EU Cyber Resilience Act (CRA) Compliance
Cogent Real-Time Systems Inc. — EU Regulation (EU) 2024/2847 Compliance Disclosure.
Last updated: September 11, 2026.
About This Page
This page provides information about how Skkynet, and its subsidiary, Cogent Real-Time Systems Inc. (“Skkynet”) addresses the European Union’s Cyber Resilience Act (CRA) — Regulation (EU) 2024/2847 — for our products with digital elements, including Cogent DataHub® manufactured by Cogent Real-Time Systems Inc. It is published in the interest of transparency for our EU customers, distribution partners, security researchers, and market surveillance authorities.
What Is the Cyber Resilience Act?
The Cyber Resilience Act is an EU regulation that establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market. It applies to hardware and software manufacturers, importers, and distributors. Key obligations for manufacturers include:
- Security by design and by default throughout the product lifecycle (Article 13, Annex I)
- Coordinated Vulnerability Disclosure (CVD) — a formal process for receiving and handling vulnerability reports (Article 13(8))
- Software Bill of Materials (SBOM) — maintained and made available to authorities and, on request, to customers (Article 13(8) and Annex I, Part II, point (1))
- Vulnerability and incident reporting — notification of actively exploited vulnerabilities and severe incidents to the EU Single Reporting Platform (SRP) operated by ENISA (Articles 14 and 16), effective September 11, 2026
- Conformity assessment and CE marking — required for products placed on the EU market from December 11, 2027
Our Products in Scope
Cogent DataHub is industrial real-time data connectivity middleware that processes, transmits, and stores operational data across network connections. As a software product with digital elements, it falls within the scope of the CRA. Related Skkynet products (DataHub Edge, SkkyHub, and the Embedded Toolkit) are addressed under the same compliance program.
Skkynet’s Compliance Program
Skkynet is actively working toward full CRA compliance and has met the September 11, 2026 reporting deadline. Our program includes:
1. Continuous SBOM Generation and Vulnerability Monitoring
Skkynet runs daily automated SBOM generation for Cogent DataHub and continuously monitors vulnerability and KEV sources using OWASP Dependency-Track (https://dependencytrack.org/) — the open-source SBOM analysis platform that inventories every component in the product and continuously checks it against vulnerability databases, including the National Vulnerability Database (NVD) and the CISA Known Exploited Vulnerabilities (KEV) catalog. Findings feed directly into our vulnerability response process and support our Article 14 awareness and reporting obligations.
2. Vulnerability and Incident Reporting via the ENISA Single Reporting Platform
The ENISA Single Reporting Platform (SRP) is operational at portal.cra-srp.enisa.europa.eu, and from September 11, 2026 manufacturers must submit Article 14 notifications through it. Skkynet has prepared its EU Login credentials and reporting procedures in advance, enabling the Article 14 reporting process:
| Report | Deadline |
| Early warning notification | Within 24 hours of becoming aware |
| Notification / assessment update | Within 72 hours of becoming aware |
| Final report (actively exploited vulnerability) | Within 14 days after a corrective or mitigating measure is available |
| Final report (severe incident) | Within 1 month after the 72-hour notification |
3. Coordinated Vulnerability Disclosure (CVD)
Skkynet has a longstanding practice of engaging with CISA ICS-CERT and the industrial cybersecurity community on vulnerability coordination, with advisories published under the ICSA framework. We have formalized this into a documented CVD process with a public vulnerability disclosure policy, aligned with CRA Article 13(8) (Annex I, Part II, point (5)) and ISO/IEC 29147.
- CVD Policy (coming soon): https://skkynet.com/cvd-policy
- Security Advisories (coming soon): https://cogentdatahub.com/advisories
- Report a vulnerability: [email protected]
4. Software Bill of Materials (SBOM)
The Cogent DataHub SBOM is generated automatically as part of every DataHub build and maintained for each release, in a machine-readable format (SPDX or CycloneDX). SBOMs are analyzed in OWASP Dependency-Track, which provides continuous monitoring of the components they inventory against known vulnerability sources. The SBOM is available to EU market surveillance authorities and, upon request, to EU customers to support vulnerability assessment and supply-chain risk management.
