of data breaches are linked to a known, documented vulnerability that was never fixed
Source: Automox Cybersecurity Report 2024
With ObsoWatch, continuously monitor every component of your software infrastructure. Anticipate end-of-support dates with alerts, and stay informed of CVEs affecting your components as soon as they are published.

EU hosting
Data stored in Europe
EU data protection
Privacy by design
NIS2, CRA, ISO 27001 & DORA
Monitoring evidence included
// THE PROBLEM
Every end-of-support component becomes an attack vector. Every unpatched CVE is an open door.
And the numbers show most IT teams discover this too late.
of data breaches are linked to a known, documented vulnerability that was never fixed
Source: Automox Cybersecurity Report 2024
median time to patch a critical vulnerability - attackers often exploit it in under a month
Source: CISA KEV Catalog / Hadrian 2025
or up to 2% of global annual turnover in potential NIS2 fines for inadequate vulnerability management and asset mapping
Source: NIS2 Directive Article 21 - EU 2022/2555
// OUR FEATURES
Spot risk early enough to act on your own terms - before it turns into an emergency.
Organize monitoring by project and see each project’s risk level at a glance. Connect your GitHub, GitLab or Bitbucket repositories, import dependency files, or add components manually-from the OS to application libraries.
No more spreadsheets, missed items, or blind spots.

For each component, access full version history, available patches, licenses, technical references, and official vendor documentation. View all CVEs by version-past, active, and resolved.
No more digging across ten different sites.

Configure your own alert rules: new CVE published, end of life in 6 or 30 days, end of life passed, new patch available, license change. Set severity, recipients, and email notifications.
Stop missing deadlines. Anticipate them.

ObsoWatch automatically documents your vulnerability and software asset management-the supporting evidence required by NIS2 (Art. 21), CRA, ISO 27001 (A.8.8) and DORA auditors. Export your SBOM in SPDX and CycloneDX formats and share it securely via a one-click link.
Ready for your next audit-at all times.

// YOUR ECOSYSTEM
From servers to development tools, we cover your entire technical stack.
Programming languages, web frameworks, runtimes and essential libraries for application development.
Relational database management systems, NoSQL, in-memory caches and storage solutions.
Web servers, proxies, containers, orchestrators and virtualization infrastructure.
Public cloud platforms, CI/CD tools, deployment automation and infrastructure management.
Authentication protocols, encryption, SSL/TLS certificates and identity management solutions.
Monitoring tools, metrics, logs, IDE, version managers and development utilities.
// COMPLIANCE & REGULATION
A platform designed to support you in your certification and regulatory compliance efforts.
// All sectors
EU directive on security of network and information systems for essential and important entities.
// International standard
International standard to structure and govern your ISMS end to end.
// Publishers & manufacturers
EU regulation on cybersecurity of digital products with obligations for manufacturers and vendors.
// Finance
Framework for digital operational resilience in the financial sector (EU).
Your components, their CVEs, and their end-of-support dates-visible at a glance.
30 jours gratuitsSans carte bancaireSans engagement