Skip to main content

OCCTET toolkit

Get Started with OCCTET

OCCTET helps SMEs and open source teams understand their CRA readiness, analyse software dependencies and document security decisions. Start with one product or repository, review the results, and build a repeatable process.

On this page

1. Choose your starting point

You can use the self-assessment and practical guides independently, or combine ORT Server and OCCTET Curator to analyse and review your software.

The self-assessment supports preparation and prioritisation. It is not a certification or a formal conformity assessment.

2. Prepare your first project

Choose a repository that represents a product you maintain. For a first trial, a small project with a familiar build system makes the results easier to interpret.

Have the following information ready:

  • Your Git repository URL.
  • The branch, tag or commit you want to analyse.
  • The languages and package managers used by the project.
  • Any private dependencies or package registries.
  • A contact who understands the project’s build and dependencies.

Before analysing confidential code on a hosted service, discuss access and data-handling arrangements with the team. Use the service’s supported credential configuration rather than sending passwords or tokens by email.

3. Request access or run the tools yourself

Use the hosted OCCTET tools

The hosted ORT Server and Curator instances require an account. Contact the OCCTET team to request access and confirm the arrangements available for your project.

Include your organisation, the tools you want to try, your project’s technologies, and whether the repository is public or private. Please do not include credentials.

Deploy in your own environment

If you prefer to manage your own infrastructure, follow the installation instructions for ORT Server and OCCTET Curator. The complete installation procedure is coming soon in deliverable D4.1 – Ready-to-Use Installation.

For an integrated setup, make sure Curator can connect to ORT Server. The required configuration depends on the versions and deployment you use.

4. Run your first analysis

Once your access and repository configuration are ready:

  1. Add or select your repository in ORT Server, or use the connected Curator workflow available in your deployment.
  2. Select the revision you want to analyse.
  3. Configure access to any private repositories or registries.
  4. Start the analysis and check its status.
  5. Review any errors or unresolved dependencies before interpreting the findings.

Processing time and coverage depend on the repository, build system and configuration. A completed run can still contain analysis issues, so check whether the components relevant to your product were successfully resolved.

Your first milestone

An analysis of a known revision, with its dependency inventory and any analysis limitations recorded.

5. Review the results with Curator

Bring the analysis results into Curator using the integration configured for your deployment. Review components, licence information and vulnerability findings.

For each important finding:

  • Check the affected package and version.
  • Identify where and how the component is used.
  • Assess whether the finding applies to your product.
  • Record your decision and supporting evidence.
  • Assign the next action, such as updating a dependency or investigating further.

A vulnerability finding is a starting point for review. It does not automatically mean that the vulnerability is exploitable in your product.

Where supported, use VEX statements to document whether a known vulnerability affects the product and why. Review AI-assisted suggestions before accepting them.

Your second milestone

A prioritised list of actions and a record of the decisions made.

6. Export and keep your evidence

Use the exports available in your deployment to retain the software inventory and reviewed findings. ORT Server supports SBOM reporting; Curator provides curation and export capabilities.

Check which SBOM and VEX formats your installed version supports. Keep exported files alongside:

  • The product version and source revision.
  • The analysis date and configuration.
  • Known analysis limitations.
  • Review decisions and follow-up actions.

These records can support your technical documentation and discussions with customers or suppliers. They are part of a broader compliance process.

7. Make it repeatable

Repeat the analysis when dependencies change, before relevant releases, and at intervals appropriate to your product’s risk. New advisories can affect an unchanged codebase.

Assign responsibility for reviewing findings and keeping the evidence current. Use the dependency update policy and vulnerability handling templates to establish a simple routine.

Need help?

What you encounterWhat to check
You cannot sign inConfirm that your account and permissions have been provisioned.
A repository cannot be accessedCheck its URL and the configured repository credentials.
Dependencies cannot be resolvedCheck package-manager support, registry access and the analysis logs.
Results are missing in CuratorCheck the ORT Server connection, permissions and selected analysis.
An export is unavailableConfirm the formats and features supported by your version.

When contacting the team, include the tool, repository or project identifier, run identifier if available, and a sanitised error message.

Back to the top