Skip to main content

Trust portal for approved viewers

The trust portal lets a company share its Cyber Resilience Act compliance records with specific external people it has approved, such as customers, auditors, and distributors. It is an Enterprise feature.

What viewers see

Approved viewers sign in at your-company.cvdportal.com/trust and see:

  • Company Compliance Documents: EU digital identity verification status (eIDAS 2.0), published security advisories (CSAF/VEX), the Coordinated Vulnerability Disclosure policy (security.txt), a statement that the audit trail is tamper-evident, and vulnerability database scan verification.
  • Shared Products: For each shared product: its CRA classification and conformity route, the security update period, the draft EU Declaration of Conformity, the Annex VII technical-documentation index, and component vulnerability scan status.

Only the latest frozen snapshot of a product is shared, never live in-progress drafts. Every conformity record carries a notice that it does not by itself constitute a presumption of conformity or a guarantee of compliance.

Enabling and customizing published records

Under Settings → Trust Portal:

  1. Enable the Trust Portal: Master toggle activates the portal at your-company.cvdportal.com/trust. When enabled, all publication options show as enabled by default so viewers receive full transparency immediately.
  2. Select Global Published Sections: Administrators can uncheck/toggle off any section:
    • EU Digital Identity Verification: Proves corporate legal identity under eIDAS 2.0.
    • Published Security Advisories: Links to public CSAF/VEX advisories required by CRA Article 14.
    • Coordinated Vulnerability Disclosure Policy: Displays RFC 9116 security contact and policy details.
    • Tamper-Evident Audit Log Notice: Confirms all compliance actions are hash-chained.
    • Vulnerability Check Verification Summary: Displays global scan verification (e.g. 0 active KEVs).

Product-level publication settings

On any product page under the Monitoring tab:

  1. Use "Share on trust portal" to include the product in the trust portal index.
  2. Customize which specific artifacts are published for that product:
    • EU Declaration of Conformity (DoC): Provides official CRA compliance declaration text.
    • Annex VII Technical Documentation Index: Displays file index for technical files.
    • Security Update Support Period: Displays committed end-of-support dates.
    • Vulnerability & SBOM Verification: Confirms component dependencies carry no known unmitigated unacceptable risks (GCVE, OSV, CISA KEV).

Managing viewer access

  1. Approve Viewers: People can request access directly from the portal, or an administrator can invite an email address.
  2. Single-Use Magic Links: Approved viewers receive a private magic link. Opening the link sets a signed 7-day session cookie on the tenant host and consumes the token.
  3. Revoking Access: Revoke a viewer at any time in Settings → Trust Portal. Access terminates immediately on their next page load.

Delegating a control (assignments)

Separately from the trust portal, an admin can assign a single CRA control to an outside person to provide information or upload a document. The assignee gets a magic link to a one-off contribution page, and their submission is filed as evidence for that control. See the Evidence tab on a product page.