Portal

Want to try the CURIUM tools with your own product?
We offer free expert support to help you use the Compliance Continuum with your real digital product.
Get in touch

What is the CURIUM Continuum Portal?

The CURIUM Continuum Portal serves as the main access point through which organisations can access the CURIUM Compliance Continuum. It provides a comprehensive set of cybersecurity compliance tools, enabling organisations to meet the requirements of the Cyber Resilience Act (CRA) through a single, user-friendly interface.

The Portal offers access to five core services, including CRA scope review, risk management, risk treatment options identification and maturity, vulnerability and penetration testing, and conformity assessment. Organisations may use these services either as standalone modules or as part of a complete compliance process, depending on their specific needs and existing capabilities.

The Portal simplifies compliance with CRA requirements through its intuitive interface, offering guided workflows, automated testing capabilities, and pre-built templates for generating technical documentation and compliance materials. By bringing together technical tools and supporting resources in one place, the CURIUM Continuum Portal enables organisations to assess, enhance, and verify the cybersecurity of their digital products.

Who it is intended for

The CURIUM Continuum Portal is intended for multiple stakeholders involved in the development, evaluation, and regulation of products with digital elements. It is particularly beneficial for small and medium-sized enterprises and manufacturers seeking to comply with the Cyber Resilience Act (CRA).

The system provides support for:

  • SMEs and industry actors through the development of user-friendly assessment tools which help them evaluate cybersecurity risks and enhance product resilience and meet regulatory standards in an affordable way.
  • Cybersecurity service providers and open-source communities, by enabling them to validate security tools and components and processes, which fosters collaborative innovation.
  • Researchers/scientific communities and cyber insurance stakeholders, by providing validated methods and data-driven insights and assessment capabilities, which enable them to conduct risk analysis and generate new knowledge and make evidence-based decisions.
  • The system delivers policy makers and regulatory bodies insights into actual cybersecurity practices which help them identify compliance shortcomings and implement cybersecurity regulations.
  • Consumer associations and the general public, indirectly through the promotion of more secure, resilient, and trustworthy digital products and services.

The Portal functions as a fundamental tool that helps different groups stay secure while meeting requirements and building confidence throughout the European digital market.

Typical customer journey

The CURIUM Continuum Portal user experience follows the sequence CyReA → DPRA → DPMA → PSTVA → CAC. This flow follows a clear logic: Scope → Risk → Mitigation → Validation → Compliance, which is aligned with CRA course of thinking.

The Cyber Resilience Assessment (CyReA) service enables organizations to assess their products’ compliance with Cyber Resilience Act (CRA) requirements while determining the correct product classification. It determines if the product falls under CRA and what category it belongs to. This is the natural starting point and a prerequisite for everything else.

The Digital Product Risk Assessment (DPRA) service enables users to start their assessment after they complete their previous step, allowing them to examine cybersecurity risks of their assets and identify all potential security threats. This defines what actually needs to be addressed and provides the evidence base.
After identifying risks, the Digital Product Maturity Assessment (DPMA) service helps organizations choose their suitable risk control measures and development stages based on their existing capabilities and threat assessment (DPRA) results.
The Penetration Self-Testing and Vulnerability Assessment (PSTVA) tool then enables users to test and validate the effectiveness of their security controls by using automated penetration testing methods together with vulnerability scanning capabilities.
Finally, the Conformity Assessment and Compliance (CAC) service combines all results to assist users with technical documentation needs while conducting gap assessments and building essential compliance documents.

The Portal provides organizations with a recommended path which enables them to choose particular services based on their unique requirements and their current development stage.