5. Security by Design
Cogent DataHub V11 (released 2025) introduced enhanced security features. We maintain security-by-design architecture documentation, configuration hardening guidance, and update lifecycle commitments supporting the CRA technical documentation requirements and our ongoing security update obligations.
6. Conformity Assessment and CE Marking
We are assessing Cogent DataHub’s classification under Annex III of the CRA and the technical descriptions in Implementing Regulation (EU) 2025/2392 to determine the appropriate conformity assessment path, with the goal of completing the EU Declaration of Conformity and CE marking ahead of the full application date of December 11, 2027.
Direct Engagement with EU Authorities
Skkynet is a manufacturer established outside the EU (Canada). Under the CRA, designation of an EU Authorized Representative is optional for manufacturers in our position (Article 18). Skkynet has elected to engage directly with ENISA and EU market surveillance authorities:
- All Article 14 vulnerability and incident reports are filed by Skkynet directly through the ENISA Single Reporting Platform, simultaneously to the coordinating CSIRT and ENISA.
- Skkynet cooperates directly with EU market surveillance authorities on conformity documentation and any market surveillance requests.
- The coordinating CSIRT for our reports is determined under the Article 14(7) fallback order — importer’s Member State, then distributor’s Member State, then the Member State where the highest number of users are located — and is selected at filing from the CSIRTs designated as coordinators published by ENISA.
Manufacturer Identification (EU Legislation-Compliant Disclosure)
| Item | Details |
| Manufacturer | Cogent Real-Time Systems Inc. (a Skkynet subsidiary) |
| Registered address | 2233 Argentia Road, Suite 302, Mississauga, ON L5N 2X7, Canada |
| Contact | [email protected] · +1-905-702-7851 |
| Security contact | [email protected] |
| Compliance contact | [email protected] |
| Products in scope | Cogent DataHub, Cogent DataHub on Azure |
| EU Authorized Representative | None appointed — Skkynet engages directly with ENISA and EU authorities (under CRA Article 18) |
| EU Declaration of Conformity | In preparation — to be published on this page ahead of December 11, 2027 |
| Technical documentation | Available to EU market surveillance authorities upon request |
Key Dates
| Date | Milestone |
| September 11, 2026 | CRA Article 14 vulnerability and incident reporting obligations take effect |
| 2026–2027 | Conformity assessment and EU Declaration of Conformity preparation |
| December 11, 2027 | Full CRA application — CE marking and Declaration of Conformity required for products on the EU market |
Reporting a Vulnerability
If you are a security researcher, customer, or partner and believe you have identified a vulnerability in a Skkynet product, please report it through our Coordinated Vulnerability Disclosure process:
- Email: [email protected]
- CVD Policy (coming soon): https://skkynet.com/cvd-policy
We acknowledge all reports within 48 hours, provide an initial assessment within 5 business days, and coordinate disclosure timelines with reporters. Skkynet will not pursue legal action against security researchers who act in good faith and in accordance with our CVD policy.
EU Customers
For EU customers operating Cogent DataHub:
- No action is required from you regarding the September 11, 2026 reporting deadline — the Article 14 reporting obligation sits with Skkynet as the manufacturer.
- Security updates are provided for at least five years from product placement, or for the product’s expected use time where it is expected to be in use for less than five years, consistent with CRA Article 13(8).
- SBOMs are generated daily and analyzed in OWASP Dependency-Track (https://dependencytrack.org/); they are available on request to support your own supply-chain risk management and NIS2 compliance activities.
- Security advisories are published at (coming soon) https://cogentdatahub.com/advisories and via RSS.
Legal Notice
This page is provided for informational purposes and reflects Skkynet’s compliance program status as of the date above. It does not constitute legal advice. Skkynet’s compliance program is subject to change as the CRA’s implementing acts, ENISA guidance, and the Single Reporting Platform evolve. For questions about this page or Skkynet’s CRA compliance program, contact [email protected].