Werkspilot
@werkspilot.de
CRA vulnerability management for plant builders: automatically monitor supplier vulnerabilities, match them against deployed plants, and report within deadline.
Werkspilot's Company Logos


Werkspilot's Brand Colors
Hex Code
Color name
RGB
HSL
CMYK
#0D1F36
Blue Zodiac
13, 31, 54
214, 61, 13
76, 43, 0, 79
#F9FAFB
Athens Gray
249, 250, 251
210, 20, 98
1, 0, 0, 2
About Werkspilot
Werkspilot is a Cyber Resilience Act (CRA) compliance and supply-chain vulnerability monitoring platform for plant builders and system integrators (Anlagenbauer/Systemintegratoren).
A modern industrial plant combines hundreds of components from dozens of suppliers, whose vulnerability advisories arrive in inconsistent formats — from machine-readable CSAF feeds to plain email. From September 2026, the CRA requires actively exploited vulnerabilities to be reported within 24 hours — across a full supply chain, doing this manually is barely feasible.
Werkspilot continuously monitors supplier feeds, matches new vulnerabilities against the SBOMs, plants and firmware versions actually deployed in the field, and prioritizes what matters — turning a supplier advisory into an audit-ready customer notification on time and fully documented.
Werkspilot also delivers STRIDE-based threat and risk assessments for complete plants, as required by the EU Machinery Regulation from January 2027 and the CRA.
Company type
Privately Held
Year founded
2025
Company size
2-10 employees