007 | sha256:3c1f… | — | 10 years · legal hold |
| Support period rationale — SensorLink Firmware | Decision record | Internal | Art. 13(8) · SensorLink Firmware | sha256:77aa… | 2027-01-01 | 10 years |
| Reporting drill 2026-06 — findings and actions | Drill report | Internal | Readiness · reporting | sha256:e2d0… | 2026-12-01 | 10 years |
Audit history
Demo data · Acme Connected Systems GmbH is fictionalAn append-only, hash-chained log per organisation: who changed which decision, when, with the previous and new value. Verifiable and exportable; it cannot be edited, not even by Vellaci.
| # | Time | Actor | Action | Entity | Chain hash |
|---|---|---|---|---|---|
| 4812 | 2026-09-23 11:00:12 | L. Brandt | cra_case.corrective_measure_recorded | CRA-2026-0007 | 5e0b…c3a1 |
| 4811 | 2026-09-20 15:10:44 | A. Rossi | cra_case.stage_submitted | CRA-2026-0007 · notification | 9a4d…17f0 |
| 4810 | 2026-09-20 15:09:58 | A. Rossi | report_snapshot.signed | notification rev. 2 | 2b77…88de |
| 4809 | 2026-09-18 21:30:03 | A. Rossi | cra_case.stage_submitted | CRA-2026-0007 · early warning | 3c1f…4be2 |
| 4808 | 2026-09-18 08:20:31 | A. Rossi | vulnerability.reportability_reviewed | CVE-2023-44487 → confirmed | c0a9…e51d |
| 4807 | 2026-09-18 08:11:07 | M. Keller | vulnerability.awareness_set | CVE-2023-44487 · rev. 1 | 71d3…0a6f |
| 4806 | 2026-09-18 08:05:49 | M. Keller | vulnerability.triaged | CVE-2023-44487 · affected | d4e8…9c02 |
| 4805 | 2026-09-18 06:44:15 | vellaci-system | vulnerability.finding_created | 7 findings · EdgeGate Router 3.2.0 | a1f2…b3c4 |
Every screen above exists in the free Evaluation workspace with your own product. The seeded demo workspace that Vellaci operators use in live walkthroughs carries the same fictional organisation, flagged as demo data in every table.
Read next
- Guide
CRA Article 14 reporting obligations: a practical guide for manufacturers
What must be reported under Article 14 of the Cyber Resilience Act, by whom, to whom and when — the 24-hour early warning, 72-hour notification and final report — and how to operationalise it now that the obligation is in force (since 11 September 2026).
- Guide
SBOM guide for the CRA: formats, minimum content and operations
CycloneDX versus SPDX, what a CRA-oriented SBOM must contain, which tools generate one per ecosystem, how to keep it current per release, how to share it, and how it feeds vulnerability handling and VEX.
- Guide
CRA vulnerability handling requirements: what Annex I Part II asks of manufacturers
The eight vulnerability-handling requirements in Annex I Part II, what each one means operationally, the evidence an authority or auditor would expect, and how to run them as one workflow from SBOM to security update.
- Guide
CRA evidence management: what to keep, for how long, and how to keep it provable
The Cyber Resilience Act is evidenced with records, not statements. Which records an authority, notified body, customer or auditor will ask for, the ten-year retention rule, and the properties — provenance, integrity, linkage, retrievability — that make a record count.
- Docs
Your first 15 minutes
From sign-up to the first vulnerable component.
- Docs
Runbook and drills
Organisation readiness and simulated exercises.
Ready to see it with your data?
Create a free Evaluation workspace, upload one SBOM and watch exposure, triage and the reporting workflow connect — or take the eight-minute assessment first.