CRA reporting from Sept 2026 · CE from Dec 2027Set up threat modeling & SBOM tracking before deadlines hit.See how it works →

Cybersecurity Engineering Platform
for IEC 62443 & EU CRA.

CyberRisk Canvas is an open-source threat analysis and risk assessment platform for IEC 62443, EU CRA, and NIS-2. 100% self-hosted & air-gap ready - your confidential architecture diagrams and zero-day findings never leave your private network.

docker compose up - running in minutes

Live demo at app.cyberriskcanvas.com - login: demo@cyberriskcanvas.com / demo1234

The situation

Most teams doing this work are not security specialists.

Mandatory reporting for actively exploited vulnerabilities starts September 2026 (Art. 14 CRA), with full CE requirements and NIS-2 in effect by December 2027. Both demand systematic threat modeling, continuous SBOM vulnerability management, and documented evidence - but most engineering teams lack a dedicated security specialist. Work falls on developers and product managers with tight deadlines.

No dedicated expert

The person running the threat model is often the same person shipping the product. Security knowledge helps, but should not be a prerequisite.

Spreadsheets break down

Tracking threats, mitigations, and compliance references manually in Excel works until it doesn't - usually right before the audit.

Auditors need evidence, not tables

A finished risk assessment is not enough. Auditors want test reports, formal risk decisions, and a document that has not been changed since sign-off.

Open Core Model

Free for everyone. Pro for growing teams.

The full risk assessment workflow is open source and free forever. Pro features unlock audit-ready exports, version history, AI analysis, and more - with a simple license key.

Who it's for

Built for teams developing connected products.

CyberRisk Canvas is used by engineering teams who need to demonstrate cybersecurity compliance - whether for type approval, customer audits, or regulatory certification. It works with or without a dedicated security engineer.

Automotive OEMs & Tier-1/2 suppliers

IEC 62443 mapping and type-approval documentation for ECUs, gateways, and vehicle systems.

Industrial automation & OT vendors

IEC 62443 compliance for PLCs, HMIs, and SCADA systems. Zone and conduit modeling out of the box.

IoT & connected product manufacturers

EU CRA (EU 2024/2847) compliance for any product with digital elements sold on the EU market from 2027.

Security consultants & TÜV assessors

Run structured TARAs for multiple clients in one platform. Export audit-ready reports under your own branding.

Community - Free

Everything you need to run structured risk assessments.

  • Visual Architecture Canvas

    Drag-and-drop diagram editor for system components, data flows, and trust boundaries.

  • Risk Assessment Workflow

    Structured threat identification, STRIDE classification, risk assessment, and treatment tracking.

  • IEC 62443 & Official CRA Mapping

    Map findings directly to IEC 62443 security levels and official EU CRA Annex I requirements (ER.0–ER.14a / VH.1–VH.8a).

  • BSI TR-03183-1 & TR-03185 SDL

    Standard BSI asset catalog (Data/Functional/Security), environmental likelihood calculator (Annex D), and secure software lifecycle checklists.

  • Real-Time Collaboration

    Multiple users work on the same diagram simultaneously.

  • Team Management

    Product teams and cross-functional review teams with fine-grained visibility.

  • 100% Self-Hosted

    Full control over your data. Deploy on your own servers with Docker Compose - completely air-gap capable.

Pro - Licensed

Unlock the full platform for your team.

  • Audit-Ready PDF & Technical Dossier

    Compliance-grade reports (CRA Annex VII) with your company logo for auditors, notified bodies, and certification authorities.

  • Project Versioning

    Each version holds a frozen risk assessment snapshot and its own SBOM. Freeze releases as immutable audit artifacts - the next version starts fresh automatically.

  • BSI TR-03183-2 SBOM Export

    Import & export CycloneDX (1.2–1.6) and SPDX (2.x / 3.0.1) BOM files with BSI property taxonomy (bsi:component:*, SHA-512 hashes) and zero vulnerability clutter.

