The evidence, mapped to the mandate.
A signed CycloneDX SBOM and provenance attestation for every component is the same artifact a dozen regulations are circling. Here's where Attestree's evidence fits each one — and, just as importantly, where it stops.
How Attestree maps to the EU CRA
The CRA's machine-readable SBOM requirement (Annex I Part II(1)), the 2026–2027 deadlines, and the exact capability-to-obligation mapping — with the obligations Attestree does not cover named plainly.
Read moreNIS2 software asset inventory and supply-chain evidence
The Article 21(2) mapping — asset management, supply-chain security, vulnerability handling — plus why a Swiss supplier meets NIS2 as a questionnaire rather than a regulator, and the obligations that stay with you.
Read moreSBOM at ingest for SaaS engineering
The engineering-org view: signed CycloneDX SBOMs that map to EU CRA, EO 14028 and CISA Secure-by-Design evidence requests — without a security team slowing delivery down.
Read moreAudit evidence for financial services
Signed, exportable provenance for regulated Windows fleets — so you stop hand-rolling the evidence examiners ask for.
Read moreInformational, not legal advice.