Visure Solutions has unveiled a compliance solution tailored for manufacturers of products with digital elements, targeting the European Union’s Cyber Resilience Act (CRA). The announcement comes just days before Article 14 of the regulation takes effect on September 11, 2026, requiring manufacturers to report actively exploited vulnerabilities to the European Union Agency for Cybersecurity (ENISA) and national Computer Security Incident Response Teams (CSIRTs) within 24 hours.
The CRA, which sets cybersecurity requirements for hardware and software products, imposes obligations that span the entire product lifecycle, from design to end-of-support. According to Fernando Valera, CTO at Visure Solutions, compliance is not a one-time documentation exercise but a structured engineering process. ‘Manufacturers who treat it as a documentation task will find themselves unable to respond to Article 14 incidents in time, unable to reproduce a historical baseline for a market surveillance audit, and unable to demonstrate a governed process to notified bodies,’ Valera said in a press release.
Visure’s ALM (Application Lifecycle Management) platform aims to address these challenges by providing end-to-end traceability across engineering disciplines. The system maps directly to CRA obligations, allowing manufacturers to trace every requirement to evidence. Annex I clauses are imported as structured items and linked to risks, design decisions, and verified tests via a live Traceability Matrix. Suspect links fire automatically on any upstream change, ensuring that alterations are promptly flagged for review.
For vulnerability response, the platform offers SBOM-driven traceability. When a Common Vulnerabilities and Exposures (CVE) entry is reported, a blast-radius analysis identifies all affected requirements, baselines, and product versions. Article 14 deadlines—24 hours, 72 hours, and 14 days—are tracked live, helping manufacturers meet their reporting obligations. The platform also generates technical audit packs on demand, compiling the Annex VII evidence pack from engineering work. These packs can be exported from a signed baseline in minutes via Word or ReqIF, facilitating market surveillance audits.
The system supports signing baselines, freezing releases, and reproducing any historical version. Requirements pass through governed review workflows before entering electronically signed, immutable baselines, which can be restored years later for any audit. Additionally, Visure’s on-premise AI engine, Vivia, can generate CRA-aligned requirement drafts from Annex I clauses in hours. Human sign-off is required before any baseline entry, and zero data leaves the customer environment, addressing data privacy concerns.
‘As manufacturers move toward operational CRA compliance, Visure provides the engineering foundation required to meet every obligation as a governed, repeatable process, not a documentation exercise,’ said Moustapha Tadlaoui, CEO at Visure Solutions. ‘Live traceability. Signed baselines. On-premise AI. All in one platform.’
The launch includes a webinar scheduled for September 24, 2026, titled ‘Ensuring Cyber Resilience Act (CRA) Compliance Across the Product Lifecycle,’ led by Fernando Valera. The session will cover Article 14 response workflows, Annex VII evidence pack generation, and AI requirements generation with Vivia. Registration is available at https://visuresolutions.com/webinars/cra-compliance-product-lifecycle/.
Visure Solutions specializes in AI-driven requirements management and ALM solutions for safety-critical industries, aiming to help regulated manufacturers improve quality and accelerate time-to-market. More information can be found at www.visuresolutions.com.
