Cybersecurity Engineering Platform
for IEC 62443 & EU CRA.
CyberRisk Canvas is an open-source threat analysis and risk assessment platform for IEC 62443, EU CRA, and NIS-2. 100% self-hosted & air-gap ready - your confidential architecture diagrams and zero-day findings never leave your private network.
docker compose up - running in minutes
Live demo at app.cyberriskcanvas.com - login: demo@cyberriskcanvas.com / demo1234
Most teams doing this work are not security specialists.
Mandatory reporting for actively exploited vulnerabilities starts September 2026 (Art. 14 CRA), with full CE requirements and NIS-2 in effect by December 2027. Both demand systematic threat modeling, continuous SBOM vulnerability management, and documented evidence - but most engineering teams lack a dedicated security specialist. Work falls on developers and product managers with tight deadlines.
No dedicated expert
The person running the threat model is often the same person shipping the product. Security knowledge helps, but should not be a prerequisite.
Spreadsheets break down
Tracking threats, mitigations, and compliance references manually in Excel works until it doesn't - usually right before the audit.
Auditors need evidence, not tables
A finished risk assessment is not enough. Auditors want test reports, formal risk decisions, and a document that has not been changed since sign-off.
Free for everyone. Pro for growing teams.
The full risk assessment workflow is open source and free forever. Pro features unlock audit-ready exports, version history, AI analysis, and more - with a simple license key.
Built for teams developing connected products.
CyberRisk Canvas is used by engineering teams who need to demonstrate cybersecurity compliance - whether for type approval, customer audits, or regulatory certification. It works with or without a dedicated security engineer.
Automotive OEMs & Tier-1/2 suppliers
IEC 62443 mapping and type-approval documentation for ECUs, gateways, and vehicle systems.
Industrial automation & OT vendors
IEC 62443 compliance for PLCs, HMIs, and SCADA systems. Zone and conduit modeling out of the box.
IoT & connected product manufacturers
EU CRA (EU 2024/2847) compliance for any product with digital elements sold on the EU market from 2027.
Security consultants & TÜV assessors
Run structured TARAs for multiple clients in one platform. Export audit-ready reports under your own branding.
Everything you need to run structured risk assessments.
Visual Architecture Canvas
Drag-and-drop diagram editor for system components, data flows, and trust boundaries.
Risk Assessment Workflow
Structured threat identification, STRIDE classification, risk assessment, and treatment tracking.
IEC 62443 & Official CRA Mapping
Map findings directly to IEC 62443 security levels and official EU CRA Annex I requirements (ER.0–ER.14a / VH.1–VH.8a).
BSI TR-03183-1 & TR-03185 SDL
Standard BSI asset catalog (Data/Functional/Security), environmental likelihood calculator (Annex D), and secure software lifecycle checklists.
Real-Time Collaboration
Multiple users work on the same diagram simultaneously.
Team Management
Product teams and cross-functional review teams with fine-grained visibility.
100% Self-Hosted
Full control over your data. Deploy on your own servers with Docker Compose - completely air-gap capable.
Unlock the full platform for your team.
Audit-Ready PDF & Technical Dossier
Compliance-grade reports (CRA Annex VII) with your company logo for auditors, notified bodies, and certification authorities.
Project Versioning
Each version holds a frozen risk assessment snapshot and its own SBOM. Freeze releases as immutable audit artifacts - the next version starts fresh automatically.
BSI TR-03183-2 SBOM Export
Import & export CycloneDX (1.2–1.6) and SPDX (2.x / 3.0.1) BOM files with BSI property taxonomy (bsi:component:*, SHA-512 hashes) and zero vulnerability clutter.
CVE Monitoring & Security Overview
Periodic re-scans check every uploaded SBOM against OSV.dev for newly disclosed vulnerabilities - without overwriting your VEX triage. Cross-project Security Overview for shared component triage.
CSAF 2.0 & CRA Art. 14 Wizard
Guided wizard for CSAF 2.0 / CycloneDX VEX 1.4 advisories, RFC 9116 security.txt / CVD policies, and CRA Art. 14 notification countdown (24h/72h/14d).
Statement of Applicability (SoA) & OSCAL
Export CRA Statement of Applicability for Module H (JSON/CSV/Markdown) and machine-readable NIST OSCAL v1.1.0 assessment results.
AI Threat Analysis
AI-assisted threat scenario generation, CWE suggestions, and IEC 62443 / BSI control recommendations.
Attack Path Visualization
Model multi-step attack scenarios across components and trust boundaries.
Change History
Full audit trail of who changed what and when across all projects.
White-Label Export
Branded PDF reports with your company logo and custom templates.
REST API
Bearer-token API for SBOM upload, vulnerability triage, version freeze, CSAF, SoA, and OSCAL export.
From architecture to audit evidence.
Draw your architecture
Use the visual canvas to model ECUs, sensors, gateways, and data flows - or import an existing diagram. Set trust boundaries and define system scope.
Identify & rate threats
AI suggests STRIDE-based threat scenarios for your components. Rate likelihood and impact, assign CVSS scores, and define treatment actions.
Map, mitigate, export
Map findings to IEC 62443, EU CRA, or NIS-2 controls. Link mitigations and evidence, then export audit-ready PDF or Excel reports.
How do you get from CRA scope classification to an audit-proof release?
CyberRisk Canvas is the technical engine for Threat Modeling (TARA) and SBOM management, connecting directly with the CyberKlartext compliance toolchain.
Scope & Classification
CyberKlartext CRA-Klartext
Determine whether your product is in scope and classify it into Default, Important (Class I/II), or Critical in under 2 minutes.
