---
title: "FOSSA and Nohau Partner to Bring Software Supply Chain Security and Compliance to the Nordics"
description: "FOSSA has teamed up with leading Nordic solutions provider Nohau to provide tools for managing security, license compliance, and regulatory compliance to their customers."
canonical_url: "https://fossa.com/blog/fossa-nohau-partner-software-security-compliance-nordics/"
markdown_url: "https://fossa.com/blog/fossa-nohau-partner-software-security-compliance-nordics.md"
content_type: "blog"
language: "en"
date_published: "2026-09-10"
date_modified: "2026-09-10"
author: "Andy Drukarev"
organization: "FOSSA"
---

# FOSSA and Nohau Partner to Bring Software Supply Chain Security and Compliance to the Nordics

> FOSSA has teamed up with leading Nordic solutions provider Nohau to provide tools for managing security, license compliance, and regulatory compliance to their customers.

We're excited to share that FOSSA has partnered with [Nohau Solutions](https://www.nohau.se/), one of the Nordic’s leading providers of tools and consulting for secure, compliant product development. Together, we're making it easier for organizations in the Nordics and beyond to manage software compliance, security, and transparency initiatives.

## Why FOSSA and Nohau Are Joining Forces

Modern applications are built on a large volume of open source and third-party software components. This has clear benefits for organizations of all types, but it also means that manual and even partially automated approaches to managing software security and compliance activities are often insufficient.

With regulations like the EU Cyber Resilience Act (CRA) turning software transparency and vulnerability management into legal requirements, organizations that distribute products with digital elements need reliable efficient ways to ensure SBOMs are being generated, license compliance obligations are being met, and vulnerabilities are being managed.

Through this partnership, Nohau’s customers will have the opportunity to add FOSSA’s solutions to their software security and compliance programs. This includes tools for:

* **[SBOM](https://fossa.com/learn/sboms.md) management**: Building and maintaining an accurate software bill of materials, an essential part of managing regulations like the CRA
* **Open source license compliance**: Staying on top of license obligations
* **Vulnerability management**: Continuously detecting and reporting on risk

## Built for the CRA

One of the topics that comes up repeatedly in our conversations with organizations that do business in the EU is the CRA. The FOSSA platform is built to enable teams to meet both the September 2026 vulnerability disclosure and December 2027 security/software transparency requirements. The FOSSA-Nohau partnership comes at the right time to help our customers manage these obligations.

> "The combination of CRA requirements taking effect and heightened global awareness of software supply chain security and compliance initiatives has led FOSSA to significantly expand our European presence," said Aaron Williams, CEO at FOSSA. "We're thrilled to partner with the Nohau team to help their customers simplify and improve essential programs for understanding and reducing risk across the software supply chain."

As Andreas Dyrhed, CEO at Nohau, put it:

> "We at Nohau are really thrilled to offer FOSSA's solution to our clients in the Nordics. The first and most intuitive value of FOSSA is to help a whole new set of companies being compliant with the regulations that are now affecting them regarding SBOMs. The other is the value of managing risk exposure when it comes to security—and for any organization to know what dependencies they have in their solutions."

You can [reach out to our team](http://fossa.com/request-demo/) for more information on this partnership. You can also visit [Nohau’s website](https://nohau.eu/) to learn more.

## Related resources

- [CRA Product Classification Explained: Default, Important, and Critical](https://fossa.com/blog/cra-product-classification.md): How the EU Cyber Resilience Act classifies products with digital elements (Default, Important Class I and II, and Critical), with the full Annex III and Annex IV product lists and what each tier means for self-assessment, third-party conformity assessment, and CE marking.
- [Highlights from ENISA's SBOM Implementation Guide](https://fossa.com/blog/highlights-enisa-sbom-implementation-guide.md): See highlights from ENISA's SBOM implementation guide, including the planning, execution, and monitoring phases of an SBOM program.

## Source

Canonical page: https://fossa.com/blog/fossa-nohau-partner-software-security-compliance-nordics/
