Skip to content
Test page This is a test landing page. It is not indexed and submitted data may be deleted.
In development · Early access

SBOMs and 24-hour CRA reports, without the scramble.

Bomline keeps a machine-readable SBOM for every firmware and software release, matches it against new vulnerabilities, and walks you through the Cyber Resilience Act early warning, notification and final report — the reporting obligations that apply since 11 September 2026.

Free to join No spam €69 / month at launch

Problem01 / 07

Why it hurts today

  1. P-01

    The clock is already running. Since 11 September 2026, Article 14 of Regulation (EU) 2024/2847 requires an early warning within 24 hours of becoming aware of an actively exploited vulnerability in your product — including products placed on the market before the rest of the Regulation applies.

  2. P-02

    You can't answer "are we affected?" fast. Dependencies live across firmware images, mobile apps and cloud services, and the list of what shipped in which release is usually reconstructed from build logs after the fact.

  3. P-03

    Reporting is a process, not a form. Early warning, 72-hour notification, final report, a coordinating CSIRT, a contact point for researchers — and for a small team, the person who knows the product is also the person fixing the bug.

Solution02 / 07

What Bomline does

  • One SBOM per release

    Import CycloneDX or SPDX from your build, or generate it in CI. Every SBOM is tied to a product version and kept for the support period, so you can answer which shipped releases contain a component.

    B-01
  • Exploited first

    New advisories are matched against your releases, with known-exploited vulnerabilities flagged at the top — so the 24-hour question gets answered with data, not memory.

    B-02
  • Reporting deadlines, tracked

    From the moment you mark a vulnerability as known, Bomline starts the 24h / 72h / final-report timers and drafts the content of each step for you to review and submit on ENISA's platform.

    B-03

Process03 / 07

How it works

  1. Step 1: Register your products

    Products, versions and support periods — the units you report on.

  2. Step 2: Attach SBOMs

    Upload CycloneDX or SPDX files, or push them from CI on every release.

  3. Step 3: Triage matches

    Review vulnerabilities that hit your releases, record exploitability and decisions, notify component maintainers.

  4. Step 4: Report and fix

    Follow the guided early warning, notification and final report, then link the patch and advisory to close the case.

Audience04 / 07

Who it's for

  • Small manufacturers of connected hardware: IoT devices, gateways, controllers, robotics
  • Software vendors whose products are sold in the EU as products with digital elements
  • Embedded and firmware teams (2–50 engineers) without a dedicated PSIRT
  • Engineering leads who are now the named contact for vulnerability reports

Pricing05 / 07

Simple, early-customer pricing

Bomline is in development. Join the waitlist for free and we’ll email you when it’s ready.

Want to lock in the founding price? Pre-order today. If we don’t launch, you get a full refund. See the pre-order terms.

Founding manufacturer

Early access

€69 / month

Founding price for the first teams on the waitlist. Pre-orders open soon: the first month is charged upfront and fully refunded if Bomline doesn't launch.

  • Up to 10 products, unlimited releases
  • SBOM import and CI upload (CycloneDX, SPDX)
  • Vulnerability matching with known-exploited flags
  • 24h / 72h / final-report deadline tracking with drafted content
  • Decision log per vulnerability, exportable for audits
  • Direct line to the engineers building it
Pre-order — €69 · €69 Join the waitlist instead

Secure checkout by Stripe. Full refund if Bomline doesn’t launch. Terms.

FAQ06 / 07

Questions, answered

Q01 Does Bomline make my product CRA-compliant?

No. The CRA covers secure design, vulnerability handling, documentation and conformity assessment; Bomline supports the SBOM and vulnerability-reporting part of that work. Decisions, reports and the conformity assessment remain yours. Bomline is not legal advice and does not replace a qualified advisor.

Q02 What applies today, and what applies later?

Article 14 reporting obligations (actively exploited vulnerabilities and severe incidents) apply from 11 September 2026, also for products already on the market. Most other obligations, including the essential requirements in Annex I with the SBOM, apply from 11 December 2027 (Article 71).

Q03 Does the CRA apply to my product?

It covers products with digital elements made available on the EU market in the course of a commercial activity. Some products are excluded because other EU rules apply, such as medical and in-vitro diagnostic devices, vehicles under type-approval, certified aviation products, marine equipment, and products made exclusively for national security or defence (Article 2). Check your own case.

Q04 Do you submit reports to ENISA for me?

No. Submissions go through ENISA's single reporting platform, which requires an EU Login account with multi-factor authentication and currently offers no API. Bomline tracks deadlines and prepares the content; a person on your team submits it.

Q05 Which SBOM formats are supported?

CycloneDX and SPDX, in JSON. The CRA asks for a commonly used, machine-readable format covering at least top-level dependencies; we keep what your tooling produces and can include transitive dependencies when your build provides them.

Q06 What about open-source projects?

Open-source software stewards have a lighter regime under Article 24. Bomline is designed for manufacturers, but it also helps you report vulnerabilities you find in components back to their maintainers, as Article 13(6) requires.

Q07 Where is data stored?

We are building Bomline to host data in the EU, encrypt it in transit and at rest, and never share your SBOMs or vulnerability records with third parties. You will be able to export and delete everything at any time.

Q08 When will it be available?

Bomline is in development. We are onboarding a small group of founding manufacturers first. Join the waitlist and we'll email you when there is something to try.

Q09 Can I pre-order?

Pre-orders open soon, first for people on the waitlist. A pre-order charges the first month (€69) upfront. If Bomline doesn't launch, you get a full refund, and you can ask for a full refund at any time before delivery, for any reason; we process refunds within 14 days.

Access07 / 07

Get early access

We're onboarding a small group of manufacturers first. Leave your work email and we'll contact you when a pilot slot opens.

Questions? hello@holtrane.com

No spam. One email when there is something to show. Unsubscribe any time.