CYBERFORT: A Compliance-Chain Platform Operationalising the Cyber Resilience Act for SMEs

📅 2026-10-07
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenges small and medium-sized enterprises face in fulfilling the full lifecycle compliance obligations of the EU Cyber Resilience Act by developing an open-source compliance platform. Methodologically, it introduces a "compliance chain" structure that seamlessly links risk assessments, controls, policies, and machine-attested evidence to technical documentation and EU declarations of conformity. Furthermore, the platform integrates ISO/IEC 27001, NIS2, and GDPR controls while incorporating AI-driven remediation and an automated evidence collection engine to enable end-to-end traceability. The proposed solution has been deployed across 43 organizations, and its efficacy in identifying and closing operational gaps was validated through an end-to-end SIEM/XDR case study.
📝 Abstract
The EU Cyber Resilience Act (CRA) turns product cybersecurity into a lifecycle compliance obligation for manufacturers, importers, distributors, and integrators of products with digital elements on the EU market, a load that falls largely on small and medium-sized enterprises (SMEs) that rarely have dedicated governance, risk, and compliance (GRC) capacity. We present CYBERFORT, an open-source CRA-first compliance platform developed under the EU Digital Europe Programme and one of twelve projects in the EU CRA cluster. CYBERFORT operationalises the CRA through a guided scope self-assessment, a question bank tied to Annex I and the vulnerability-handling obligations, and a compliance-checking engine that links every answer to controls, policies, and machine-attested evidence, reusing ISO/IEC 27001, NIS2, and GDPR controls only where they coincide with CRA obligations. Its central contribution is the compliance chain, a traceable structure linking each product risk through its controls and policies to the CRA obligations it satisfies, and onward through evidence to the technical-documentation file and EU declaration of conformity, so that every operational gap is traceable and can be closed before market placement. Deployed at https://access.cyber-fort.eu/ for a first cohort of 43 organisations, the platform is presented with the engineering behind the chain, measured results from a completed end-to-end case study on a SIEM/XDR product with AI-driven remediation spanning the CRA obligation chapters, and the controlled effort study that remains in progress.
Problem

Research questions and friction points this paper is trying to address.

Cyber Resilience Act
SMEs
compliance
cybersecurity
GRC
Innovation

Methods, ideas, or system contributions that make the work stand out.

Compliance Chain
Cyber Resilience Act
Traceability
Automated Compliance Engine
AI-driven Remediation
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
N
Nikolaos Kekatos
Clone Systems, Cyprus