{"id":2069,"date":"2026-03-10T23:00:02","date_gmt":"2026-03-10T23:00:02","guid":{"rendered":"https:\/\/abstractionslab.com\/?p=2069"},"modified":"2026-03-23T19:20:04","modified_gmt":"2026-03-23T19:20:04","slug":"c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module","status":"publish","type":"post","link":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/","title":{"rendered":"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography"},"content":{"rendered":"\n<div class=\"wp-block-uagb-image aligncenter uagb-block-e8a9e679 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-grayscale wp-block-uagb-image--align-center\"><figure class=\"wp-block-uagb-image__figure\"><a class=\"\" href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2.png 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2.png 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png\" alt=\"\" class=\"uag-image-2207\" width=\"150\" height=\"150\" title=\"3D3B2C_LOG_C5DEC-CAD_v1.2\" loading=\"lazy\" role=\"img\"\/><\/a><figcaption class=\"uagb-image-caption\"><a href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">C5-DEC CAD<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<p>March 11, 2026 \u2014 Abstractions Lab announces the release of <a href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">C5-DEC CAD<\/a> v1.2. This release marks the most expansive functional milestone in the project&#8217;s history, delivering four new production-ready modules alongside significant enhancements to the SpecEngine, DocEngine, and Common Criteria tooling already present in the platform. For a visual stakeholder-oriented tour of C5-DEC CAD, visit the <strong><a href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">product presentation page<\/a><\/strong>. The release is now <a href=\"https:\/\/github.com\/AbstractionsLab\/c5dec\" target=\"_blank\" rel=\"noreferrer noopener\">available on GitHub<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-uagb-image aligncenter uagb-block-ada9db3f wp-block-uagb-image--layout-default wp-block-uagb-image--effect-grayscale wp-block-uagb-image--align-center\"><figure class=\"wp-block-uagb-image__figure\"><a class=\"\" href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CAD-product-website-scaled-1-1024x599.jpg ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CAD-product-website-scaled-1-scaled.jpg 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CAD-product-website-scaled-1-scaled.jpg 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CAD-product-website-scaled-1-1024x599.jpg\" alt=\"\" class=\"uag-image-2245\" width=\"727\" height=\"425\" title=\"Screenshot\" loading=\"lazy\" role=\"img\"\/><\/a><figcaption class=\"uagb-image-caption\">C5-DEC CAD product presentation website<\/figcaption><\/figure><\/div>\n\n\n\n<p>C5-DEC CAD is the open-source, AI-enabled toolkit for computer-aided secure system design, development, and evaluation that underpins the <a href=\"https:\/\/abstractionslab.com\/index.php\/research-and-development\/cyfort\/\">CyFORT<\/a> project, carried out in the context of IPCEI-CIS. Where v1.0 established the stable core \u2014 Common Criteria Toolbox, SSDLC scaffolding, CPSSA, Transformer, and containerized dev environments \u2014 and v1.1 refined workspace management and AI-assisted design workflows, v1.2 substantially broadens the platform&#8217;s surface area. The release brings native CRA compliance automation, full SBOM lifecycle management, a self-contained cryptography module, an expanded CPSSA subsystem with threat modelling and quantitative risk analysis, and a richer SpecEngine and DocEngine layer. Together, these additions position C5-DEC CAD as an end-to-end secure engineering workbench that spans regulatory compliance, software supply chain security, threat modelling, structured specification management, and technical publishing \u2014 all from a single, traceability-first toolchain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key Highlights Of V1.2<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">CRA Compliance Automation For EU Regulation 2024\/2847<\/h3>\n\n\n\n<p>The most strategically significant addition in v1.2 is a fully integrated CRA compliance module (<code>c5dec\/core\/cra.py<\/code>), directly targeting EU Regulation 2024\/2847 (Cyber Resilience Act). The module covers Tier 1 of the CRA obligations with a YAML-backed requirements database of 35+ Annex I essential requirements, a Doorstop-integrated checklist engine with pass\/fail\/na verdict tracking and spreadsheet export annotated with per-category compliance percentages, a CRA Technical Documentation generator for all seven Annex VII chapters, and an EU Declaration of Conformity (DoC) generator for Annex V.