  • CVE Monitoring & Security Overview

    Periodic re-scans check every uploaded SBOM against OSV.dev for newly disclosed vulnerabilities - without overwriting your VEX triage. Cross-project Security Overview for shared component triage.

  • CSAF 2.0 & CRA Art. 14 Wizard

    Guided wizard for CSAF 2.0 / CycloneDX VEX 1.4 advisories, RFC 9116 security.txt / CVD policies, and CRA Art. 14 notification countdown (24h/72h/14d).

  • Statement of Applicability (SoA) & OSCAL

    Export CRA Statement of Applicability for Module H (JSON/CSV/Markdown) and machine-readable NIST OSCAL v1.1.0 assessment results.

  • AI Threat Analysis

    AI-assisted threat scenario generation, CWE suggestions, and IEC 62443 / BSI control recommendations.

  • Attack Path Visualization

    Model multi-step attack scenarios across components and trust boundaries.

  • Change History

    Full audit trail of who changed what and when across all projects.

  • White-Label Export

    Branded PDF reports with your company logo and custom templates.

  • REST API

    Bearer-token API for SBOM upload, vulnerability triage, version freeze, CSAF, SoA, and OSCAL export.

How it works

From architecture to audit evidence.

Draw your architecture

Use the visual canvas to model ECUs, sensors, gateways, and data flows - or import an existing diagram. Set trust boundaries and define system scope.

Identify & rate threats

AI suggests STRIDE-based threat scenarios for your components. Rate likelihood and impact, assign CVSS scores, and define treatment actions.

Map, mitigate, export

Map findings to IEC 62443, EU CRA, or NIS-2 controls. Link mitigations and evidence, then export audit-ready PDF or Excel reports.

End-to-End Compliance Chain

How do you get from CRA scope classification to an audit-proof release?

CyberRisk Canvas is the technical engine for Threat Modeling (TARA) and SBOM management, connecting directly with the CyberKlartext compliance toolchain.

01

Scope & Classification

CyberKlartext CRA-Klartext

Determine whether your product is in scope and classify it into Default, Important (Class I/II), or Critical in under 2 minutes.

Check Scope →
02Core Platform

Threat Modeling, TARA & BSI Risk Model

CyberRisk Canvas

Visually model architecture, evaluate BSI TR-03183-1 asset protection needs (C/I/A), calculate environmental likelihoods (Annex D), and map CRA Annex I controls.

03Pro Feature

BSI TR-03183-2 SBOM & OSV.dev Monitoring

CyberRisk Canvas Pro

Import and export CycloneDX 1.6 / SPDX 3.0.1 SBOMs with BSI property taxonomy, track VEX triage, and continuously monitor CVEs via OSV.dev.

04

CSAF 2.0, security.txt & CRA Art. 14 Reporting

CyberRisk Canvas Pro + CSAF Studio

Generate machine-readable CSAF 2.0 advisories, RFC 9116 security.txt, CVD policies, and track statutory CRA Art. 14 notification deadlines (24h/72h/14d).

CSAF Studio →
05

SoA, NIST OSCAL & EU Declaration of Conformity

CyberRisk Canvas + CyberKlartext

Export CRA Statement of Applicability (SoA) for Module H, machine-readable NIST OSCAL results, and generate standard-compliant EU Declarations of Conformity.

EU Declaration Generator →
Standard-to-feature mapping

Where each requirement lives in the product.

A direct map from each compliance requirement group to the CyberRisk Canvas workflow that covers it.

Requirement groupWhat it demandsCovered by
EU CRA Annex I, Part I — Risk assessmentSystematic cybersecurity risk assessment across the product lifecycleVisual architecture canvas, STRIDE threat modeling, BSI Annex D likelihood calculator
EU CRA Annex I, ER.0–ER.14aEssential cybersecurity requirements (secure by design/default, vulnerability handling capability)Requirement-by-requirement mapping inside the risk assessment workflow
EU CRA Art. 13 (SBOM)Software bill of materials covering top-level dependenciesBSI TR-03183-2 SBOM import/export (CycloneDX, SPDX) + OSV.dev CVE monitoring
EU CRA Annex I, Part II, VH.1–VH.8aVulnerability handling process obligationsCSAF 2.0 wizard, RFC 9116 security.txt/CVD generator, CRA Art. 14 notification tracker
EU CRA Module H / Annex VIIStatement of Applicability & technical documentationSoA export, audit-ready PDF technical dossier
IEC 62443Zone/conduit modeling, Security Levels SL-1 to SL-4Zone/conduit modeling on the canvas, per-component Security Level mapping
Audit readiness

Be ready when the auditor arrives.

