Responsibility for software
does not end with delivery

Make components, licence terms and updates traceable.

Dependencies and forms of provision influence which evidence and measures a software product requires. Without an overview, assessing new vulnerabilities and licence obligations becomes laborious.

IQstruct Engineering supports the technical and organisational preparation of product requirements. Open source components are examined with regard to planned use, modification and distribution. An SBOM can complement the component overview. Manufacturer notices and updates are integrated into test and operating processes.

Start now at no cost

In a free first conversation we sort out which of your products fall under the regulation and which records are still missing for them.

Arrange a first conversation

Scope of services

Record components transparently

Product components and versions form the basis for further assessment.

Clarify licence terms before use

Relevant conditions are agreed with the customer.

Prepare updates

Testing, maintenance windows and rollback connect development and later operation.

Keeping an eye on components, licences and updates

IQstruct Engineering supports the technical and organisational preparation of product requirements, including those from the Cyber Resilience Act.

Before an open source component is used, we check the licence type, commercial use, modification, distribution and server-side provision. Copyleft licences such as the AGPL are distinguished from permissive licences such as MIT; relevant conditions are documented and agreed with you.

An SBOM complements the component overview and supports later vulnerability and update processes. Manufacturer notices and security updates are monitored and brought into operation via relevance, testing, release, rollout and rollback.

Green printed circuit board with microchips and components in close-up

Product compliance

Responsibility for software extends beyond delivery

A traceable component overview makes it easier to assess new vulnerabilities and licence obligations.

Approach in the project

  1. Three people record a device with embedded software at a table, the product overview on the screenAi

    1

    Record digital products

    Products with embedded software and their interfaces are recorded.

  2. A developer checks the list of software components with versions and licences on the screenAi

    2

    Assess components

    Software components, libraries and licences are listed in an SBOM.

  3. An employee compares published vulnerabilities with the component inventory on the screenAi

    3

    Monitor vulnerabilities

    Manufacturer notices and CVE information are matched against the component inventory.

  4. An employee processes an incoming vulnerability report on the screen and forwards itAi

    4

    Handle reporting channels

    Incoming vulnerability reports are handled and forwarded in the ticket system.

Which form of use counts

Internal use

The software stays within your own company.

Distribution and modification

The product goes to customers with modified components.

Provision as a service

The software runs on the server side and is used over the network.

Scope boundary

Technical classification with legal supplement

Our documentation classifies components, licences and updates in a technically traceable way.

You clarify binding legal advice and final conformity decisions with your legal experts; our documents serve them as a basis.

Frequently asked questions

We are glad to answer your detailed questions in a personal conversation.

Does IQstruct Engineering take on the legal assessment?

The legal assessment lies with your legal advisers. IQstruct Engineering supplies the technical classification and documentation.

Is an SBOM mandatory?

Whether and in which form an SBOM is required depends on the product and the applicable requirements. We take it into account as part of the component documentation.

How do security updates get into the product?

Manufacturer notices are monitored; updates run via relevance assessment, testing, release, rollout and rollback.

First conversation

Arrange a free first conversation

Describe your task. We agree a date and discuss the possible project scope.

  1. Notebook on a desk with an open calendar and a selected appointmentAi

    1

    You request an appointment

  2. Experts at a meeting table discussing an extensive software architecture on the screenAi

    2

    We discuss your requirements

  3. Workstation with a measuring application built with graphical programming and a web interfaceAi

    3

    You receive a quotation for the agreed scope

Philipp Niemann-Stryczek
Philipp Niemann-StryczekManaging DirectorLeads the company on the commercial side and answers questions on IT/OT security, asset administration shells, compliance and research projects.
Free first conversation

Describe your task in the contact form. We come back with a proposed date.

Arrange a first conversation

Not quite what you need?

Discover further suitable services.

CI/CD and quality assurance

Combine automated tests, security checks and traceable releases.

Information security, audits and evidence

Organise responsibilities, risks and evidence in an operable information security management system.

Vulnerabilities and updates

Prioritise findings and plan updates to suit your operating systems and plants.