EU Cyber Resilience Act for Telecom Equipment & 5G CNFs
Automated CE mark cybersecurity certification, Software Bill of Materials (SBOM) generation, and statutory 24-hour vulnerability reporting for carrier hardware and cloud-native network functions.
Security-by-Design & Default
Mandatory zero-trust baseline configuration for network elements, Base Transceiver Stations (BTS), and eSIM Remote SIM Provisioning (RSP) nodes.
Automated CycloneDX SBOM
Real-time tracking of open-source and proprietary software dependencies across 5G User Plane Functions (UPF) and Open RAN DU/CU codebases.
24-Hour ENISA Incident Reporting
Direct STIX 2.1 integration for reporting actively exploited vulnerabilities in telecommunication products to ENISA and national CSIRTs within 24 hours.
CycloneDX v1.5 Telecom SBOM Explorer
CRA Article 10 Mandatory Technical Documentation & Vulnerability Ledger
| Component / Library | Type | License | CRA Essential Controls | Known CVEs | CE Status |
|---|---|---|---|---|---|
dpdk-kni pkg:generic/dpdk@23.11?vlan=true | Framework | BSD-3-Clause | Memory Bounds Check & Zeroization | 0 VULNS | ✓ CE CONFORMANT |
openssl-fips pkg:generic/openssl@3.0.12?fips=140-3 | Cryptographic | Apache-2.0 | Hardware TRNG & Post-Quantum KEM | 0 VULNS | ✓ CE CONFORMANT |
libgtp5g pkg:github/free5gc/gtp5g@0.8.4 | Kernel Driver | GPL-2.0 | TEID Randomization (GSMA FS.37) | 0 VULNS | ✓ CE CONFORMANT |
json-c pkg:generic/json-c@0.17 | Library | MIT | Strict Schema Validator (CRA Art. 10) | 0 VULNS | ✓ CE CONFORMANT |
Connect Your Telecom Pipeline to TelcoSec CRA Engine
Integrate continuous CycloneDX SBOM exports into your CI/CD delivery pipeline and automate statutory ENISA Article 11 vulnerability notifications.