CyberRisk Canvas turns your ongoing risk work into a structured evidence package - so certification doesn't require a last-minute scramble.

Traffic-light status

Every threat and mitigation has a clear status indicator. Auditors see at a glance what is open, in progress, or closed.

Linked evidence

Attach test reports, Jira tickets, and design documents directly to findings. Evidence lives alongside the risk, not in a separate spreadsheet.

Formal risk acceptance

Remaining risks are formally accepted with a named decision owner and rationale - documented, traceable, and defensible.

Version freeze

Freeze the active version - risk assessment snapshot and SBOM are locked together as an immutable audit artifact. A new working version starts automatically. CSAF advisories cover all versions.

Supported Standards

Which compliance standards does CyberRisk Canvas support?

CyberRisk Canvas maps findings directly to the control requirements of each standard - no manual translation, no spreadsheet pivoting.

IEC 62443

IEC 62443 - Industrial Cybersecurity

Zone and conduit modeling, security level assignment (SL-1 to SL-4), and direct mapping to IEC 62443-3-3 system requirements and IEC 62443-4-2 component requirements.

IEC 62443 details →
EU CRA

EU Cyber Resilience Act (2024/2847)

Harmonized Annex I requirements (ER.0–ER.14a / VH.1–VH.8a): threat analysis, risk treatment, SBOM management, Statement of Applicability (SoA), and vulnerability disclosure.

EU CRA details →
BSI TR-03183 & BSI TR-03185

BSI TR-03183 Series & TR-03185 SDL

Concrete technical baseline for CRA: Part 1 (TARA & environment calculator), Part 2 (SBOM taxonomy & SHA-512), Part 3 (security.txt & CVD), Part H (Module H SoA), BSI TR-03185 (Secure Software Lifecycle & AI governance), and NIST OSCAL.

BSI TR-03183 Guide →
NIS-2

NIS-2 (EU 2022/2555)

Risk assessment documentation and incident management evidence for operators of essential and important services. Covers Art. 21 security measures and Art. 23 reporting obligations.

NIS-2 Guide →
CRA Scope & Classification

Not sure if your product falls under the EU CRA?

Check your product applicability and Annex III/IV classification in 2 minutes with the free CRA-Klartext tool on cyberklartext.de. Then use CyberRisk Canvas to build your full threat model, SBOM triage, and audit evidence.

Get started in minutes

Deploy. Configure. Work.

Deploy with Docker

Copy the docker-compose.yml, set your environment variables, and run docker compose up. The database is initialized automatically.

Create your team

The first admin user is created from your environment variables. Add team members and organize them into product and review teams.

Start your assessment

Create a project, draw your system architecture, and start identifying threats. Your first project comes with a starter template.

$ curl -O https://raw.githubusercontent.com/cyberriskcanvas/cyberriskcanvas-app/main/docker-compose.yml
$ cp .env.example .env # ADMIN_EMAIL, ADMIN_PASSWORD, LICENSE_KEY
$ docker compose up -d
Simple pricing

One plan, one price.

Unlimited users. One server. All Pro features included.

