Skip to content

CRA's first obligation takes effect

Platform

A single SDK from chip to cloud; integration in days, compliance in hours.

TegmenSoft enables you to manage CRA compliance from a single control plane, from embedded teams fighting hardware constraints to enterprise IT teams managing tens of thousands of devices.

MCU minimum

256 KB Flash · 64 KB RAM

Linux support

ARM64 · x86_64 · MIPS

TLS

1.3 + mTLS, AES-256-GCM

Signing

Ed25519 / ECDSA-P256

Architecture

Chip-to-Cloud three-layer security

A single control plane from hardware identity to cloud reporting. Each layer is built as a cryptographic foundation that the layer above can trust.

Layer 01

Device Security

MCU / Embedded Linux

Starting at Root of Trust and hardware identity level, the fundamental cryptographic identity that all upper layers depend on.

Secure BootSigned bootloader chain
Root of TrustHardware-rooted identity
TLS 1.3 / AES-256End-to-end encrypted channel
SDK AgentTelemetry, OTA, log management
Layer 02

SDK & Orchestration

Chip-to-Cloud Control Plane

The middle layer housing PKI/CA, SBOM engine, and OTA server. Integrates into CI/CD pipelines as a low-footprint library.

PKI / CACertificate and key rotation
SBOM EngineSPDX, CycloneDX, VEX generation
OTA ServerSigned firmware distribution
Event CorrelationIoC and behavioral analysis
Layer 03

Data & Analytics

Multi-tenant Cloud

Multi-tenant cloud layer; each manufacturer's fleet, audit trails, and reports are isolated with RLS guarantees.

SQL Server + RLSRow-level isolation
ENISA SRP BridgeAutomated notification drafts
10-Year ArchiveSigned audit logs
Compliance DashboardFleet-level compliance status

Lifecycle

Factory-to-Cloud: six-phase operational flow

Six core phases where TegmenSoft works alongside the manufacturer, from the production line to a retired device.

Phase 01

CI/CD Integration

The SDK runs as a build step in existing Jenkins/GitLab/GitHub Actions pipelines; produces and signs SBOM for every artifact.

Phase 02

Provisioning

Each device receives a unique, unclonable cryptographic identity (PUF + certificate) on the production line; Root of Trust is established here.

Phase 03

Runtime Telemetry

The device streams periodic telemetry and event logs to the cloud control plane over mTLS; behavioral anomalies are correlated.

Phase 04

ENISA SRP Bridge

When active exploitation is detected, notification drafts are automatically generated; the compliance team approves, the system sends.

Phase 05

Fleet Patch Deployment

The OTA infrastructure distributes signed firmware with staged (canary → general) rollout and A/B partition protection.

Phase 06

10-Year Audit Trail

All events, reports, and OTA deployments are stored signed in long-term archive; meets CRA Article 14 requirements.

Platform

Diagnose → Detect → Act → Deploy

Competitors silo this cycle. TegmenSoft completes every stage within a single SDK.

DIAGNOSEQ3 2026

Dynamic SBOM Engine

Software Bill of Materials & CVE Matching

Extracts a real-time inventory of all software components (open-source and commercial) running on the device; automatically matches them against NVD and MITRE CVE databases. Produces signed SBOM in SPDX and CycloneDX formats.

  • Automatic dependency discovery (binary + manifest)
  • SPDX 2.3 and CycloneDX 1.7 generation
  • NVD, OSV, MITRE CVE matching
  • VEX (Vulnerability Exploitability eXchange) output
DETECTQ3 2026

Telemetry & Active Exploitation Detection

Article 14 Trigger Mechanism

Detects not just theoretical vulnerabilities but active in-the-wild exploitation through device logs and alarms. The early warning layer that triggers CRA Article 14's 24-hour reporting obligation.

  • Device-to-cloud log streaming over mTLS
  • Behavioral anomaly and IoC correlation
  • Vulnerability × telemetry matching
  • Severity scoring engine
ACTQ3 2026

ENISA SRP Automated Reporting

< 24 Hour Legal Notification Automation

Automatically converts detected vulnerabilities into ENISA Single Reporting Platform (SRP) format; prepares early warning, 72-hour full notification, and 14-day final report drafts including affected member states, product lines, and mitigation steps.

  • ENISA SRP schema-compliant output
  • 24h / 72h / 14-day automated schedule
  • Automatic affected market and device pool mapping
  • Signed audit trail
DEPLOYActive

Secure OTA Distribution

Signed Firmware, Bricking Protection

Cryptographically signed (Ed25519 / RSA-PSS) secure firmware distribution with A/B partition rollback and bricking protection — deploys vulnerability patches fleet-wide within hours.

  • Cryptographic signature verification (Ed25519 / RSA-PSS)
  • A/B partition rollback
  • Staged (canary) deployment and fleet segmentation
  • Delta updates for low-bandwidth devices

Secure OTA

Bricking-protected OTA infrastructure

Cryptographically signed, A/B partition rollback-supported, and optimized for low-bandwidth secure update layer.

Signed Firmware

Ed25519 / RSA-PSS signed packages; the device only accepts approved firmware verified with the manufacturer's root certificate.

A/B Partition

If an update fails, the device automatically rolls back to the working partition. Bricking risk is eliminated.

Delta Updates

Only changed blocks are sent; enables practical deployment even on low-bandwidth 2G/NB-IoT devices.

Security Stack

Defense-in-depth at every layer

From hardware to cloud database, each layer is built as a cryptographic foundation that the layer above trusts.

Device Layer

  • Secure Boot (chained signatures)
  • Hardware identity / PUF
  • mTLS + AES-256-GCM

SDK Layer

  • SBOM (SPDX 2.3 · CycloneDX 1.7)
  • PKI / key rotation
  • Event correlation engine

Cloud Layer

  • Multi-tenant SQL + Row-Level Security
  • ENISA SRP automation
  • Signed 10-year archive

Meet our technical team for an architecture review.

Schedule a 30-minute technical deep-dive with our CTO, cryptography, and embedded systems experts. We'll analyze your current product portfolio and map a CRA compliance path.

Schedule Technical Call
Platform — Chip-to-Cloud Architecture · TegmenSoft