CRA compliance doesn't end at product launch.
Neither does Lucerna.

AI led, audit ready vulnerability management for your products, built by engineers who live with the same challenge every day.

EU Cyber Resilience Act: reporting duties begin 11 September 2026

Rufilla is trusted by teams building smart products for:

Visual Portfolio, Posts & Image Gallery for WordPress
Curtiss Wright Logo

The problem.

Embedded products live for years in the field. The CVE databases that affect your platform update every single day. Without a clear, documented record of which vulnerabilities you reviewed and what you decided, you’re either redoing the same triage work every sprint, or flying blind.

And if a regulator, a customer’s procurement team or an auditor asks you to prove your security decisions, a spreadsheet won’t cut it.

Smart products live for years.
Vulnerabilities never stop.

That’s exactly why we built Lucerna.
red partnership icon

Every CVE decision recorded, timestamped, and retrievable

red arrow

AI that reads your actual build, not just a generic CVE list

The rules have changed. Security compliance is now
a legal requirement.

Connected products are now subject to mandatory cybersecurity obligations in both the UK and EU. Regulators increasingly expect manufacturers to prove how vulnerabilities are identified, assessed and managed over time. Under the EU Cyber Resilience Act, reporting obligations begin on 11 September 2026, with full obligations following in December 2027. Lucerna is built to have you ready.

If you sell products with digital elements into the EU and you learn of an actively exploited vulnerability in one of them, you have 24 hours to file an early warning with your CSIRT and ENISA. It applies to products already on the market, not just new ones. Full obligations follow from December 2027, but the reporting duty starts now. Lucerna is built to have you ready.

Everything You Need to Know About the New Smart Product Security Laws

Download our free guide

See Lucerna in Action

See exactly how Lucerna fits into your workflow and what your audit trail would look like.

What Lucerna actually does

Lucerna gives you a single, persistent home for every CVE decision your team makes across your product’s entire lifetime.

It’s AI led. Lucerna reads your actual software build, your hardware configuration where available and your product spec, so it can show whether a CVE genuinely applies to your product, and explain why. The AI advises. Your engineers decide.

Every triage action is recorded with who made the call, when, why, and what the AI said at the time, creating the documented audit trail that PSTI and EU CRA auditors look for.

It’s not another scanner that floods you with alerts. It’s the place where those alerts get turned into defensible decisions.

Upload and baseline in minutes

Upload and baseline in minutes

Automatic for Yocto teams
A custom meta layer, built by Rufilla, feeds every software build into Lucerna automatically. No manual step, Lucerna builds your baseline from the first scan.
Works with SPDX and SBOMs too
Prefer to work another way? Import a Yocto-style CVE JSON manifest, a standard SPDX format, or upload a software bill of materials (SBOM) directly. Lucerna also generates SBOM downloads and PDF status reports, so information flows both in and out.
Stop reviewing old vulnerabilities twice
Future uploads become deltas, helping teams focus on newly introduced risk instead of repeating old triage work.
Upload and baseline in minutes
Triage App
Triage that actually sticks

Triage that actually sticks

Every decision is recorded
Each CVE action includes rationale, timestamp and ownership, alongside the AI’s assessment at the time you made the call.
Previously reviewed issues stay closed
Triaged vulnerabilities only reappear if upstream statuses change or your team intentionally reopens them.
Four clear actions
Untriaged, patched, accepted risk, not applicable. When you triage a CVE, you choose a status and record your reasoning. Every call is documented, versioned and retrievable, so your team always knows where each decision came from and why.
Your AI Triage Assistant

Your AI Triage Assistant

It knows your product
Ask the AI Triage Assistant about any CVE and it explains why the vulnerability does, or doesn’t, apply to your build.
Tell it something once, and it remembers
Tell the AI Triage Assistant a fact about your product, such as “we don’t use Bluetooth”, and its assessments update from there. It will flag things back to you too, for instance if Bluetooth is switched on in the software but never used.
Context aware scoring with the Lucerna Scoring System
A vulnerability might carry a generic industry score (CVSS) of 9.8 out of 10, but if your product doesn’t have the affected interface, Lucerna’s own Lucerna Scoring System (LSS) might rate it 5.0. It works the other way too, knowledge of your platform can make a vulnerability more serious than its CVSS rating suggests. The AI recommends. The engineer decides.
Joe at Rufilla on a support call with clients