Threat Modeling, TARA & BSI Risk Model
CyberRisk Canvas
Visually model architecture, evaluate BSI TR-03183-1 asset protection needs (C/I/A), calculate environmental likelihoods (Annex D), and map CRA Annex I controls.
BSI TR-03183-2 SBOM & OSV.dev Monitoring
CyberRisk Canvas Pro
Import and export CycloneDX 1.6 / SPDX 3.0.1 SBOMs with BSI property taxonomy, track VEX triage, and continuously monitor CVEs via OSV.dev.
CSAF 2.0, security.txt & CRA Art. 14 Reporting
CyberRisk Canvas Pro + CSAF Studio
Generate machine-readable CSAF 2.0 advisories, RFC 9116 security.txt, CVD policies, and track statutory CRA Art. 14 notification deadlines (24h/72h/14d).
SoA, NIST OSCAL & EU Declaration of Conformity
CyberRisk Canvas + CyberKlartext
Export CRA Statement of Applicability (SoA) for Module H, machine-readable NIST OSCAL results, and generate standard-compliant EU Declarations of Conformity.
Where each requirement lives in the product.
A direct map from each compliance requirement group to the CyberRisk Canvas workflow that covers it.
| Requirement group | What it demands | Covered by |
|---|---|---|
| EU CRA Annex I, Part I — Risk assessment | Systematic cybersecurity risk assessment across the product lifecycle | Visual architecture canvas, STRIDE threat modeling, BSI Annex D likelihood calculator |
| EU CRA Annex I, ER.0–ER.14a | Essential cybersecurity requirements (secure by design/default, vulnerability handling capability) | Requirement-by-requirement mapping inside the risk assessment workflow |
| EU CRA Art. 13 (SBOM) | Software bill of materials covering top-level dependencies | BSI TR-03183-2 SBOM import/export (CycloneDX, SPDX) + OSV.dev CVE monitoring |
| EU CRA Annex I, Part II, VH.1–VH.8a | Vulnerability handling process obligations | CSAF 2.0 wizard, RFC 9116 security.txt/CVD generator, CRA Art. 14 notification tracker |
| EU CRA Module H / Annex VII | Statement of Applicability & technical documentation | SoA export, audit-ready PDF technical dossier |
| IEC 62443 | Zone/conduit modeling, Security Levels SL-1 to SL-4 | Zone/conduit modeling on the canvas, per-component Security Level mapping |
Key terms & standards explained
Be ready when the auditor arrives.
CyberRisk Canvas turns your ongoing risk work into a structured evidence package - so certification doesn't require a last-minute scramble.
Traffic-light status
Every threat and mitigation has a clear status indicator. Auditors see at a glance what is open, in progress, or closed.
Linked evidence
Attach test reports, Jira tickets, and design documents directly to findings. Evidence lives alongside the risk, not in a separate spreadsheet.
Formal risk acceptance
Remaining risks are formally accepted with a named decision owner and rationale - documented, traceable, and defensible.
Version freeze
Freeze the active version - risk assessment snapshot and SBOM are locked together as an immutable audit artifact. A new working version starts automatically. CSAF advisories cover all versions.
Which compliance standards does CyberRisk Canvas support?
CyberRisk Canvas maps findings directly to the control requirements of each standard - no manual translation, no spreadsheet pivoting.
IEC 62443 - Industrial Cybersecurity
Zone and conduit modeling, security level assignment (SL-1 to SL-4), and direct mapping to IEC 62443-3-3 system requirements and IEC 62443-4-2 component requirements.
EU Cyber Resilience Act (2024/2847)
Harmonized Annex I requirements (ER.0–ER.14a / VH.1–VH.8a): threat analysis, risk treatment, SBOM management, Statement of Applicability (SoA), and vulnerability disclosure.
BSI TR-03183 Series & TR-03185 SDL
Concrete technical baseline for CRA: Part 1 (TARA & environment calculator), Part 2 (SBOM taxonomy & SHA-512), Part 3 (security.txt & CVD), Part H (Module H SoA), BSI TR-03185 (Secure Software Lifecycle & AI governance), and NIST OSCAL.
NIS-2 (EU 2022/2555)
Risk assessment documentation and incident management evidence for operators of essential and important services. Covers Art. 21 security measures and Art. 23 reporting obligations.
Not sure if your product falls under the EU CRA?
Check your product applicability and Annex III/IV classification in 2 minutes with the free CRA-Klartext tool on cyberklartext.de. Then use CyberRisk Canvas to build your full threat model, SBOM triage, and audit evidence.
Deploy. Configure. Work.
Deploy with Docker
Copy the docker-compose.yml, set your environment variables, and run docker compose up. The database is initialized automatically.
Create your team
The first admin user is created from your environment variables. Add team members and organize them into product and review teams.
Start your assessment
Create a project, draw your system architecture, and start identifying threats. Your first project comes with a starter template.
One plan, one price.
Unlimited users. One server. All Pro features included.
Pro
Unlimited users · 1 server
Community
Free forever. No license key required.
Frequently asked questions
Is there a demo I can try before deploying?+
Does CyberRisk Canvas really run on my own servers?+
Can CyberRisk Canvas run in fully air-gapped or restricted networks?+
Which standards does CyberRisk Canvas support?+
How do I know if my product falls under the EU CRA?+
How does CyberRisk Canvas assist with CSAF 2.0, security.txt, and CRA Art. 14 Reporting?+
How long does setup take?+
What is included in the free Community edition?+
What does the Pro license add?+
Who is CyberRisk Canvas built for?+
Still have questions?
We're happy to help.