Compliance

The EU Cyber Resilience Act

Where ProcessView+ and GVE Inc. stand on Regulation (EU) 2024/2847.

What the CRA is

The Cyber Resilience Act is an EU regulation that sets cybersecurity requirements for products with digital elements sold in the European Union. It covers how a product is built and secured, how vulnerabilities are handled after it has been released, and what information has to be supplied with it. It applies to the software itself, not only to the organization that makes it.

The two dates

When obligations apply

11 September 2026 Reporting obligations begin. From this date a manufacturer must report actively exploited vulnerabilities and severe incidents to EU authorities, and inform affected users.
11 December 2027 The substantive product requirements apply in full — how a product is built and secured, how vulnerabilities are handled after release, and what information must accompany it.

Where we stand

The substantive requirements do not apply until 11 December 2027, and the framework they depend on is not yet fully in place. We are not claiming ProcessView+ is compliant today, and we would treat any supplier who does with caution.

What we have done is complete a technical review of ProcessView+ against the regulation's essential requirements — covering the components we ship and where they come from, every external interface, cryptography and credential handling, our build and update process, what data the product stores, and the accuracy of what we publish about it. It produced a prioritized list of work, which we are now executing.

Some of that work has already changed what is published on this site. Where a claim on these pages went further than the code supported, we corrected the claim rather than leaving it to be discovered.

What customers get

  • A disclosure policy and a security contact. A published route for reporting a vulnerability, with safe harbor for good-faith research and no NDA. Read the disclosure policy.
  • A stable place for advisories. One URL, published before there was anything to put on it, so it is already there when the first advisory is needed. None have been issued to date. See advisories.
  • Release notes that identify security content. Security fixes are labeled as security fixes and separated from feature changes, so you can tell whether a release needs scheduling. Where a release contains none, it says so. See release notes.
  • A component inventory (SBOM) on request. A list of the components we ship and where they come from, available to customers who need it for their own assessment.

To request an SBOM, email support@chamberdatahub.com.

For distributors and integrators

If you resell ProcessView+ without applying your own branding and without modifying it, the regulation treats you as a distributor, and the manufacturer's obligations remain ours. If you apply your own name or trademark, or modify the software, it treats you as its manufacturer, with the obligations that brings.

If you are unsure which describes you, talk to us — we would rather establish it early than after someone has been asked to produce documentation.

Existing installations

Products placed on the market before 11 December 2027 are not brought into scope retrospectively, unless they are substantially modified after that date.

Questions

For CRA questions — including from distributors assessing their own position — email support@chamberdatahub.com .

To report a security vulnerability, use our disclosure policy instead — it goes to the same place, but it tells you what to include.