Filter for what actually matters

Prioritise genuine risk
Filter by Lucerna Score (LSS), CVSS, EPSS percentile, attack vector, package or other criteria, and sort straight to the vulnerabilities attackers are actively exploiting right now. Under the CRA, these are the ones that start the 24 hour reporting clock.
Share views across teams
Generate a PDF report to share with internal teams and subcontractors, a clear snapshot of exactly where your product stands.
Joe at Rufilla on a support call with clients
red box icons

Overnight alerts without the noise

Behind the scenes, Lucerna’s own vulnerability engine works through around 380,000 published CVEs, and rising daily, combining multiple data sources and running deep AI analysis to filter that down to the roughly 1,600 that attackers are actively exploiting right now. It refreshes overnight, every night.

Once a product has shipped, Lucerna keeps tracking it. Every release is rechecked daily as new CVEs appear, with an email alert the moment something dangerous lands in your software, and a daily reminder of anything still needing attention for CRA reporting.

You can also integrate Lucerna into CI workflows, preventing critical unresolved vulnerabilities from passing through builds unnoticed.

CRA reporting, without the blank page

The 24 hour early warning, handled
Learn of an actively exploited vulnerability and the clock starts. The AI CRA Assistant drafts your early warning to CSIRT and ENISA from inside Lucerna, ready for your engineer to check and submit within the 24 hour window.
The 14 day final report, tracked
The final report is due within 14 days of an actively exploited vulnerability landing, and Lucerna won’t let you mark it complete until every required field is filled in. From the report, jump straight back to triage to check whether the CVE is still applicable before you submit.
Incident reporting, covered
Report against a known CVE that’s been used to attack your product, or against something brand new that isn’t catalogued yet, and it applies whether the product shipped last week or five years ago. The AI CRA Assistant auto fills the CSIRT and ENISA forms either way.


Generate evidence instantly

Export a compliance report in PDF at any point
Every report includes open vulnerabilities, dismissed issues and recorded rationale, a clear, defensible snapshot of exactly where your product stands.
Built for real world audits
The goal isn’t certification. It’s a security process that stands up when it’s asked to.

Core capability

Yocto-style JSON and standard SPDX formats, including automatic upload through Rufilla's Yocto meta layer
AI Triage Assistant with context aware scoring through the Lucerna Scoring System (LSS)
Persistent CVE triage with mandatory rationale
Multi-product vulnerability tracking
Role based access and audit history
REST API for CI integration and build gating
Overnight high severity alerts and daily post release monitoring
CSIRT and ENISA reporting with the AI CRA Assistant, early warning within 24 hours
Bulk triage operations
PDF compliance reporting and SBOM generation
red box icons

Built By People Who Actually Use It

We built Lucerna because we needed it ourselves.


We work on long life embedded products where security audits can happen years after deployment. Explaining every vulnerability decision through spreadsheets and disconnected processes simply wasn’t sustainable.

So we built the platform we wanted to use ourselves, then gave it the AI we wished we’d had from day one.

Lucerna is used internally across Rufilla projects every day, which means the roadmap is driven by real engineering needs, not abstract feature lists or marketing trends.

See Lucerna in Action

See exactly how Lucerna fits into your workflow and what your audit trail would look like.

Oxford Instruments Sets the Standard for Embedded Security Compliance with Rufilla Lucerna

by Joe Nicholson

Managing Director & Founder

Oxford Instruments sets the standard for embedded security compliance with Rufilla Lucerna

May 1, 2026

Oxford Instruments has always held itself to a high standard. When it comes to embedded security, they’re not waiting to be told what to do. They’re already doing it.

