The evidence, mapped to the mandate.
A CycloneDX SBOM and an attestation for each component is the evidence a dozen regulations are circling. Here's where Attestree's evidence fits each one — and, just as importantly, where it stops.
How Attestree maps to the EU CRA
The CRA's machine-readable SBOM requirement (Annex I Part II(1)), the 2026–2027 deadlines, and the exact capability-to-obligation mapping — with the obligations Attestree does not cover named plainly.
Read moreNIS2 software asset inventory and supply-chain evidence
The Article 21(2) mapping — asset management, supply-chain security, vulnerability handling — plus why a Swiss supplier meets NIS2 as a questionnaire rather than a regulator, and the obligations that stay with you.
Read moreSBOM at ingest for SaaS engineering
The engineering-org view: CycloneDX SBOMs at ingest for EU CRA and EO 14028 SBOM requests. A horizon segment: winget ingest ships today, the npm and pip ingest it needs does not yet.
Read moreAudit evidence for financial services
Signed, exportable audit evidence for regulated Windows fleets. A horizon segment: the framework-mapped evidence packs are on the roadmap.
Read moreInformational, not legal advice.