CRA evidence

Secure-update evidence for EU CRA work

Meshanics connects what was approved, what devices received, what the devices reported, and how a vulnerability or incident case was handled. Issued evidence is packaged with hashes and signatures for independent verification.

Good fit

When to evaluate it

  • +Manufacturers of products with digital elements
  • +Product security teams preparing technical documentation
  • +Operators who need a traceable update and vulnerability history

Product boundary

What the current product does

A1

Product record

Define intended purpose, support period, classification rationale, versions, risk assessments and release-change decisions.

A2

Vulnerability exposure

SBOM packages are matched against release-specific vulnerability ecosystems and correlated with devices that report the affected artifact.

A3

Article 14 workflow

Progressive case records retain awareness rationale, report revisions, submission references, attachments and review state.

A4

Verifiable export

Issued dossiers contain a manifest of every included byte, signatures, verification keys and optional retention-locked managed copies.

Explicit limit

Evidence supports compliance work, not a compliance verdict. Meshanics does not decide product classification, notify ENISA, act as a conformity-assessment body, or replace legal advice.

Console proof

See the operational record

Meshanics vulnerability exposure screen
Vulnerability exposure - artifact findings correlated with reported fleet state.
Meshanics issued evidence verification screen
Issued evidence - verification state for a signed customer evidence package.

Questions

Are downloaded reports tamper-resistant?

Issued packages are signed and include a digest manifest for offline verification. A managed copy is described as immutable only when it is stored with enforced retention; an exported file can always be deleted by its holder.

Does Meshanics require changes to application code?

No. The static Linux agent installs on the device and activates signed payloads through typed adapters. Health behavior and recovery limits are configured for the artifact, not embedded in customer application code.

Does Meshanics certify CRA compliance?

No. Meshanics records and exports evidence for the manufacturer's compliance work. The manufacturer remains responsible for product scope, risk decisions, conformity assessment, reporting, and declarations.