For MSPs & consultancies

Deliver CRA readiness to every client — not just your biggest.

The CRA is forcing thousands of manufacturers to build a capability they don't have. That's your opportunity. But delivering vulnerability handling and evidence by hand, client by client, caps how many you can serve. ProvenVEX makes it a repeatable, multi-tenant service — with exploitation evidence your clients can't get from a scan.

Multi-tenantPer-client isolation, auditedEU-hosted
The opportunity

A wave of forced demand, and most of it has nowhere to turn.

From September 2026 the CRA obliges manufacturers to report and handle vulnerabilities. Most small and mid-market makers have no product-security function to do it. They will look for help — and the ones who provide it early win the account.

Demand

Non-discretionary and dated

This isn't a project a client can defer. The deadline is fixed and the penalty is real, which makes CRA readiness one of the few security services that sells itself.

Fit

Your relationship already exists

You're the trusted security or engineering partner your clients already call. CRA readiness extends that relationship into a recurring engagement, not a one-off.

Ceiling

Manual delivery doesn't scale

Assessing which CVEs matter, per product, per client, by hand is the same bottleneck a manufacturer faces — multiplied by every client you take on.

Built for the way you work

Multi-tenant by design.

Run every client from one console, without standing up separate tooling — or separate risk — for each.

Isolation you can show a client.

Each client is a separate tenant with strict data separation. Your cross-tenant access as an operator is explicit, scoped to your assigned clients, and audited — so when a manufacturer asks who can see their vulnerability data, the answer is a log, not a promise. That's the difference between a platform a regulated client will accept and one they won't.

Onboard

A new client in an afternoon

Bring their SBOMs — or generate them — and their portfolio is under management. No per-client infrastructure to build.

Operate

One view across the book

See every client's products, determinations and reportability candidates from a single operator console, scoped to what you're allowed to see.

The engagement

What you deliver, repeatably.

The same defensible outcome for every client, produced by the engine and delivered under your name.

01

Ingest the client's inventory

Their SBOMs, per product and version — taken as input from whatever they already generate.

02

Run the assessment

Correlation, then reachability and exploitation proof, to decide which CVEs actually affect the client's product.

03

Deliver the evidence

Evidence-backed VEX where each not_affected carries its proof, plus a reportability shortlist for the 24 / 72 / 14 obligation.

04

Retain and repeat

An immutable evidence bundle per product for the technical file — and a standing relationship as the client's portfolio grows.

The differentiator you can sell

Evidence, not another SBOM tool.

Any consultancy can hand a client a scan report and a VEX file full of asserted statuses. So can a free tool. It's a commodity, and it prices like one. What almost nobody can deliver is a not_affected backed by an exploitation attempt — a determination the client could put in front of a market-surveillance authority.

That's a higher-value engagement, and a more defensible one: you're not asserting on the client's behalf, you're delivering evidence. It moves the conversation from "we ran a scan" to "we can prove which vulnerabilities you have to report," which is exactly what the accountable owner at your client is anxious about. The mechanics are the same evidence-backed VEX the platform runs everywhere — you're just delivering it as a service.

Commercials

Priced to grow with your book.

The partner model is priced by client and usage rather than a single seat licence, so your cost tracks the accounts you actually serve — you add margin, not overhead, with each new manufacturer. Onboard a first client to prove the motion, then scale across your base as the September 2026 deadline pulls demand forward.

Exact partner terms are set case by case. The best next step is a conversation about your client base and how you'd package the service.

Partner questions

The honest answers.

Can I manage multiple client manufacturers from one place?

Yes. ProvenVEX is multi-tenant: you operate across the client manufacturers assigned to you, each as an isolated tenant, from a single console. You onboard a client's SBOMs, run the assessment, and deliver the outcome without standing up separate tooling per client.

Is each client's data isolated?

Yes. Tenant data is strictly separated per client. Your cross-tenant access as an MSP operator is explicit, scoped to the clients assigned to you, and audited — so a client can see that their data is only reachable by the people who should reach it.

What do I actually deliver to a client?

A defensible CRA vulnerability-handling outcome per product and version: evidence-backed VEX where each not_affected carries its proof, a reportability shortlist for the 24/72/14 obligation, and an immutable, retained evidence bundle for the technical file. It's a service outcome you can put your name on, not a raw scan report.

How does pricing work for partners?

Through a partner/MSP arrangement priced by client and usage rather than a single per-seat licence, so your cost tracks the clients you serve. Exact terms are set per partner; pricing is indicative and best discussed directly.

Channel partners

Add CRA readiness to what you already deliver.

Tell us about your client base. We'll set up a partner tenant and run a first client's product end to end, so you can see the service you'd be selling.

Multi-tenant · per-client isolation, audited · EU-hosted · partner pricing by client & usage