<\/p>\n\n\n\n<p>All three artefact types are accessible through the <code>c5dec cra<\/code> CLI command (<code>create<\/code>, <code>verify<\/code>, <code>export<\/code>), and the CRA Technical Documentation template is also reachable via the DocEngine pipeline (<code>c5dec docengine cra-tech-doc<\/code>). Feature flags and dedicated constants in <code>c5settings.py<\/code> ensure that CRA-specific configuration is kept clean and audit-ready. <\/p>\n\n\n\n<p>Support for Default, Class I, Class II, and Critical CRA product risk classes is included, making the module applicable across the full range of products with digital elements subject to the regulation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SBOM Lifecycle Management With Syft Integration<\/h3>\n\n\n\n<p>Complementing CRA compliance, v1.2 introduces a dedicated SBOM lifecycle management module exposed via the <code>c5dec sbom<\/code> CLI command (<code>generate<\/code>, <code>import<\/code>, <code>diff<\/code>, <code>validate<\/code>). Generation relies on <a href=\"https:\/\/github.com\/anchore\/syft\">Syft<\/a> and supports both CycloneDX and SPDX output formats. Beyond generation, the module provides structured SBOM parsing and validation, version-to-version diff analysis for change visibility, and Doorstop traceability linking SBOM entries to specification items.<\/p>\n\n\n\n<p>A key integration point is <code>auto_verify_sbom_requirement()<\/code>, which automatically cross-verifies the CRA essential requirement <code>cra_ii_1_1<\/code> against the generated SBOM, tightening the loop between supply chain documentation and regulatory compliance. <\/p>\n\n\n\n<p>This addition reflects the project&#8217;s broader philosophy that security artefacts should not exist in isolation: SBOM data, CRA verdicts, and Doorstop specification items are mutually linked, providing continuous, machine-verifiable traceability from product components to regulatory obligations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A Native Python Cryptography Module<\/h3>\n\n\n\n<p>V1.2 introduces a self-contained cryptography module implementing a range of classical and modern operations directly in Python \u2014 without requiring external toolchain dependencies for the core operations. The module covers SHA-256 file integrity checking, GnuPG-based file signing and encryption, Shamir&#8217;s Secret Sharing over GF(2^127\u22121), and NaCl Ed25519 digital signatures.<\/p>\n\n\n\n<p>All functionality is accessible through the <code>c5dec crypto<\/code> CLI command, which provides 11 subcommands: <code>hash<\/code>, <code>verify-hash<\/code>, <code>sign<\/code>, <code>verify-sig<\/code>, <code>encrypt<\/code>, <code>decrypt<\/code>, <code>shamir-split<\/code>, <code>shamir-recover<\/code>, <code>nacl-keygen<\/code>, <code>nacl-sign<\/code>, and <code>nacl-verify<\/code>. Prior to v1.2, the <code>c5dec crypto<\/code> command existed as a stub; it is now a fully dispatching implementation. Post-quantum cryptography capabilities remain accessible through the dedicated OQS-OpenSSL dev container, which continues to be supported alongside the new native module.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">An Expanded CPSSA Subsystem With Threat Modelling &amp; FAIR Risk Analysis<\/h3>\n\n\n\n<p>The Cyber-Physical System Security Assessment (CPSSA) module, introduced in v1.0, has been substantially expanded in v1.2. It is now structured as a proper multi-subsystem package, reflecting the increased breadth of its capabilities. The <code>create_threat_model()<\/code> function generates Threagile-compatible and OWASP pytm YAML threat models from Doorstop ARC artefacts through auto-discovery of architecture folders. A Threagile field-mapping subsystem (<code>threagile-mappings.yml<\/code>, <code>threagile-schema.json<\/code>) bridges the gap between C5-DEC&#8217;s specification model and Threagile&#8217;s input schema. Sidecar YAML files (<code>threat-actors.yml<\/code>, <code>assumptions.yml<\/code>) allow analysts to enrich threat models without modifying source Doorstop items.<\/p>\n\n\n\n<p>Quantitative risk analysis has been added via <code>generate_fair_input_template()<\/code> and <code>run_quantitative_risk_analysis()<\/code>, with support for <code>--fair-params<\/code> YAML overrides and PERT distribution modelling for uncertainty-aware loss estimates. The <code>c5dec cpssa<\/code> CLI has been extended with <code>fair-input<\/code> and <code>risk-analysis<\/code> subcommands. A fully worked water-treatment system example provides a practical reference for applying the complete CPSSA workflow end-to-end.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SpecEngine And DocEngine Expansions<\/h3>\n\n\n\n<p>The SpecEngine toolkit gains four new tools in v1.2 and two significant upgrades to existing ones. <code>c5graph.py<\/code> produces an interactive, self-contained <code>specs-graph.html<\/code> traceability graph powered by Cytoscape.js with dagre layout, expand\/collapse controls, and color-coded coverage indicators. <\/p>\n\n\n\n<div class=\"wp-block-uagb-image aligncenter uagb-block-a8389398 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-static wp-block-uagb-image--align-center\"><figure class=\"wp-block-uagb-image__figure\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-specs-graph-1024x473.png ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-specs-graph.png 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-specs-graph.png 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-specs-graph-1024x473.png\" alt=\"\" class=\"uag-image-2100\" width=\"730\" height=\"337\" title=\"c5dec-cad-specs-graph\" loading=\"lazy\" role=\"img\"\/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><code>c5mermaid.py<\/code> is