Skip to main content

The permanent product-security record for the EU market.

Permenta is where makers of software and connected products do what the Cyber Resilience Act asks of them, and keep the proof: product registry and scope, SBOMs and their vulnerabilities, Article 14 reports filed against the clock, the technical file, advisories, and a record you can hand to a customer or an authority ten years from now.

Free for one product. No card needed.

Kestrel Router firmware

Sample record, release 4.2

  1. Release 4.2.1 registered

    SBOM anchored: CycloneDX 1.6, 412 components, three licences flagged for review.

  2. Actively exploited vulnerability matched

    A bundled library is on the KEV and EUVD lists. Article 14 case opened; the 24-hour clock started.

  3. Early warning submitted

    Single Reporting Platform reference recorded, 17 hours and 6 minutes after awareness.

  4. Security update 4.2.2 published

    Availability recorded for the rest of the support period, as Article 13(9) asks.

  5. Advisory published

    CSAF 2.0 document issued; the public trust page updated itself.

  6. Final report submitted

    Four days after the fix was available. Case closed; every step above stays on the record.

A sample record for a fictional product. Every event is appended with its timestamp and a hash that links it to the entry before it; nothing is edited later, only added.
  1. In force since

    Reporting obligations apply

    Actively exploited vulnerabilities and severe incidents go to ENISA’s Single Reporting Platform: early warning within 24 hours, notification within 72 hours, final report within 14 days.

  2. Today

    14 days into the reporting obligation, 442 days until the rest applies

    Products already on the EU market are covered by the reporting duty; the rest of the Act reaches them when they are substantially modified.

  3. From

    The rest of the Act applies

    Technical documentation, the EU declaration of conformity and CE marking for products placed on the market, with a support period of at least five years.

What you get

Six modules in the order the work happens: register, know what is inside, watch, report, document, prove.

  • Product registry and scope wizard

    Register each product once. The wizard walks the Act’s scope questions and product classes and records the answer with its reasoning, including an honest “uncertain, seek advice” outcome.

    Default, important class I and II, and critical products; legacy products placed on the market before 11 December 2027.

  • SBOM and vulnerability operations

    Upload SBOMs from CI. Components are matched against vulnerability feeds every day; a finding keeps its identity across releases, so triage and VEX statements survive the next upload.

    CycloneDX 1.4 to 1.7 and SPDX 2.3; matched against OSV, KEV, EUVD and EPSS.

  • Article 14 reporting desk

    When an actively exploited vulnerability or a severe incident surfaces, open a case and the clocks start. Guided forms mirror the Single Reporting Platform field by field, and every submission is recorded with its reference.

    24 hours for the early warning, 72 hours for the notification, 14 days for the final report on a vulnerability (one month for an incident).

  • Technical file and declaration of conformity

    An Annex VII-structured workspace with editable drafts, evidence coverage per section, approvals and versioned exports. Every generated document says it is a draft until you have reviewed it.

    Annex VII structure, Annex V declaration; tagged PDF, Markdown and ZIP exports.

  • CSAF advisories

    Publish machine-readable advisories with a human-readable page, an index that CSAF consumers can discover, and the contact files the Act and RFC 9116 expect.

    CSAF 2.0 with provider-metadata.json, security.txt and a coordinated-disclosure policy.

  • Ten-year evidence ledger and public trust page

    Every release, update, advisory, support period and filing is appended to a hash-chained ledger. A public trust page per product shows customers and authorities what you publish, and expiring share links open the rest to an auditor.

    Append-only, kept for ten years: the retention period the Act sets for technical documentation.

Who it is for

Teams of five to two hundred who ship products with digital elements into the EU, use GitHub or GitLab, and have no compliance department.

  • Downloadable software
  • Mobile and desktop apps
  • Plugins and extensions
  • Self-hosted software
  • Firmware and connected devices

Based outside the EU? The Act applies to products placed on the EU market wherever the maker sits, and exporters are the least served by EU-local vendors. Permenta is built with you in mind: prices in euro or dollars, Article 14 guidance written for a first-time reporter, and a public trust page that answers your European customers before they ask.

Agencies and consultancies serving several such clients get separate workspaces per client on the Scale plan.

Pricing

Every workspace starts free with one product. Upgrade from inside the workspace when you register more, or when you want the reporting desk and exports.

  • Free

    0 €per month

    Your first product, on the record.

    • 1 product
    • 2 members
    • 1 SBOM upload a month
    • Public trust page and security.txt
    • Scope wizard and obligations checklist
    • Disclosure-policy generator
    • Article 14 dry run
  • Starter

    99 €per month

    A small catalogue with live monitoring.

    • Everything in Free
    • 3 products
    • 5 members
    • Unlimited SBOM uploads
    • Continuous vulnerability monitoring
    • Article 14 reporting desk
    • Advisory and technical-file drafts
    • Security advisories (CSAF 2.0)
    • API keys and CLI
  • Recommended for teams with several products

    Growth

    299 €per month

    Several products and people who need to see the evidence.

    • Everything in Starter
    • 15 products
    • 20 members
    • Unlimited SBOM uploads
    • VEX exports
    • CSAF advisory feeds
    • Share links for customers and auditors
    • Slack alerts
    • Document approvals
    • Supplier diligence
  • Scale

    799 €per month

    Whole portfolios and agencies.

    • Everything in Growth
    • Unlimited products
    • Unlimited members
    • Unlimited SBOM uploads
    • Agency workspaces
    • Audit exports
    • Priority support

Prices in euro, excluding VAT. Annual billing costs 10 times the monthly price, and the same figures are available in US dollars. Compare plans and read the billing questions.

Start with one product, free.

Register it, answer the scope questions and see that product’s obligations timeline in an afternoon. No card needed.

A stack of ruled paper sheets held down by one bronze seal.

What Permenta is not

Permenta provides tooling and evidence management; it does not certify compliance. Whether a product meets the Act’s requirements is your assessment, or your notified body’s. Permenta makes the work easier to do and the evidence easier to keep and show.