The company has taken out an annual licence for Lucerna, putting the infrastructure in place to build the documented, auditable security record that regulators and customers increasingly expect to see, across a product portfolio with deployment timelines measured in years.

“We built Lucerna because we needed it ourselves. Working on long life embedded products, we understood that staying compliant over time is the genuinely hard part. Oxford Instruments has understood this from the outset, and we’re proud to be supporting them in building exactly the kind of structured, continuous security process their products deserve.”

Frequently Asked Questions

Does Lucerna work with build systems other than Yocto?
Lucerna is built specifically around Yocto Linux and ingests native Yocto JSON natively, alongside SPDX and CycloneDX formats. If your build system outputs SPDX or CycloneDX, you can upload those directly. If you’re working on a Buildroot or custom BSP setup, get in touch and we can talk through what’s possible.
Does Lucerna need to connect to the internet or our internal systems?
From signing up to your first baseline scan is typically a matter of hours, not weeks. Incorporate the Lucerna Yocto layer into your build, run your first scan, upload the output, and the platform creates your baseline. Everything from there is a delta on top of that first snapshot.
How long does it take to get started?
The honest answer is that it depends on how you manage vulnerability triage now. If you’re currently doing it ad-hoc or in spreadsheets, Lucerna will actually reduce the time you spend on it — particularly through bulk operations, overnight diff alerts, and persistent triage decisions that mean you never re-examine the same CVE from scratch. If you have no existing process, there’s a short setup phase, but most teams are running smoothly within a day or two.
We're a small team. Is Lucerna going to add a lot of overhead?
Yes. Role-based access controls let you define who can triage, who can view, and who gets read-only access. Subcontractors can be given a shareable filtered URL for a specific project view without needing a full account if the project is set to read-only.
Does the AI make our triage decisions for us?
No. The AI Triage Assistant reads your build, hardware configuration and product spec to score and explain each CVE, but every decision, and the responsibility for it, stays with your engineer. The full reasoning is kept in the audit trail.
Does Lucerna certify our product as compliant?
No. Lucerna doesn’t certify products or replace security engineering work.
What it does provide is a structured, auditable record of the vulnerability decisions your team makes over time, including rationale, ownership, and history. That evidence is increasingly important for PSTI, EU CRA, procurement reviews, and customer security assessments.
What compliance frameworks does the audit trail support?
If the NVD score on a previously triaged CVE changes materially, Lucerna automatically returns it to your Open list so it can be re-reviewed in light of the updated information. Nothing falls through the gaps between build cycles.
What happens when a CVE I've already triaged changes?
No. Lucerna deploys on-premises via a single Docker Compose command and runs in fully air-gapped environments. Your build data stays on your infrastructure. If you need to share a filtered view with an external subcontractor, the read-only shareable URL feature handles that without requiring them to have an account or access to your full project.
Can multiple team members and subcontractors use the platform?
The triage audit trail — with timestamps, user IDs, and free-text rationale stored in PostgreSQL — is designed to satisfy the documentation requirements of UK PSTI, the EU Cyber Resilience Act, and IEC 81001-5-1 for medical devices. It also holds up well against the kind of security questionnaires that enterprise procurement teams and insurers are increasingly sending out before contracts are signed.
How is the Lucerna Score different from CVSS?
CVSS is a generic industry score. The Lucerna Score (LSS) reflects your actual product, so a critical rated vulnerability that doesn’t apply to your build shows as low risk, and a lower rated one that does apply can show as high. It works alongside CVSS, not instead of it.

See Lucerna in action.

We’ll walk you through the platform with your build environment and use case in mind. If you’ve got a SBOM you’d like to run through it, bring it along.
 
In 30 minutes you’ll see exactly how Lucerna fits into your workflow and what your audit trail would look like.
 
What to expect: a live walkthrough tailored to your sector and stack, an honest conversation about what compliance looks like for your specific product, and clear next steps with no hard sell.

Prefer to talk first? Call us on +44 (0)1865 601201 or email hello@rufilla.com