a Mermaid-to-SVG\/PNG pre-processor that renders fenced Mermaid blocks in Doorstop item files via <code>mmdc<\/code>, stores outputs in per-item <code>assets\/<\/code> directories, and replaces blocks with HTML comments preserving the original source; the transformation is idempotent and supports <code>render<\/code>, <code>undo<\/code>, and <code>--dry-run<\/code> modes. <code>prune_bad_links.py<\/code> removes malformed Doorstop links, and <code>doorstop_yml_to_md.py<\/code> migrates items from pure YAML to Markdown with YAML frontmatter; all four integrate with <code>publish.sh<\/code>. On the existing-tool side, <code>c5browser.py<\/code> \u2014 the standalone Bootstrap + DataTables HTML items browser \u2014 adds per-column filter inputs, dual <code>.md<\/code>\/<code>.yml<\/code> format support, runtime document-type auto-discovery, and correct numeric column sorting.<\/p>\n\n\n\n<div class=\"wp-block-uagb-image uagb-block-482b37a6 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-static wp-block-uagb-image--align-none\"><figure class=\"wp-block-uagb-image__figure\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-spec-browser-1024x297.png ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-spec-browser.png 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-spec-browser.png 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-spec-browser-1024x297.png\" alt=\"\" class=\"uag-image-2099\" width=\"1024\" height=\"297\" title=\"c5dec-cad-spec-browser\" loading=\"lazy\" role=\"img\"\/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><code>c5traceability.py<\/code> has been generalized into a YAML-configurable, project-agnostic traceability analyzer with <code>--config<\/code>, <code>--discover<\/code>, and <code>--discover-write<\/code> flags and section-titled HTML navigation. Both continue to produce self-contained, offline-ready HTML output.<\/p>\n\n\n\n<div class=\"wp-block-uagb-image aligncenter uagb-block-661dd4b3 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-static wp-block-uagb-image--align-center\"><figure class=\"wp-block-uagb-image__figure\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-traceability-stats-1024x481.png ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-traceability-stats.png 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-traceability-stats.png 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/c5dec-cad-traceability-stats-1024x481.png\" alt=\"\" class=\"uag-image-2102\" width=\"681\" height=\"320\" title=\"c5dec-cad-traceability-stats\" loading=\"lazy\" role=\"img\"\/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>On the DocEngine side, v1.2 adds the <code>c5dec docengine report|presentation -n &lt;name&gt;<\/code> CLI command, which scaffolds ready-to-use document projects from report or presentation templates with variable substitution, overwrite protection, and Quarto dependency checking. The Quarto presentation template (<code>c5dec\/assets\/presentation\/<\/code>) supports both Reveal.js and PowerPoint output with ALab branding and modular slide organization. A new <code>c5dec_config_v2.yml<\/code> configuration format with a matching <code>custom_vars_v2.py<\/code> pre-render script brings automatic LaTeX conversion, support for string\/list\/dict changelog entry formats, and LaTeX escaping for special characters. A dedicated <code>docEngine.Dockerfile<\/code> separates DocEngine dependencies (Quarto, TeX Live, Kryptor, Cryptomator CLI) from the lightweight C5-DEC dev container, which now lives in <code>.devcontainer\/c5dec-dev\/<\/code>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Common Criteria Knowledge Base Completion And Quality Improvements<\/h3>\n\n\n\n<p>The CC concept wiki, introduced in earlier releases, has been completed with new articles and revisions to achieve full coverage of CC:2022. The knowledge base now spans 50+ structured articles across CC Concepts, Core Constructs, Certification Schemes (EUCC), and a Terms &amp; Definitions register, making it directly usable as an LLM context source for AI-assisted CC evaluation workflows.<\/p>\n\n\n\n<div class=\"wp-block-uagb-image aligncenter uagb-block-5b1ea181 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-static wp-block-uagb-image--align-center\"><figure class=\"wp-block-uagb-image__figure\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CC-wiki-1024x799.png ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CC-wiki.png 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CC-wiki.png 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/C5DEC-CC-wiki-1024x799.png\" alt=\"\" class=\"uag-image-2104\" width=\"569\" height=\"444\" title=\"C5DEC-CC-wiki\" loading=\"lazy\" role=\"img\"\/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>Unit test coverage has been significantly extended: new test files for CLI, ISMS, SSDLC, Transformer, CPSSA, and cryptography, bring total coverage to a level commensurate with a maturing engineering platform. Docker security hardening \u2014 non-root users, dropped Linux capabilities, <code>--no-install-recommends<\/code>, and