Press

Material on the CRA readiness check and on Innomatica GmbH. Everything on this page may be used free of charge.

Diese Seite auf Deutsch

Press contact

Ivan Maradzhiyski

Founder and Managing Director, Innomatica GmbH

Phone: +49 711 365 570 21
Mobile: +49 151 5814 6334
Email: [email protected]

Call any time, including at short notice. I am a developer, not a press officer — if you want to dig into the technical detail, all the better. Test access and further screenshots are available on request.

About Innomatica — free to use

This paragraph is written to be quoted verbatim.

Innomatica GmbH, based in Ostfildern near Stuttgart, Germany, builds self-hosted tools for release management and CRA compliance in embedded software development. Its product embtrace generates software bills of materials, tracks known vulnerabilities across a product's lifetime and prepares the evidence the EU Cyber Resilience Act requires from manufacturers. The company was founded by Ivan Maradzhiyski, who has been writing embedded software for more than twenty years. More at embtrace.dev.

Images

Free of charge, credit: Innomatica GmbH. Please do not alter the proportions.

embtrace logo

embtrace logo

Caption: “embtrace — a tool for CRA evidence in embedded development, Innomatica GmbH”

SVG, light · SVG, dark · PNG, 512 px

embtrace icon

Icon

For small formats and thumbnails.

SVG, light · SVG, dark

Portrait of Ivan Maradzhiyski, Managing Director of Innomatica GmbH

Portrait of Ivan Maradzhiyski

Caption: “Ivan Maradzhiyski, Managing Director of Innomatica GmbH. Photo: Photo Schneider, Kirchheim unter Teck. Free of charge when the source is credited.”

Print resolution, 2400 × 3000 pixels, 1.5 MB · Web resolution, 800 × 1000 pixels

The print file gives roughly 20 cm width at 300 dpi. Please credit the photographer — the name belongs in the caption even though the image is free to use.

Excerpt from an embtrace report: table with component, version, supplier and licence

Excerpt from a report

Caption: “The component inventory from an embtrace report: version, supplier and licence for every component. Example from a public demonstration project (Zephyr and U-Boot). Credit: Innomatica GmbH, free of charge.”

Download PNG

The report shown comes from a public demonstration project, not from customer work. A full sample report is available as a PDF on request.

Releases

3 September 2026

CRA reporting duty starts 11 September: free readiness check shows embedded teams where they stand, within 24 hours

Ostfildern, Germany, 3 September 2026. From 11 September, the EU Cyber Resilience Act (Regulation (EU) 2024/2847, Article 14) requires manufacturers to report actively exploited vulnerabilities within 24 hours, to the CSIRT designated as coordinator and to ENISA. The clock starts the moment the manufacturer becomes aware. Many embedded projects lack what it takes to meet that deadline: a current inventory of the software components they ship. If you do not know what is inside your product, you cannot tell whether an actively exploited flaw affects you.

Innomatica GmbH, based in Ostfildern near Stuttgart, has released the CRA Readiness Check for exactly that question — free of charge, once per company. A team requests a one-time code at embtrace.dev/en/check, runs a single command in the project folder and receives a PDF report by email: traffic-light status against EU 2024/2847, the component inventory, known vulnerabilities with a concrete update plan, and licence risks. There is a reason it takes up to 24 hours: every report is reviewed by hand before it goes out.

The collector is open source (MIT licence), runs inside the customer's project folder and transmits metadata only to servers in Germany — essentially which components are present in which versions; no source code, no file paths. What leaves the building can be checked byte for byte beforehand with the --dry-run option. On the server, components are matched against public vulnerability databases; the analysis rests on a deterministic parser pipeline covering eleven build systems. On one real production project it inventoried 1,089 components, each with supplier, version, licence and package identifier.

“You cannot hold a 24-hour deadline without a current component inventory,” says Ivan Maradzhiyski, founder of Innomatica GmbH. “The check is deliberately a starting point, not a certificate: it shows what is inside a product and where the known gaps are. It claims nothing beyond that.”

The free check reports CRA status; embtrace generates SBOMs either to CRA requirements or to BSI TR-03183-2 (v2.1.0), the technical guideline of the German Federal Office for Information Security — for manufacturers selling to public authorities or critical infrastructure, that guideline is the yardstick that counts. The check is aimed at smaller embedded teams and at importers who take on the CRA's manufacturer obligations for products from outside the EU. Available at: embtrace.dev/en/check

About Innomatica: Innomatica GmbH (Ostfildern, Germany) builds self-hosted tools for release management and CRA compliance in embedded software development.

Press contact: Ivan Maradzhiyski · [email protected] · embtrace.dev