MonthlyAnnualSave 2 months
All Pro features included:
✓ Audit-Ready PDF & CRA Annex VII technical dossier
✓ Project versioning with frozen immutable snapshots
✓ BSI TR-03183-2 SBOM import & export (CycloneDX 1.6 / SPDX 3.0)
✓ Continuous CVE monitoring (OSV.dev) + cross-project security overview
✓ CSAF 2.0 advisory wizard & CycloneDX VEX export
✓ BSI TR-03183-3 security.txt & CVD policy generator
✓ CRA Article 14 statutory reporting tracker (24h/72h/14d)
✓ CRA Statement of Applicability (SoA) & NIST OSCAL export
✓ AI threat analysis & CWE suggestions
✓ Attack path visualization
✓ Change history & audit trail
✓ White-label reports
✓ REST API (SBOM, triage, versions, CSAF, SoA, OSCAL)

Pro

Unlimited users · 1 server

€249/mo

Community

Free forever. No license key required.

Get Started Free →
FAQ

Frequently asked questions

Is there a demo I can try before deploying?+
Yes. A hosted demo instance is available at app.cyberriskcanvas.com. Login with demo@cyberriskcanvas.com and password demo1234 - no sign-up required.
Does CyberRisk Canvas really run on my own servers?+
Yes. CyberRisk Canvas is deployed via Docker Compose on your own infrastructure. Your data never leaves your environment - no cloud sync, no telemetry. The only external call is a one-time license validation request to our licensing server when the application starts.
Can CyberRisk Canvas run in fully air-gapped or restricted networks?+
Yes. CyberRisk Canvas is designed for self-hosted environments. No external telemetry or cloud sync is performed. Architecture diagrams, threat matrices, and vulnerability data stay completely inside your infrastructure, ensuring full intellectual property and security compliance for automotive, OT, and defense teams.
Which standards does CyberRisk Canvas support?+
CyberRisk Canvas supports IEC 62443 (zone/conduit modeling, security levels SL-1 to SL-4), EU Cyber Resilience Act (EU 2024/2847), BSI TR-03183 (Parts 1, 2, 3, and Module H), BSI TR-03185 (Secure Software Lifecycle for proprietary and open-source software, including AI governance), NIST OSCAL v1.1.0, and NIS-2.
How do I know if my product falls under the EU CRA?+
You can check whether your product falls under the scope of Regulation (EU 2024/2847) and which product category applies in about 2 minutes using the free browser tool CRA-Klartext on cyberklartext.de. Once classified, CyberRisk Canvas helps you fulfill the mandatory threat analysis, risk assessment (TARA), and SBOM vulnerability management. For detailed background information on CRA timelines and manufacturer duties, consult the CyberKlartext CRA Guide.
How does CyberRisk Canvas assist with CSAF 2.0, security.txt, and CRA Art. 14 Reporting?+
CyberRisk Canvas Pro includes a CSAF 2.0 wizard, CycloneDX VEX export, an RFC 9116 security.txt & CVD policy generator, and an automated CRA Article 14 notification countdown (24h early warning, 72h vulnerability report, 14-day final report to CERT-Bund and ENISA). It also exports CRA Statements of Applicability (SoA) and machine-readable NIST OSCAL results.
How long does setup take?+
Under 10 minutes. Copy the docker-compose.yml, set three environment variables (admin email, password, license key), and run docker compose up. The database is initialized automatically.
What is included in the free Community edition?+
The full risk assessment workflow: visual architecture canvas, STRIDE threat modeling, BSI TR-03183-1 asset catalog, environmental likelihood calculator, BSI TR-03185 SDL checklists, CRA Annex I mapping, treatment tracking, IEC 62443 mapping, and real-time collaboration.
What does the Pro license add?+
Pro adds audit-ready PDF dossiers, project versioning with frozen snapshots, BSI TR-03183-2 SBOM import & export, continuous CVE monitoring (OSV.dev), CSAF 2.0 advisory wizard, CRA Art. 14 notification countdown, security.txt/CVD generator, CRA Statement of Applicability (SoA) export, NIST OSCAL v1.1.0 export, AI threat analysis, attack path visualization, and REST API.
Who is CyberRisk Canvas built for?+
Development teams that need to demonstrate cybersecurity compliance - automotive OEMs and Tier-1 suppliers, industrial automation manufacturers (IEC 62443), IoT and connected product makers (EU CRA), and security consultants running TARAs for multiple clients.

Still have questions?

We're happy to help.