Drivesec unveils SaaS platform to automate Cyber Resilience Act compliance

Turin, Italy — September 1, 2026

Drivesec’s AI-powered solution automates the creation and maintenance of the technical documentation required by the EU’s new cybersecurity regulation for digital products. Starting in late September, it will be accessible to a first group of companies through a Private Beta version.

Drivesec, an Italian company specializing in cybersecurity for automotive and IoT, today announced the development of its CRA Platform, a SaaS solution designed to support manufacturers, importers and distributors on their path to compliance with the Cyber Resilience Act (EU Regulation 2024/2847).

Regulatory context. The Cyber Resilience Act is the EU regulation that, for the first time, introduces mandatory cybersecurity requirements for all products with digital elements sold in the European Union: connected devices, embedded components, industrial equipment, software, and the open-source components shipped with them. It covers an estimated 90% of the hardware and software placed on the EU market, shifting direct responsibility for product security from end users onto manufacturers.

The regulation entered into force in December 2024. Starting September 2026 – the same month in which Drivesec is unveiling its platform – the first concrete obligations take effect: companies will be required to report actively exploited vulnerabilities and security incidents within strict deadlines (24 hours for an early warning, 72 hours for formal notification, 14 days for the final report). Full enforcement of the regulation, including mandatory CE marking, is expected by December 2027.

Drivesec’s solution. The CRA Platform is an AI-based solution that uses information the customer’s company already holds about its products – such as technical specifications – to automatically generate the documentation required under the Cyber Resilience Act: from the Item Definition to the Risk Assessment and Test Plan. The platform also includes:

  • generation and management of product-specific CRA compliance artifacts such as Item Definition, Risk Assessment, Vulnerability Management process;
  • generation of cybersecurity requirements, countermeasures and test plans;
  • a vulnerability management system with an AI-supported PSIRT (Product Security Incident Response Team);
  • Incident notification and management

The goal is to reduce the manual workload currently placed on engineering, cybersecurity and compliance teams, while ensuring continuous compliance over time – release after release – rather than a one-off certification exercise.

Expected results. According to Drivesec’s estimates, using the platform can reduce the time required to prepare CRA documentation by 70-80%, cut compliance-related operational costs by 60-70%, and reduce errors and non-conformities found during audits by 90%. Documentation can also be updated in under 24 hours following a software or firmware change, with full traceability maintained across all documents and evidence.

“We are very excited to bring this new product to market. We believe it will support product makers on their journey toward compliance with this important new regulation. Our SaaS platform will bring greater efficiency to the compliance process, reduce costs, and provide full control throughout the compliance lifecycle.”, said Giuseppe Faranda Cordella, CEO of Drivesec.

The Private Beta. Starting in late September 2026, the CRA Platform will be available to a first group of companies through a Private Beta, giving early access to the platform’s core features and the chance to shape upcoming releases through direct feedback.

Companies interested in joining the Private Beta can request information by emailing marketing@drivesec.com or by visiting the dedicated page on our website at LINK.

Watch the webinar: