The permanent product-security record for the EU market.
Permenta is where makers of software and connected products do what the Cyber Resilience Act asks of them, and keep the proof: product registry and scope, SBOMs and their vulnerabilities, Article 14 reports filed against the clock, the technical file, advisories, and a record you can hand to a customer or an authority ten years from now.
Free for one product. No card needed.
Kestrel Router firmware
Sample record, release 4.2
Release 4.2.1 registered
SBOM anchored: CycloneDX 1.6, 412 components, three licences flagged for review.
Actively exploited vulnerability matched
A bundled library is on the KEV and EUVD lists. Article 14 case opened; the 24-hour clock started.
Early warning submitted
Single Reporting Platform reference recorded, 17 hours and 6 minutes after awareness.
Security update 4.2.2 published
Availability recorded for the rest of the support period, as Article 13(9) asks.
Advisory published
CSAF 2.0 document issued; the public trust page updated itself.
In force since
Reporting obligations apply
Actively exploited vulnerabilities and severe incidents go to ENISA’s Single Reporting Platform: early warning within 24 hours, notification within 72 hours, final report within 14 days.
Today
14 days into the reporting obligation, 442 days until the rest applies
Products already on the EU market are covered by the reporting duty; the rest of the Act reaches them when they are substantially modified.
From
The rest of the Act applies
Technical documentation, the EU declaration of conformity and CE marking for products placed on the market, with a support period of at least five years.
What you get
Six modules in the order the work happens: register, know what is inside, watch, report, document, prove.
Product registry and scope wizard
Register each product once. The wizard walks the Act’s scope questions and product classes and records the answer with its reasoning, including an honest “uncertain, seek advice” outcome.
Default, important class I and II, and critical products; legacy products placed on the market before 11 December 2027.
SBOM and vulnerability operations
Upload SBOMs from CI. Components are matched against vulnerability feeds every day; a finding keeps its identity across releases, so triage and VEX statements survive the next upload.
CycloneDX 1.4 to 1.7 and SPDX 2.3; matched against OSV, KEV, EUVD and EPSS.
Article 14 reporting desk
When an actively exploited vulnerability or a severe incident surfaces, open a case and the clocks start. Guided forms mirror the Single Reporting Platform field by field, and every submission is recorded with its reference.
24 hours for the early warning, 72 hours for the notification, 14 days for the final report on a vulnerability (one month for an incident).
Technical file and declaration of conformity
An Annex VII-structured workspace with editable drafts, evidence coverage per section, approvals and versioned exports. Every generated document says it is a draft until you have reviewed it.
Annex VII structure, Annex V declaration; tagged PDF, Markdown and ZIP exports.
CSAF advisories
Publish machine-readable advisories with a human-readable page, an index that CSAF consumers can discover, and the contact files the Act and RFC 9116 expect.
CSAF 2.0 with provider-metadata.json, security.txt and a coordinated-disclosure policy.
Ten-year evidence ledger and public trust page
Every release, update, advisory, support period and filing is appended to a hash-chained ledger. A public trust page per product shows customers and authorities what you publish, and expiring share links open the rest to an auditor.
Append-only, kept for ten years: the retention period the Act sets for technical documentation.
Who it is for
Teams of five to two hundred who ship products with digital elements into the EU, use GitHub or GitLab, and have no compliance department.
- Downloadable software
- Mobile and desktop apps
- Plugins and extensions
- Self-hosted software
- Firmware and connected devices
Based outside the EU? The Act applies to products placed on the EU market wherever the maker sits, and exporters are the least served by EU-local vendors. Permenta is built with you in mind: prices in euro or dollars, Article 14 guidance written for a first-time reporter, and a public trust page that answers your European customers before they ask.
Agencies and consultancies serving several such clients get separate workspaces per client on the Scale plan.
Pricing
Every workspace starts free with one product. Upgrade from inside the workspace when you register more, or when you want the reporting desk and exports.
Free
0 €per month
Your first product, on the record.
- 1 product
- 2 members
- 1 SBOM upload a month
- Public trust page and security.txt
- Scope wizard and obligations checklist
- Disclosure-policy generator
- Article 14 dry run
Starter
99 €per month
A small catalogue with live monitoring.
- Everything in Free
- 3 products
- 5 members
- Unlimited SBOM uploads
- Continuous vulnerability monitoring
- Article 14 reporting desk
- Advisory and technical-file drafts
- Security advisories (CSAF 2.0)
- API keys and CLI
Recommended for teams with several products
Growth
299 €per month
Several products and people who need to see the evidence.
- Everything in Starter
- 15 products
- 20 members
- Unlimited SBOM uploads
- VEX exports
- CSAF advisory feeds
- Share links for customers and auditors
- Slack alerts
- Document approvals
- Supplier diligence
Scale
799 €per month
Whole portfolios and agencies.
- Everything in Growth
- Unlimited products
- Unlimited members
- Unlimited SBOM uploads
- Agency workspaces
- Audit exports
- Priority support
Prices in euro, excluding VAT. Annual billing costs 10 times the monthly price, and the same figures are available in US dollars. Compare plans and read the billing questions.
Start with one product, free.
Register it, answer the scope questions and see that product’s obligations timeline in an afternoon. No card needed.

What Permenta is not
Permenta provides tooling and evidence management; it does not certify compliance. Whether a product meets the Act’s requirements is your assessment, or your notified body’s. Permenta makes the work easier to do and the evidence easier to keep and show.