
CRA vulnerability notification obligations take effect in September 2026, including 24-hour early warning requirements. OnBoard™ IoT Security (OBIS) keeps SBOMs, provisioning records, and OTA state on the same operational trust chain — so the path from a CVE to the affected device serial resolves through a single query.
SBOMs, provisioning records, and device state remain cryptographically linked across build, provisioning, and OTA operations — so exposure analysis always reflects the device's current state.

OBIS connects vulnerability intelligence, production history, OTA state, and VEX decisions into a single operational workflow — so exposure analysis and remediation tracking stay tied to the device's current state.
Vulnerability assessments, remediation decisions, and deployment coverage remain attached to the governed product record throughout the lifecycle.
Discuss your SBOM architecture, vulnerability workflows, OTA operations, and compliance requirements with the OBIS engineering team.