This section is The content in this section is supplied by GlobeNewswire for the purposes of distributing press releases on behalf of its clients. Postmedia has not reviewed the content. by GlobeNewswire Article content

Visure provides the traceability, SBOM management, and signed baseline infrastructure for CRA compliance demands

Sign In or Create an Account

or View more offersArticle content

SAN FRANCISCO, Sept. 02, 2026 (GLOBE NEWSWIRE) — Visure Solutions today announced its EU Cyber Resilience Act (CRA) compliance solution, enabling manufacturers of products with digital elements to meet every CRA obligation, from Annex I essential cybersecurity requirements and Article 14 vulnerability reporting through 10-year Annex VII documentation retention. The launch coincides with Article 14 reporting obligations activating on 11 September 2026, requiring manufacturers to report actively exploited vulnerabilities to the European Union Agency for Cybersecurity (ENISA) and national Computer Security Incident Response Teams (CSIRTs) within 24 hours.

Article contentWe apologize, but this video has failed to load.Try refreshing your browser, or
tap here to see other videos from our team.Article content

Story continues below

This advertisement has not loaded yet, but your article continues below.

Article content

“CRA compliance is not a one-time documentation exercise. It is a structured engineering process that runs from Day 1 of product design through the end of the support period,” said Fernando Valera, CTO at Visure Solutions. “Manufacturers who treat it as a documentation task will find themselves unable to respond to Article 14 incidents in time, unable to reproduce a historical baseline for a market surveillance audit, and unable to demonstrate a governed process to notified bodies.”

Article contentArticle content

Transforming Fragmented Compliance into Governed Engineering

Article content

CRA obligations, from tracing each Annex I clause to a verified design decision and maintaining a machine-readable SBOM, to retaining evidence for 10 years and responding to vulnerabilities in 24 hours, are engineering process obligations, not documentation tasks. Without live traceability across the product lifecycle, compliance becomes a costly retrospective effort market surveillance authorities are unlikely to accept.

Article contentArticle contentArticle contentArticle content

Visure ALM Integrated CRA Compliance Workflow: Displays end-to-end traceability across engineering disciplines and domain-specific toolchains for CRA obligations.

Article content

Story continues below

This advertisement has not loaded yet, but your article continues below.

Article content

Visure’s platform maps directly to each CRA obligation, replacing fragmented tools with a single governed engineering environment. Through Visure, manufacturers can:

Article content

  • Trace Every Requirement to Evidence: Annex I clauses imported as structured items, linked to risks, design decisions, and verified tests via a live Traceability Matrix. Suspect links fire automatically on any upstream change.
  • Respond to Vulnerabilities with SBOM-Driven Traceability: When a Common Vulnerabilities and Exposures (CVE) entry is reported, blast-radius analysis surfaces every affected requirement, baseline, and product version instantly. Article 14 SLA deadlines of 24 hours, 72 hours, and 14 days are tracked live.
  • Generate Technical Audit Packs on Demand: The Annex VII evidence pack built continuously from engineering work and exported from a signed baseline in minutes via Word or ReqIF.
  • Sign Baselines, Freeze and Reproduce Any Release: Requirements pass through governed review workflows before entering electronically signed, immutable baselines, fully restorable years later for any market surveillance request.
  • Define Security Requirements with AI: Vivia (Visure Virtual Assistance), Visure’s on-premise AI engine, generates CRA-aligned requirement drafts from Annex I clauses in hours. Human sign-off is required before any baseline entry. Zero data leaves the customer environment.