Visure provides the traceability, SBOM management, and signed baseline infrastructure for CRA compliance demands
SAN FRANCISCO, Sept. 02, 2026 (GLOBE NEWSWIRE) — Visure Solutions today announced its EU Cyber Resilience Act (CRA) compliance solution, enabling manufacturers of products with digital elements to meet every CRA obligation, from Annex I essential cybersecurity requirements and Article 14 vulnerability reporting through 10-year Annex VII documentation retention. The launch coincides with Article 14 reporting obligations activating on 11 September 2026, requiring manufacturers to report actively exploited vulnerabilities to the European Union Agency for Cybersecurity (ENISA) and national Computer Security Incident Response Teams (CSIRTs) within 24 hours.
“CRA compliance is not a one-time documentation exercise. It is a structured engineering process that runs from Day 1 of product design through the end of the support period,” said Fernando Valera, CTO at Visure Solutions. “Manufacturers who treat it as a documentation task will find themselves unable to respond to Article 14 incidents in time, unable to reproduce a historical baseline for a market surveillance audit, and unable to demonstrate a governed process to notified bodies.”
Transforming Fragmented Compliance into Governed Engineering
CRA obligations, from tracing each Annex I clause to a verified design decision and maintaining a machine-readable SBOM, to retaining evidence for 10 years and responding to vulnerabilities in 24 hours, are engineering process obligations, not documentation tasks. Without live traceability across the product lifecycle, compliance becomes a costly retrospective effort market surveillance authorities are unlikely to accept.
Visure ALM Integrated CRA Compliance Workflow: Displays end-to-end traceability across engineering disciplines and domain-specific toolchains for CRA obligations.
Visure’s platform maps directly to each CRA obligation, replacing fragmented tools with a single governed engineering environment. Through Visure, manufacturers can:
- Trace Every Requirement to Evidence: Annex I clauses imported as structured items, linked to risks, design decisions, and verified tests via a live Traceability Matrix. Suspect links fire automatically on any upstream change.
- Respond to Vulnerabilities with SBOM-Driven Traceability: When a Common Vulnerabilities and Exposures (CVE) entry is reported, blast-radius analysis surfaces every affected requirement, baseline, and product version instantly. Article 14 SLA deadlines of 24 hours, 72 hours, and 14 days are tracked live.
- Generate Technical Audit Packs on Demand: The Annex VII evidence pack built continuously from engineering work and exported from a signed baseline in minutes via Word or ReqIF.
- Sign Baselines, Freeze and Reproduce Any Release: Requirements pass through governed review workflows before entering electronically signed, immutable baselines, fully restorable years later for any market surveillance request.
- Define Security Requirements with AI: Vivia (Visure Virtual Assistance), Visure’s on-premise AI engine, generates CRA-aligned requirement drafts from Annex I clauses in hours. Human sign-off is required before any baseline entry. Zero data leaves the customer environment.
“As manufacturers move toward operational CRA compliance, Visure provides the engineering foundation required to meet every obligation as a governed, repeatable process, not a documentation exercise,” Moustapha Tadlaoui, CEO at Visure Solutions, added. “Live traceability. Signed baselines. On-premise AI. All in one platform.”
Governed Traceability Architecture: Illustrates live requirement-to-evidence mapping, suspect-link flags, and real-time CVE impact analysis across releases.
Webinar September 24th: Ensuring CRA Compliance Across the Product Lifecycle
Join Fernando Valera, CTO of Visure Solutions, for Ensuring Cyber Resilience Act (CRA) Compliance Across the Product Lifecycle: Embedding Cybersecurity, Traceability, and Compliance from Design to Deployment. The webinar will cover Article 14 response workflows, Annex VII evidence pack generation, and AI requirements generation with Vivia.
Date/Times: September 24th, 2026 | 8:00 AM PST • 11:00 AM EST • 17:00 CEST
Register Now: https://visuresolutions.com/webinars/cra-compliance-product-lifecycle/
About Visure Solutions
Visure Solutions is a leading provider of AI-driven requirements management and ALM solutions, helping regulated manufacturers improve quality, ensure compliance, and accelerate time-to-market across safety-critical industries.
For more information, visit: www.visuresolutions.com
Media Contact
Marcelo Zegarra
Visure Solutions
+1 415 745-3304
marketing@visuresolutions.com
Photos accompanying this announcement are available at:
https://www.globenewswire.com/NewsRoom/AttachmentNg/24d14e3e-1c55-4dc1-945a-31db94cbf23a
https://www.globenewswire.com/NewsRoom/AttachmentNg/aaadc1d7-09b0-4bfe-9395-d8775bd3afd1

