CRA vulnerability management from detection to deployment.
Farion connects vulnerability discovery, application-specific assessment, ownership, remediation, merge tracking, deployment tracking, and technical evidence in one traceable workflow for products with digital elements.
Farion supports vulnerability handling and technical documentation under Regulation (EU) 2024/2847. The manufacturer remains responsible for its conformity assessment and legal obligations.
Turn scanner findings into managed engineering work.
The Cyber Resilience Act introduces cybersecurity requirements across the product lifecycle and requires manufacturers to handle vulnerabilities during the support period. Farion provides the application-security workflow for discovering, assessing, assigning, remediating, and documenting software vulnerabilities.
1. Identify components and findings
Generate SAST and SCA findings across source code, direct dependencies, transitive dependencies, containers, VMs, and imported SBOMs.
2. Assess application-specific impact
Use route context, vulnerable-function reachability, tainted paths, current vulnerability intelligence, and Active Verification to determine how the finding affects the product.
3. Assign and remediate
Set the priority, assign the responsible person, document comments and decisions, generate an AI-assisted fix, and create a pull or merge request.
4. Track the fix into deployment
Record when the change was merged, when it was deployed, and when the corrected state was verified.
Preserve the complete timeline behind every vulnerability decision.
The Finding History and Audit Log record when an issue was first detected, which evidence was available, how its priority and ownership changed, when a fix was produced, and when the corrected version reached the relevant environment.
First detected
Evidence collected
Impact assessed
Owner assigned
Fix generated
PR or MR created
Merged
Deployed
Verified
Connect the component inventory to affected-status decisions.
Generate CycloneDX or SPDX SBOMs across direct and transitive application dependencies. Produce evidence-backed VEX for application dependency findings and retain the technical context used to classify the component.
Export the evidence required by internal and external reviewers.
Farion provides SBOM, VEX, Finding History, Audit Logs, SARIF, PDF reports, APIs, and custom enterprise reports. These artifacts support vulnerability handling and technical documentation. They do not replace the manufacturer’s complete conformity assessment.
Scope of Farion
Farion supports software vulnerability discovery, assessment, remediation, tracking, and technical evidence. Product risk assessment, conformity assessment, CE marking, regulatory submissions, organizational controls, and the final legal classification remain the responsibility of the manufacturer.
Frequently asked questions
Yes. Farion records the finding’s first detection, assessment, assignment, remediation, pull or merge request, merge, deployment, and verification history.
According to the European Commission, the CRA entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026, while the main obligations apply from 11 December 2027.
See how Farion works on your application.
Request a guided evaluation or walk through the relevant workflow with our technical team.