For a machinery exporter, the product long consisted of nothing but mechanics and electrics. Today the same machine contains a control board, an operating system, communication libraries, an interface application and, more often than not, remote connectivity. Most of that software is not written from scratch either; it is assembled from ready-made components and open source libraries. The problem is that most manufacturers do not know exactly which components, at which versions, are inside their own product.
That blind spot squeezes from two sides. First, security: when a widespread vulnerability is disclosed in a library in use, the manufacturer's first question is whether its own product is affected — and a firm without an inventory cannot answer that question for days. Second, regulation: under the European Union's Cyber Resilience Act, the obligations on reporting actively exploited vulnerabilities and serious incidents begin on 11 September 2026, with defined timeframes for early warning, detailed notification and a final report after remediation. The full set of additional requirements becomes binding on 11 December 2027.
At the centre of the regime we build is the inventory. A software bill of materials is generated and stored for every version of the product; the answer to which component, at which version, under which licence, sits in which product and at which customer lives in one place. Known vulnerability sources are connected on top of this inventory; when a new vulnerability is disclosed, the affected products and versions are flagged automatically. Response time then depends on decision time, not search time.
The second piece is process. How will vulnerability reports be received, who will assess them, which notification is made in which case, how will the security update reach the customer, and how will you know whether the machine in the field has been updated? Without written answers to those questions, the inventory alone is not enough. Let us also draw an honest line here: the legal scoping assessment — which category your product falls into and which obligations it is subject to — is your legal adviser's territory. We build the technical infrastructure and the process.