Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Discover how AI is transforming phishing, business email compromise, and social engineering. Register for the free September 1 webinar →

CSA STAR Registry

Security, Trust, Assurance, and Risk Registry

Listings for CVD Portal by Porta Regulus B.V.

Listings for CVD Portal by Porta Regulus B.V.

Porta Regulus develops cybersecurity assurance and regulatory compliance software platforms for European hardware and software manufacturers.

Its core SaaS product, CVD Portal, delivers an automated conformity workspace for the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), governing all products with digital elements placed on the European market.

The platform provides comprehensive compliance management across the full product lifecycle: product classification, cybersecurity risk assessment, Annex I essential security requirements verification, Annex VII technical documentation generation, and EU Declaration of Conformity creation for CE marking.

For coordinated vulnerability disclosure (CVD) and statutory reporting, the platform delivers RFC 9116 security.txt hosting, whitelabel researcher submission portals, 48-hour acknowledgment tracking, and automated CRA Article 14 notification filing packages (24-hour early warning, 72-hour notification, and 14-day final reports) aligned with national CSIRTs and the ENISA Single Reporting Platform (SRP). Built-in tooling includes CycloneDX and SPDX Software Bill of Materials (SBOM) ingestion, CVSS v3.1/v4.0 scoring, and CSAF 2.0 machine-readable security advisories.

CVD Portal

CVD Portal is a multi-tenant SaaS compliance and coordinated vulnerability disclosure platform for manufacturers selling products with di...

Listed Since: 2026-08-21

CAIQ
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).