# Complioty - Cyber Security Compliance Platform > Complioty is a cyber security compliance platform built for manufacturers who need to comply with the EU Cyber Resilience Act (CRA). The platform covers vulnerability monitoring, threat modeling, SBOM management, and coordinated vulnerability disclosure across the entire product lifecycle. ## About the EU Cyber Resilience Act (CRA) The EU Cyber Resilience Act is European legislation that establishes mandatory cybersecurity requirements for products with digital elements. It requires manufacturers to: - Perform risk assessments and threat modeling for their products - Monitor and remediate known vulnerabilities throughout the product lifecycle - Maintain a Software Bill of Materials (SBOM) for each product - Implement coordinated vulnerability disclosure (CVD) processes - Report actively exploited vulnerabilities within 24 hours Complioty provides an integrated platform to address all of these requirements. ## Apps ### Designer **Threat Modeling & Security Architecture** The Designer app enables manufacturers to create and maintain threat models for their products with digital elements. Features include: - Visual threat modeling with data flow diagrams - STRIDE-based threat identification - Risk assessment and mitigation tracking - Security requirement generation aligned with CRA Annex I - Export and documentation for audit purposes [Learn more](https://complioty.de/apps/designer) ### Observer **Vulnerability Monitoring & CVE Tracking** The Observer app continuously monitors product components for known vulnerabilities. Features include: - Automated CVE matching against product SBOMs - Integration with NVD, CISA KEV, ExploitDB, and EPSS scoring - Risk prioritization based on exploitability and impact - Continuous monitoring with alerting - Audit-ready vulnerability assessment reports proving products have no known exploitable vulnerabilities [Learn more](https://complioty.de/apps/observer) ### Tracer **SBOM Management & Supply Chain Tracking** The Tracer app manages Software Bills of Materials across the supply chain. Features include: - SBOM import and generation (CycloneDX, SPDX formats) - Component dependency tracking and visualization - License compliance checking - Supply chain risk assessment - Supplier management and component provenance tracking [Learn more](https://complioty.de/apps/tracer) ### Notifier **Coordinated Vulnerability Disclosure & Incident Notification** The Notifier app handles vulnerability disclosure and regulatory notification workflows. Features include: - Coordinated vulnerability disclosure (CVD) process management - ENISA/CSIRT notification workflows compliant with CRA Article 14 - 24-hour early warning and 72-hour incident notification templates - Stakeholder communication management - Disclosure timeline tracking and documentation [Learn more](https://complioty.de/apps/notifier) ## Solutions by Industry ### Maschinen- und Anlagenbauer (Machinery & Equipment Manufacturers) Complioty helps machinery and equipment manufacturers who build complex systems with embedded software and networked components to achieve CRA compliance. These manufacturers face challenges with large product portfolios, long lifecycles, and deep supply chains. [Learn more](https://complioty.de/solutions/maschinen-und-anlagenbauer) ### Komponentenhersteller (Component Manufacturers) Component manufacturers supplying digital components (controllers, sensors, communication modules) to OEMs need to provide security documentation and SBOM data to their customers. Complioty streamlines this process. [Learn more](https://complioty.de/solutions/komponentenhersteller) ### Bauteilhersteller (Parts Manufacturers) Parts manufacturers producing sub-components with embedded firmware must ensure their products meet CRA requirements and can provide required security artifacts to integrators. [Learn more](https://complioty.de/solutions/bauteilhersteller) ## Pricing Complioty offers tiered pricing plans: - **Starter**: For small teams getting started with CRA compliance. Includes basic threat modeling, SBOM management, and vulnerability monitoring. - **Professional**: For growing organizations with multiple products. Adds advanced features, team collaboration, and priority support. - **Enterprise**: For large manufacturers with complex supply chains. Includes custom integrations, dedicated support, SSO, and on-premise deployment options. Contact sales for current pricing: [https://complioty.de/contact](https://complioty.de/contact) ## Blog Articles ### Wie Hersteller nachweisen, dass ihre Produkte keine relevanten Schwachstellen haben - **Date**: 2025-02-05 - **Author**: Dr. Philip Empl - **Summary**: Explains why "no vulnerabilities" is not a state but a proof — and how CVEs, CISA KEV, ExploitDB, and EPSS together provide a reliable evidence base for the security of industrial products. - [Read more](https://complioty.de/blog/hello-world) ### Cyber Resilience Act - Was Hersteller jetzt wissen muessen - **Date**: 2025-01-25 - **Summary**: The EU Cyber Resilience Act is coming — what it means for your business and how to prepare. - [Read more](https://complioty.de/blog/cra-guide) ### SBOM - Software Bill of Materials verstehen - **Date**: 2025-01-20 - **Author**: Dr. Markus Hornsteiner - **Summary**: What is an SBOM and why is it becoming increasingly important for businesses? A comprehensive guide. - [Read more](https://complioty.de/blog/sbom-guide) ## Company Information - **Company**: Complioty (by Silenccio GmbH) - **Location**: Germany - **Website**: [https://complioty.de](https://complioty.de) - **Contact**: [https://complioty.de/contact](https://complioty.de/contact) ## Technical Details - **Platform Type**: SaaS (cloud-hosted) with optional on-premise deployment - **API**: REST API with OpenAPI specification - **Authentication**: OAuth 2.0 / SSO support - **SBOM Formats**: CycloneDX, SPDX - **Integrations**: CI/CD pipelines, vulnerability databases (NVD, CISA KEV, ExploitDB) - **Data Residency**: EU (Germany)