Keep your tools. Connect your lifecycle.
KaaS TRACE links your software releases to Windchill product configurations, imports and validates Software BOMs, and shows exactly which products are affected by a component: the evidence trail the EU Cyber Resilience Act requires, built on top of the PLM, ALM, Git and CI/CD tools you already use.
Operational in weeks, not a lengthy PLM/ALM programme.
Standard connectors and central product updates, without heavy customer-specific customisation.
Clear impact analysis and CRA traceability, without requiring users to be PLM, Software BOM or security specialists.
Register the product configuration and the software release, then import and validate its Software BOM.
The release-product relationship is the functional core: everything flows into it or out of it.
Components are matched against the CVE database automatically, then you get a full report with explanation and remediation guidance.
From 11 September 2026, an actively exploited vulnerability must be reported to ENISA within 24 hours. TRACE will pre-fill an Early Warning report from data it already has: CVE, component, SBOM, affected product and version.