# trust · eu regulation

CRA alignment — EU

The EU Cyber Resilience Act — entered into force December 2024, with main obligations effective December 2027. Covers products with digital elements placed on the EU market. VAOS is architected around the CRA core: security by design, vulnerability handling, and continued security support.

← Trust Architecture EU RED →
Status. VAOS is positioned as a component supplied to manufacturers. Under the CRA, the integrator is the responsible economic operator. VAOS provides the technical evidence — SBOM, vulnerability handling, security update window — that integrators need to file conformity assessments.
# core obligations

Six CRA pillars mapped to VAOS

🛡️

Security by design

Validation envelope, sensor-aware perception, structured Scene Contracts — security is the architecture, not a wrapper around it. See the eight commitments →

📋

Risk assessment & documentation

Reference threat model, attack-surface map, and runtime-failure modes documented per release. Distributable as part of the OEM evidence pack.

🔧

Vulnerability handling

Coordinated disclosure, CVE-style IDs, advisory feed (RSS + JSON), 72-hour active-exploit notification to ENISA when applicable.

🔄

Security updates

Published support window per release. Updates signed, deltas verified at boot. Failure-safe rollback if integrity check fails.

📦

SBOM & provenance

Each VAOS release publishes a CycloneDX SBOM. Provenance attestations for binary artifacts. OEMs inherit and extend.

⚖️

Conformity-assessment support

Technical documentation pack — architecture, risk assessment, security policy, update support window — ready to bundle into integrator filings.

Important products & class boundaries

The CRA distinguishes default-class products from "important" and "critical" classes — which face stricter conformity routes. VAOS-powered devices fall into different classes depending on use:

ClassConformity routeVAOS scenario
DefaultSelf-assessmentHobby / dev kits
Important class ISelf or harmonised standardsSmart cameras, doorbell-class
Important class IIThird-party assessmentIndustrial / safety
CriticalMandatory third-partyHealthcare / critical infra

Architectural alignment is the same. The filing route varies by integrator product class.

EU-ready as a supplier.

SBOM, advisory feed, signed updates, support window — the evidence integrators need.

Integrator evidence pack EU RED alignment ← Trust overview