CRA vulnerability management for machine and plant builders — from your own firmware to supplier components.
Monitor vulnerabilities in your own software and in supplier components centrally, assess them per installation, document them and report within the 24-hour deadline.
Request a free demo
Part of the VDMA Startup MachineUnder the CRA, actively exploited supplier vulnerabilities must be passed on within 24 hours.
Hundreds of components from dozens of suppliers across hundreds of installations.
Unstructured supplier feeds — from CSAF to email.
24-hour reporting deadline from September 2026 — barely feasible by hand.
Werkspilot covers the entire CRA process in a single platform.
Create SBOMs
Software bills of materials, automated from TIA export, ERP or network scan.
Monitor supplier feeds
Capture advisories from structured CSAF to informal email.
Monitor your own software
Check your own software and firmware continuously for new CVEs.
Assess exposure
Map vulnerabilities to each installation, assess exploitability and filter out the noise.
Manage documentation
Maintain CRA evidence, checklists and the technical documentation centrally — per installation.
Report on time
Report vulnerabilities automatically to the ENISA reporting platform and to customers.
STRIDE threat analysis of your installations for CRA and the Machinery Regulation.
From 20 January 2027, the new Machinery Regulation (EU) 2023/1230 requires a traceable cybersecurity risk assessment for new installations — and so does the CRA. We deliver it as a STRIDE threat analysis, documented in an auditable form.
“With Werkspilot we have a capable partner who supports us in meeting the requirements of the Cyber Resilience Act – both as advisors and technically, from risk analysis through to implementing systematic vulnerability monitoring.”
Günter Arztmiller
Managing Director, The Imaging Source GmbH


Articles on the CRA and the Machinery Regulation.
Cybersecurity roadmap for machine and plant builders: what has to be ready by when
The CRA and Machinery Regulation deadlines are well known – the roadmap behind them is not. What actually has to be finished by 11 Sep 2026, 20 Jan 2027 and 11 Dec 2027, in the order in which each step depends on the previous one.
CRA reporting obligation from September 2026: What must be reported for machines and plants?
On 11 September 2026 the Cyber Resilience Act's reporting obligations take effect – more than a year before the rest of the CRA. What must be reported (and what not), which deadlines apply, how ENISA's Single Reporting Platform (SRP) works, and what can be prepared today.
Frequently asked questions on the CRA, the Machinery Regulation and vulnerability management for machine and plant builders and integrators.
Request a demo now.
See how you can manage vulnerabilities for your installations simply and meet every reporting deadline.