package pinning \u2014 has been applied uniformly across <code>Dockerfile<\/code>, <code>dev.Dockerfile<\/code>, and <code>docEngine.Dockerfile<\/code>, and a <code>.dockerignore<\/code> file limits the build context. All Doorstop item files across <code>arc<\/code>, <code>mrs<\/code>, <code>srs<\/code>, <code>swd<\/code>, <code>tcs<\/code>, and <code>trp<\/code> documents have been migrated from pure YAML to Markdown with YAML frontmatter, and all document configs updated to <code>itemformat: markdown<\/code>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Availability<\/h2>\n\n\n\n<p>C5-DEC CAD v1.2 product presentation page:<\/p>\n\n\n\n<p><a href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html<\/a><\/p>\n\n\n\n<p>C5-DEC CAD v1.2 is available now as a free and open-source release on GitHub, including updated documentation, user manuals, a complete technical specification tree with traceability coverage:<\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/AbstractionsLab\/c5dec\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/AbstractionsLab\/c5dec<\/a><\/p>\n\n\n\n<p>A live specification browser at: <a href=\"https:\/\/abstractionslab.github.io\/c5dec\/traceability\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/abstractionslab.github.io\/c5dec\/traceability\/index.html<\/a><\/p>\n\n\n\n<p>Community feedback and contributions are welcome.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>March 11, 2026 \u2014 Abstractions Lab announces the release of C5-DEC CAD v1.2. This release marks the most expansive functional [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[7,6],"tags":[9],"class_list":["post-2069","post","type-post","status-publish","format-standard","hentry","category-c5dec","category-cyfort","tag-software-release-2"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography - Abstractions Lab<\/title>\n<meta name=\"description\" content=\"Latest release of C5-DEC on GitHub: SSDLC, EU CRA, SBOM, threat modelling and risk assessment, cryptography, DocEngine, SpecEngine\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography - Abstractions Lab\" \/>\n<meta property=\"og:description\" content=\"Latest release of C5-DEC on GitHub: SSDLC, EU CRA, SBOM, threat modelling and risk assessment, cryptography, DocEngine, SpecEngine\" \/>\n<meta property=\"og:url\" content=\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/\" \/>\n<meta property=\"og:site_name\" content=\"Abstractions Lab\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-10T23:00:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-23T19:20:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png\" \/>\n<meta name=\"author\" content=\"Arash\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Arash\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/\"},\"author\":{\"name\":\"Arash\",\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac\"},\"headline\":\"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography\",\"datePublished\":\"2026-03-10T23:00:02+00:00\",\"dateModified\":\"2026-03-23T19:20:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/\"},\"wordCount\":1193,\"publisher\":{\"@id\":\"https:\/\/abstractionslab.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png\",\"keywords\":[\"software-release\"],\"articleSection\":[\"C5-DEC\",\"CyFORT\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/\",\"url\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/\",\"name\":\"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography - Abstractions Lab\",\"isPartOf\":{\"@id\":\"https:\/\/abstractionslab.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png\",\"datePublished\":\"2026-03-10T23:00:02+00:00\",\"dateModified\":\"2026-03-23T19:20:04+00:00\",\"description\":\"Latest release of C5-DEC on GitHub: SSDLC, EU CRA, SBOM, threat modelling and risk assessment, cryptography, DocEngine, SpecEngine\",\"breadcrumb\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage\",\"url\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2.png\",\"contentUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2.png\",\"width\":532,\"height\":508},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/abstractionslab.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/abstractionslab.com\/#website\",\"url\":\"https:\/\/abstractionslab.com\/\",\"name\":\"Abstractions Lab\",\"description\":\"Verifiably secure digital solutions built upon solid mathematical foundations\",\"publisher\":{\"@id\":\"https:\/\/abstractionslab.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/abstractionslab.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/abstractionslab.com\/#organization\",\"name\":\"itrust Abstractions Lab\",\"url\":\"https:\/\/abstractionslab.