arXiv · 2610.07873
Preparing an AI-Augmented SIEM for the EU Cyber Resilience Act: A Practitioner Case Study
Abstract
The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, makes product cybersecurity a lifecycle obligation for products with digital elements on the EU market: risk assessment, vulnerability handling, conformity documentation, and Article 14 incident- and vulnerability-reporting readiness must be operational before market placement. Small and medium-sized enterprises that build security products are doubly exposed, since their products are in scope while their customers expect them to be exemplary. This case study documents a CRA preparedness pilot for one such product, SEUXDR, an AI-augmented security monitoring product with a large-language-model active-response component, on the open-source CYBERFORT platform. We contribute a reproducible six-step recipe (Scope and Classify, Asset Registration, Produce Evidence, Map to CRA, Gap and Actions, Audit Pack), two end-to-end traceability threads, and a pilot snapshot tracing product risks through baseline and AI-specific controls and policies to CRA objectives. It offers practitioners a replicable starting point for translating CRA legal text into operational preparedness for incident response, vulnerability reporting, and conformity assessment.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Georgios Koutidis, Nikolaos Kekatos, Marina Korgiala-Karyda, Alexios Lekidis, Tom Nianios. 2026-10-06. Preparing an AI-Augmented SIEM for the EU Cyber Resilience Act: A Practitioner Case Study. https://arxiv.org/abs/2610.07873
Cite the original work for its findings. Save a collection to share your selection of sources.