KaaS Trace KaaS TRACE
Contact

Keep your tools. Connect your lifecycle.

CRA traceability without a PLM transformation.

KaaS TRACE links your software releases to Windchill product configurations, imports and validates Software BOMs, and shows exactly which products are affected by a component: the evidence trail the EU Cyber Resilience Act requires, built on top of the PLM, ALM, Git and CI/CD tools you already use.

Why KaaS TRACE

1

Rapid implementation

Operational in weeks, not a lengthy PLM/ALM programme.

2

Low-maintenance operation

Standard connectors and central product updates, without heavy customer-specific customisation.

3

Effortless everyday use

Clear impact analysis and CRA traceability, without requiring users to be PLM, Software BOM or security specialists.

How it works

STEP 1

Set up

Register the product configuration and the software release, then import and validate its Software BOM.

STEP 2

Link

The release-product relationship is the functional core: everything flows into it or out of it.

STEP 3

Assess & report

Components are matched against the CVE database automatically, then you get a full report with explanation and remediation guidance.

What's included

Core capabilities, available from the first release.
Multiple Windchill environments (PROD, DEV, TEST)
Product context via Windchill reference
Software BOM import & validation
Release-product relationship
Automatic CVE matching
Vulnerability reports with remediation guidance
Impact analysis
Reporting & evidence
Auditability
REST API for automated workflows
Automated build-pipeline integration
Automatic email notifications for CRA compliance

CRA Reporting: Prepare Early Warning

From 11 September 2026, an actively exploited vulnerability must be reported to ENISA within 24 hours. TRACE will pre-fill an Early Warning report from data it already has: CVE, component, SBOM, affected product and version.