Łukasiewicz – AI: Expertise in Cybersecurity and Artificial Intelligence
The Łukasiewicz Research Network – Institute of Artificial Intelligence and Cybersecurity (Łukasiewicz – AI) conducts projects with a real impact on digital security. We carry out research, develop tools, and support businesses in increasing their resilience to cyber threats. Our activities help make products and systems across Europe more secure and resistant to attacks.
The OSCRAT Project in Practice
Since 2024, Łukasiewicz – AI has been participating in the international OSCRAT project (Open-Source Cyber Resilience Act Tools), co-funded by the European Union under the Digital Europe Programme. The project aims to develop open, free tools to assist small and medium-sized enterprises (SMEs) in implementing the requirements of the Cyber Resilience Act (CRA) in practice.
The project focuses on increasing the real-world resilience of digital products throughout their entire lifecycle — from design and deployment to incident response.
Activities So Far
Throughout the project, the Łukasiewicz – AI team has presented the OSCRAT tool at numerous international conferences and meetings to gather feedback. A survey was also conducted among SMEs to collect opinions and needs, ensuring that the platform aligns with actual market challenges.
(See information about the OSCRAT survey)
What OSCRAT Offers
- CRA Self-Assessment – interactive checklists, role and product category assignments, and reports supporting EU compliance declarations.
- SBOM and Supply Chain Security – automatic and manual component lists with vulnerability analysis.
- Vulnerability and Incident Management – policy creation, reporting to ENISA and CSIRT teams, improving response capabilities.
- Centralized Documentation Repository – all reports, policies, certificates, and security patches in one location.
- SME Support – ready-to-use tools and guidelines for quickly implementing cyber resilience principles without building solutions from scratch.
OSCRAT in the European Context
The project is aligned with the CRA, which defines digital product security requirements throughout their lifecycle. OSCRAT fits into the EU’s broader strategy to strengthen digital security and enhance enterprise resilience against cyber threats.
Collaboration and Consultations
OSCRAT is implemented by an international consortium: PMF Research (Italy), Oves Enterprise and ENERSEC (Romania), EDIH Trakia (Bulgaria), Unicis.Tech OÜ (Estonia), and Łukasiewicz – AI (Poland).
Consultations and surveys of SMEs, experts, and business support centers ensure the tools are tailored to real market needs.
Role of Łukasiewicz – AI
As the leader of the WP2 Requirements Gathering and Analysis work package, Łukasiewicz – AI defines the scope and requirements for OSCRAT tools, develops interaction models, the graphical user interface, and cybersecurity specifications.
Summary
OSCRAT provides practical, open support for European SMEs in enhancing the cyber resilience of digital products and preparing for CRA requirements. The platform enables enterprises to efficiently implement digital security principles in their daily operations.