Master the obsolescence of your software portfolio

With ObsoWatch, continuously monitor every component of your software infrastructure. Anticipate end-of-support dates with alerts, and stay informed of CVEs affecting your components as soon as they are published.

Capture d'écran de l'application ObsoWatch

EU hosting

Data stored in Europe

EU data protection

Privacy by design

NIS2, CRA, ISO 27001 & DORA

Monitoring evidence included

// THE PROBLEM

Your IT estate contains ticking time bombs.You don't know which ones.

Every end-of-support component becomes an attack vector. Every unpatched CVE is an open door.

And the numbers show most IT teams discover this too late.

60%

of data breaches are linked to a known, documented vulnerability that was never fixed

Source: Automox Cybersecurity Report 2024

55 days

median time to patch a critical vulnerability - attackers often exploit it in under a month

Source: CISA KEV Catalog / Hadrian 2025

€10M

or up to 2% of global annual turnover in potential NIS2 fines for inadequate vulnerability management and asset mapping

Source: NIS2 Directive Article 21 - EU 2022/2555

// OUR FEATURES

Everything you need to never be caught off guard

Spot risk early enough to act on your own terms - before it turns into an emergency.

Real-time inventory

A complete, structured view of your IT estate, in real time

Organize monitoring by project and see each project’s risk level at a glance. Connect your GitHub, GitLab or Bitbucket repositories, import dependency files, or add components manually-from the OS to application libraries.

No more spreadsheets, missed items, or blind spots.

Illustration inventaire en temps reel
Detailed information

Full datasheet for every component

For each component, access full version history, available patches, licenses, technical references, and official vendor documentation. View all CVEs by version-past, active, and resolved.

No more digging across ten different sites.

Illustration fiche composant detaillee
Maximum responsiveness to threats

Smart email alerts

Configure your own alert rules: new CVE published, end of life in 6 or 30 days, end of life passed, new patch available, license change. Set severity, recipients, and email notifications.

Stop missing deadlines. Anticipate them.

Email alert illustration
NIS2 & CRA compliance

Compliance evidence for your audits

ObsoWatch automatically documents your vulnerability and software asset management-the supporting evidence required by NIS2 (Art. 21), CRA, ISO 27001 (A.8.8) and DORA auditors. Export your SBOM in SPDX and CycloneDX formats and share it securely via a one-click link.

Ready for your next audit-at all times.

SBOM compliance illustration

// YOUR ECOSYSTEM

We monitor your entire ecosystem

From servers to development tools, we cover your entire technical stack.

Languages & Frameworks

Programming languages, web frameworks, runtimes and essential libraries for application development.

Databases & Storage

Relational database management systems, NoSQL, in-memory caches and storage solutions.

Servers & Infrastructure

Web servers, proxies, containers, orchestrators and virtualization infrastructure.

Cloud & DevOps

Public cloud platforms, CI/CD tools, deployment automation and infrastructure management.

Security & Auth

Authentication protocols, encryption, SSL/TLS certificates and identity management solutions.

Monitoring & Tools

Monitoring tools, metrics, logs, IDE, version managers and development utilities.

// COMPLIANCE & REGULATION

Meet regulatory requirements

A platform designed to support you in your certification and regulatory compliance efforts.

// All sectors

NIS 2

EU directive on security of network and information systems for essential and important entities.

  • Up-to-date register of critical software assets
  • Vulnerability management and remediation plans
  • Visibility of suppliers and the supply chain
  • Metrics and reports for regulatory oversight

// International standard

ISO 27001

International standard to structure and govern your ISMS end to end.

  • Up-to-date software asset inventory and mapping
  • CVE monitoring and remediation prioritization
  • Traceability of actions and audit evidence
  • Identification of at-risk third-party and open-source components

// Publishers & manufacturers

Cyber Resilience Act

EU regulation on cybersecurity of digital products with obligations for manufacturers and vendors.

  • SPDX / CycloneDX SBOMs usable for audits
  • Per-component vulnerability tracking and follow-up
  • Lifecycle: EOL, patches, and communication
  • Documentation and evidence for authorities

// Finance

DORA

Framework for digital operational resilience in the financial sector (EU).

  • Mapping of critical dependencies and ICT risks
  • Automated resilience indicators and reporting
  • Audit logs and traceability for IT governance
  • Critical third-party component monitoring (Art. 28)

Your first scan in 15 minutes

Your components, their CVEs, and their end-of-support dates-visible at a glance.

30 jours gratuitsSans carte bancaireSans engagement