Skip to main content

Norigen

Norigen provides a supply chain security platform that helps EU companies map suppliers, software components, and vulnerabilities to the products and business services that depend on them. The platform is built specifically to support compliance with the EU Cyber Resilience Act (CRA), including its mandatory vulnerability reporting timelines. It offers a four-step workflow—assess, tier, assess, and mitigate—to identify critical dependencies and prepare for regulatory obligations.

Stockholm, Sweden · HQ
310+ followers
Updated 4 days ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

EU companies that manufacture products with digital elements face growing regulatory pressure to secure their supply chains, yet most lack a consistent process for mapping which suppliers and software components feed into which products. When a vulnerability is discovered, teams often cannot quickly answer which product is affected, which component caused it, or which supplier introduced it—leaving them unable to meet the Cyber Resilience Act's strict reporting deadlines of 24 hours for early warnings and 72 hours for technical notifications.

Solution

Norigen provides a supply chain security platform that maps suppliers, software components, and vulnerabilities to the products and business services that depend on them. The platform guides users through a four-step workflow: assess suppliers against standard security requirements, tier them by criticality and vulnerable dependencies, apply the security model, and decide on mitigation actions. It is built in accordance with ISO/IEC 27036 for supplier and ICT supply chain security, and is designed to help companies prepare for CRA reporting obligations that begin applying on 11 September 2026. The platform is GDPR compliant and EU hosted, ensuring data sovereignty for European customers.

Target Audience

Primary customers are EU companies shipping products with digital elements, as well as organizations assessing third-party suppliers and their components for supply chain security and regulatory compliance.

Features

  • Supplier mapping and dependency visualization that links components, releases, and products to identify critical paths in the digital supply chain
  • Standardized security assessment framework aligned with ISO/IEC 27036 for consistent supplier evaluation
  • Criticality tiering to prioritize vulnerable dependencies and focus mitigation efforts
  • CRA-specific reporting readiness, including the ability to answer which product, component, and supplier are involved in an incident within regulatory timelines
  • GDPR-compliant, EU-hosted infrastructure for data protection compliance
This profile is AI-generated and may contain inaccuracies.