Detect, track, and remediate vulnerabilities — across your entire portfolio
Continuous NVD/OSV matching, CVE tracking with SLA management, and dashboard analytics in one platform
Annex I Part II of the EU Cyber Resilience Act requires manufacturers to address and remediate vulnerabilities without delay across the entire support period. Kunnus covers the complete workflow: components are continuously matched against NVD and OSV, and every detected vulnerability is tracked against SLA deadlines to resolution — including a real-time dashboard with MTTA, MTTD, and MTTR.
Vulnerability Mgmt
Key Benefits
CVE Tracking & SLA Management
CVE list with CVSS score, severity badge, SLA status (On Track / At Risk / Breached), assignee, and discovered date.
Continuous Sync with Trustify
One-click sync against the Trustify database. Shows SBOMs scanned and new vulnerabilities discovered. Automatic correlation with your portfolio.
Security Updates Followed Up
Fixes and security updates are tracked per product and version — separate from feature updates, as Annex I Part II No. 2 requires.
Security Dashboard Analytics
MTTA/MTTD/MTTR metrics, CVSS histogram, top-risk products, components, and vendors. Configurable time range for trend analysis.
Capabilities
CVE Detail & Response Timeline
Annex I Part II No. 2Full CVE information, affected components, status, assignment, and response timeline. Every step documented and traceable.
Own Vulnerability Reporting & Tracking
Art. 13Manually report and track internally discovered vulnerabilities. Manual CVE entry, SLA assignment, and full tracking.
Regular Tests & Reviews
Annex I Part II No. 3Continuous vulnerability monitoring plus CI scans with the open-source kunnus-scanner. Test cycles are documented as evidence.
CSAF Feed Ingestion
External CSAF feeds are auto-ingested and tracked against your SLA rules. Seamless integration into the existing vulnerability workflow.
Configurable Dashboard
Severity breakdown, SLA status, resolution metrics, and trend charts. Freely configurable time range for management reporting.
Use Cases
Proactive Vulnerability Management
A manufacturer syncs daily with Trustify, detects new CVEs automatically, and tracks remediation with SLA tracking — from discovery to fix.
Shared Components across the Portfolio
A vulnerability in a shared library affects twelve product variants. Kunnus shows all affected products instantly and tracks remediation per variant.
Management Reporting
The security dashboard shows MTTA, MTTD, and MTTR at a glance. Leadership gets reliable metrics for audits and compliance evidence.
Related Features
Keep vulnerabilities under control
See how Kunnus automates CVE tracking and SLA management. We'll walk you through the workflow in a personalized demo.