Supply Chain Compliance
Something you did not write is sitting in your product, and it can block a deal, fail an audit or put liability on you. Not because it has a vulnerability, but because its licence changed, its supplier changed terms, or you were supposed to have an agreement in place and do not. BETA - expected release Q1 2027.
You answer for everything in your product, including what you did not build.
Multiple regimes now impose duties that attach to what is inside your product rather than to what your product does. Grecta tracks the legal state of your components and tells you which obligation each change touches.
Watches the legal state, not the CVE feed.
Licence terms, maintainer status, support lifecycle, sub-processor lists and supplier terms, each mapped to the obligation it affects.
Names the duty, not just the risk score.
A change is reported as the provision it engages and the action it requires, not as a severity number your legal team cannot act on.
Covers both directions.
What you owe buyers and authorities about your components, and what you owe upstream to the people maintaining them.
Security tooling answers whether a component is dangerous. Grecta answers whether it is lawful.
From manifest to obligation
Grecta reads your component inventory and resolves which regimes impose duties on each item, based on what the component is and how your product uses it. Each component is bound to the specific obligations it engages, from CRA due diligence through to AI Act supplier agreements and GDPR sub-processor terms. When the legal state of a component changes, the affected obligations are flagged with what is now required.
Connect sources, derive position, publish link
Your manifests, lock files and vendor list are resolved into a component inventory, including transitive dependencies, third-party services and any foundation models the product calls. Each component is mapped to the duties it engages across every applicable regime, and to the artefacts in your technical file that currently evidence those duties.
When a licence, a term, a maintainer status or a support position changes, the affected obligation is flagged along with the document it invalidates and the action required.
12
regimes with component-level duties
5
legal event types tracked — licence change, supplier terms change, sub-processor addition, maintainer or stewardship change, end of support.
2
directions of duty — what you owe downstream to buyers and authorities, and what you owe upstream to component maintainers under Article 13(6) of the CRA.
The four things a scanner cannot tell you (but Grecta does)
Due diligence you can evidence.
Article 13(5) of the Cyber Resilience Act requires manufacturers to exercise due diligence when integrating third-party components, expressly including free and open-source software not placed on the market commercially. Due diligence is something you have to show you did, not something you can assert afterwards, and Grecta records it as it happens.
Supplier agreements you are required to hold.
Article 25(4) of the AI Act requires third parties supplying tools, services, components or processes to a high-risk AI provider to specify by written agreement the information, capabilities and technical access you need to meet your own obligations. Most companies discover this obligation exists after the supplier relationship is already contracted.
The upstream duty nobody knows about.
Article 13(6) of the CRA requires you to report vulnerabilities you find in an integrated component to the person or entity maintaining it, and to share the fix. Your obligation does not stop at your own product boundary, and almost nobody has a process for the part that points outward.
An SBOM that means something legally.
Annex I Part II of the CRA requires you to identify and document components, including the supply chain relationships between them. Grecta takes the inventory you already generate and binds it to the obligations each component engages, so it becomes evidence rather than a file.
Where lack of supply chain compliance becomes the problem
Products built on open-source components.
The CRA imposes due diligence on integrated free and open-source software and a reporting duty back to maintainers. A component that loses its maintainer, changes licence or is relicensed under restrictive terms changes your position without changing a line of your code.
AI products built on third-party foundation models.
You need the supplier's Article 25(4) written agreement, and you need the documentation a general-purpose model provider is obliged to give you. If you substantially modify the model or change its intended purpose, Article 25(1) can make you the provider, with the full obligation set that carries.
Financial entities under DORA.
The register of information on ICT third-party arrangements is a legal artefact available to competent authorities on request, and contractual requirements bite where a provider supports a critical function. A sub-outsourcing change at a vendor is a register update, not an IT ticket.
SaaS processing personal data.
A vendor adding a sub-processor triggers notice and objection rights under your Article 28 terms, and a sub-processor in a third country changes your transfer position. Your customers' own DPAs make this your problem within days of it happening.
Find out what your stack actually obliges you to do
Map your component inventory once and see which duties each item engages, across every regime that applies to your product. Join the waitlist, or ask for a sample supply chain compliance report against a component set like yours.
Join the pilotFAQ
Those tools answer whether a component is vulnerable. This answers which legal obligation a component engages and what changes when its legal state moves. They are complementary rather than competing, and you should keep yours. A CVE lands in your engineering backlog. A licence change or a supplier terms change lands nowhere at all, which is the gap.
No. This covers the software and service components inside your product, and the obligations they create under the Cyber Resilience Act, the AI Act, DORA, NIS2 and GDPR. Corporate sustainability due diligence under Directive (EU) 2024/1760 is a separate regime with a different subject matter, and Grecta does not cover it.
Yes, and you should keep generating the SBOM where you generate it now. Grecta consumes it. Annex I Part II of the CRA requires you to identify and document components and their supply chain relationships, and the useful step is binding that inventory to the obligations each component engages, so the file becomes evidence rather than an artefact nobody reads.
A licence change or relicensing, a change to a supplier's terms of service or data retention position, a sub-processor addition or removal, a change of maintainer or stewardship, and an end-of-support or end-of-life declaration. None of these produce a vulnerability, all of them change an obligation, and most of them are announced somewhere nobody on your team reads.
Three things. You need the Article 25(4) written agreement from the supplier unless the exception applies, and the free and open-source exception expressly does not cover general-purpose AI models. You need the documentation the model provider is obliged to supply. And if you substantially modify the model or put it to a purpose that makes it high-risk, Article 25(1) can transfer provider obligations onto you.
Under Article 13(6) of the CRA, where you identify a vulnerability in a component integrated into your product, you report it to the person or entity maintaining that component, and where you have developed a fix, you share the relevant code or documentation. It is the only obligation in this area that points away from you rather than at you, and it is the one most companies have no process for at all.
Regulatory change, without the monitoring
When a component obligation moves under CRA, DORA, NIS2, GDPR or the AI Act, we work out what changed and what it means for products like yours. One email, only when something actually happens.
Subscribe to waitlistNo digest, no roundup, no news you already saw on LinkedIn.