QUILONSQUILONS AI
AssureCRA by QUILONS
Cyber Resilience ActCustomer-private deployment

Continuous evidence and assurance for Cyber Resilience Act readiness.

AssureCRA connects product evidence, cybersecurity assurance, code findings and CRA assessment in one governed system — so your teams can see what is supported, what is missing and how each conclusion was reached.

Know where you stand. Prove how you got there.

See How It Works

Governed evidence flow

Two independent evidence paths. One CRA assessment layer.

Customer-private
A

Security assurance path

Repository evidence governed through Core and Cyber

Repository

Source & revision

QUILONS

Core + Cyber

Regulatory

CRA assessment

B

Code findings path

Independent SentryCode acquisition and governed finding review

Repository

Source & revision

QUILONS

SentryCode

Regulatory

CRA review

Customer workspace

QUILONS Compliance

Traceable findings, evidence status, review outcomes and CRA readiness in one governed view.

The CRA evidence problem

A checklist is not an evidence system.

CRA work spans product security, source code, vulnerability handling, product documentation and organizational evidence. AssureCRA is designed to connect those facts to regulatory assessment without hiding uncertainty or treating every requirement as automatically provable.

01

Acquire evidence

Bring repository, security and technical findings into governed evidence flows at immutable revisions.

02

Assess against CRA

Connect technical facts and product evidence to CRA requirements without pretending software alone proves every obligation.

03

Govern gaps and review

Separate supported facts, partial support and external evidence needs so teams know what is proven and what still needs action.

04

Preserve the trail

Keep lineage, assessment results and evidence references traceable for internal review, release decisions and technical documentation.

How it works

Two evidence paths. One governed CRA view.

AssureCRA keeps repository security assurance and source-code scanning distinct, then brings their evidence into the CRA layer for regulatory interpretation and review.

Important architectural boundary

SentryCode acquires repositories independently. It is not downstream of Core. CRA owns the review and disposition of SentryCode findings.

A

Repository → Core → Cyber → CRA → Compliance

Core governs repository access and identity. Cyber generates security assurance evidence. CRA interprets that evidence in the regulatory context, and Compliance exposes the governed result to the customer.

B

Repository → SentryCode → CRA → Compliance

SentryCode independently analyzes source and publishes governed technical findings. CRA controls finding review and regulatory disposition before the result is surfaced through Compliance.

Result

A traceable chain from source evidence to CRA assessment.

The goal is not a magic compliance score. It is a reviewable body of evidence that shows which facts support the assessment and where additional evidence or human judgment is required.

The complete solution

Six QUILONS components, clear responsibilities.

AssureCRA is the customer product experience built from specialized QUILONS capabilities rather than a monolithic compliance database.

QUILONS Core

Identity, governance, repository access and governed artifact foundations.

QUILONS Cyber

Security assurance and cybersecurity evidence acquired through Core-governed repository access.

QUILONS SentryCode

Independent source-code scanning and technical findings, delivered into CRA for governed review.

QUILONS CRA

Regulatory interpretation, evidence mapping, assessment and finding disposition semantics.

QUILONS Compliance

The customer-facing workspace for assessment status, evidence and governed readback.

QUILONS Installer

Customer-private deployment, lifecycle operations and release evidence packaging.

Designed boundaries: Core, Cyber, SentryCode and CRA keep separate persistence. Modules do not reach into each other's databases, and the Compliance UI does not receive product database credentials.

Evidence coverage

AssureCRA tells you what the evidence can actually support.

Not every CRA obligation can be proven from code or scanner output. The platform makes that boundary explicit instead of converting missing evidence into false confidence.

1

Fully supported facts

Technical evidence is sufficient to support the relevant factual part of a requirement.

2

Partially supported facts

AssureCRA has technical evidence, while product-specific or operational proof is still required.

3

External evidence required

The obligation depends on evidence outside automated technical analysis and must be supplied or reviewed separately.

Customer-private by design

Keep sensitive product evidence in infrastructure you control.

AssureCRA is designed for customer-private deployment, with dedicated module boundaries, separate persistence and governed service-to-service access.

On-premises

Deploy the solution inside infrastructure controlled by your organization.

Separate persistence

Core, Cyber, SentryCode and CRA retain their own data boundaries.

Governed interfaces

Versioned capability APIs and evidence flows replace cross-module database access.

Deployment lifecycle

QUILONS Installer supports installation, lifecycle operations and release evidence.

Assurance, not a legal shortcut

Evidence-backed CRA readiness without overclaiming certification.

AssureCRA helps manufacturers establish, maintain and demonstrate confidence in CRA readiness through governed evidence and traceable assessment. It does not replace the manufacturer's legal responsibility, declaration of conformity or any third-party conformity assessment required for a product.

AssureCRA by QUILONS

See AssureCRA against your product evidence.

Walk through your repository model, security evidence, CRA obligations and deployment constraints with QUILONS.

Contact QUILONS

Product page: /assurecra · AssureCRA is a QUILONS product.