Featured Governance & Compliance
Cyber Resilience Act: what changes for software companies?
A practical review of the Cyber Resilience Act milestones in 2026 and 2027 and the technical evidence software manufacturers need to organize.
Xmart Blog
Technical insights on AppSec, DevSecOps, and software supply chain security for teams turning risk, architecture, and evidence into action.
Featured Governance & Compliance
A practical review of the Cyber Resilience Act milestones in 2026 and 2027 and the technical evidence software manufacturers need to organize.
Xmart Library
Versioned, referenced technical content connected to architecture decisions.
Software Supply Chain
AI agents can now access code, terminals, tools, and services. See why MCP, skills, and permissions expand the surface that AppSec needs to govern.
Malware
Recent attacks show that historical reputation does not guarantee a safe version. See how compromised legitimate packages move through the Software Supply Chain.
Software Supply Chain
Receiving an SBOM is just the beginning. Learn how to validate identity, composition, vulnerabilities, VEX, EOL, policies, and continuous monitoring.
DevSecOps
A repository stops being mere storage when it controls the availability, integrity, and promotion of components used by CI/CD.
Governance & Compliance
A practical review of the Cyber Resilience Act milestones in 2026 and 2027 and the technical evidence software manufacturers need to organize.
Software Supply Chain
A03:2025 expanded the focus from vulnerable components to dependencies, builds, repositories, distribution, and software supply chain governance.
Malware
CVEs, vulnerability intelligence, and malicious package detection solve different problems and must operate as complementary controls.
From insight to environment
Xmart supports the assessment, implementation, and operation of AppSec and DevSecOps controls.