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png\",\"contentUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png\",\"width\":1200,\"height\":600,\"caption\":\"itrust Abstractions Lab\"},\"image\":{\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/github.com\/AbstractionsLab\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac\",\"name\":\"Arash\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g\",\"caption\":\"Arash\"},\"url\":\"https:\/\/abstractionslab.com\/index.php\/author\/arash\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography - Abstractions Lab","description":"Latest release of C5-DEC on GitHub: SSDLC, EU CRA, SBOM, threat modelling and risk assessment, cryptography, DocEngine, SpecEngine","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/","og_locale":"en_GB","og_type":"article","og_title":"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography - Abstractions Lab","og_description":"Latest release of C5-DEC on GitHub: SSDLC, EU CRA, SBOM, threat modelling and risk assessment, cryptography, DocEngine, SpecEngine","og_url":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/","og_site_name":"Abstractions Lab","article_published_time":"2026-03-10T23:00:02+00:00","article_modified_time":"2026-03-23T19:20:04+00:00","og_image":[{"url":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png","type":"","width":"","height":""}],"author":"Arash","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Arash","Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#article","isPartOf":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/"},"author":{"name":"Arash","@id":"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac"},"headline":"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography","datePublished":"2026-03-10T23:00:02+00:00","dateModified":"2026-03-23T19:20:04+00:00","mainEntityOfPage":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/"},"wordCount":1193,"publisher":{"@id":"https:\/\/abstractionslab.com\/#organization"},"image":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage"},"thumbnailUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png","keywords":["software-release"],"articleSection":["C5-DEC","CyFORT"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/","url":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/","name":"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography - Abstractions Lab","isPartOf":{"@id":"https:\/\/abstractionslab.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage"},"image":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage"},"thumbnailUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2-150x150.png","datePublished":"2026-03-10T23:00:02+00:00","dateModified":"2026-03-23T19:20:04+00:00","description":"Latest release of C5-DEC on GitHub: SSDLC, EU CRA, SBOM, threat modelling and risk assessment, cryptography, DocEngine, SpecEngine","breadcrumb":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#primaryimage","url":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2.png","contentUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/3D3B2C_LOG_C5DEC-CAD_v1.2.png","width":532,"height":508},{"@type":"BreadcrumbList","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/10\/c5-dec-v1-2-cra-compliance-sbom-lifecycle-management-and-a-full-cryptography-module\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/abstractionslab.com\/"},{"@type":"ListItem","position":2,"name":"C5-DEC (v1.2): AI-enabled SSDLC, CRA, SBOM, Threat Modelling, Risk Analysis, SpecEngine, DocEngine, Cryptography"}]},{"@type":"WebSite","@id":"https:\/\/abstractionslab.com\/#website","url":"https:\/\/abstractionslab.com\/","name":"Abstractions Lab","description":"Verifiably secure digital solutions built upon solid mathematical foundations","publisher":{"@id":"https:\/\/abstractionslab.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/abstractionslab.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/abstractionslab.com\/#organization","name":"itrust Abstractions Lab","url":"https:\/\/abstractionslab.com\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/","url":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png","contentUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png","width":1200,"height":600,"caption":"itrust Abstractions Lab"},"image":{"@id":"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/github.com\/AbstractionsLab"]},{"@type":"Person","@id":"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac","name":"Arash","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g","caption":"Arash"},"url":"https:\/\/abstractionslab.com\/index.php\/author\/arash\/"}]}},"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"Arash","author_link":"https:\/\/abstractionslab.com\/index.php\/author\/arash\/"},"uagb_comment_info":0,"uagb_excerpt":"March 11, 2026 \u2014 Abstractions Lab announces the release of C5-DEC CAD v1.2. This release marks the most expansive functional [&hellip;]","_links":{"self":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts\/2069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/comments?post=2069"}],"version-history":[{"count":23,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts\/2069\/revisions"}],"predecessor-version":[{"id":2248,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts\/2069\/revisions\/2248"}],"wp:attachment":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/media?parent=2069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/categories?post=2069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/tags?post=2069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}