EN
Back to the archive

The archive · Developer & Business Tools · Strategic decision · 2021–2026

Endor Labs bets EU Cyber Resilience Act makes dependency security a must-buy

Endor Labs bets supply-chain attacks plus the EU Cyber Resilience Act make dependency security a must-buy; $163M raised, 30x ARR growth by 2025.

Endor Labs

The betThat supply-chain attacks would push regulators to mandate SBOMs and vulnerability management, turning dependency security into a compliance purchase.Scaling

What the business is

Endor Labs is an AI-native application security platform that maps open-source dependencies, surfaces reachable and exploitable vulnerabilities, generates SBOMs, and scans AI-generated code for flaws via plugins for Cursor and GitHub Copilot.

Starting capital$163M total raised through the April 2025 Series B (TechCrunch).

How it started

Founded in 2021 by Varun Badhwar (RedLock, acquired by Palo Alto Networks) and Dimitri Stiliadis (Aporeto), who watched developers at Palo Alto struggle to know which open-source components were safe to update. The SolarWinds (2020) and Log4j (2021) breaches, plus the resulting policy push — US Executive Order 14028, the Securing Open Source Software Act, and later the EU Cyber Resilience Act — convinced them supply-chain security was becoming regulated, not optional.

What happened

Endor emerged from stealth in October 2022 with $25M from Lightspeed, Dell Technologies Capital and others, and closed a $70M Series A (Lightspeed, Coatue) in August 2023. It then expanded from dependency security into AI-generated-code security with plugins for Cursor and GitHub Copilot. In April 2025 it closed a $93M Series B led by DFJ Growth with Salesforce Ventures, reporting 30x ARR growth, 5M+ applications protected and 1M+ weekly scans. The EU CRA entered into force on December 10, 2024, with reporting obligations from September 11, 2026 and main obligations from December 2027.

How it ended up

Still scaling. The CRA obligations Endor markets against began taking effect in September 2026 (vulnerability reporting), with main product obligations in December 2027 — the regulatory bet is entering its payoff window as of September 2026.

Background

Endor Labs, founded in 2021 by security veterans Varun Badhwar and Dimitri Stiliadis, sells an AI-native application security platform for the software supply chain: it maps an organization's open-source dependencies, shows which vulnerable packages are actually reachable and exploitable, generates software bills of materials, and scans AI-generated code through plugins for Cursor and GitHub Copilot.

The founding bet was that supply-chain attacks — SolarWinds in 2020, Log4j in 2021 — would turn into regulation, making dependency security a compliance purchase rather than an engineering nicety. The company emerged from stealth in October 2022 with $25M, closed a $70M Series A in August 2023, and expanded into AI-code security as that market emerged. By April 2025 it reported 30x ARR growth since 2023, 5M+ applications protected, 1M+ weekly scans, and customers including OpenAI, Rubrik, Peloton, Snowflake, Egnyte and Dropbox.

The regulatory tailwind arrived on schedule: the EU Cyber Resilience Act entered into force December 10, 2024, making manufacturers responsible for vulnerability management and mandatory SBOMs across the product lifecycle, with reporting obligations applying from September 11, 2026 and main obligations from December 2027. Endor explicitly markets its platform as the path to CRA readiness, pointing to 24-hour disclosure windows for actively exploited vulnerabilities and penalties in the millions.

As of September 2026, Endor Labs is still scaling with roughly $163M raised; the CRA reporting regime it was built for is just beginning, so the payoff window for its regulatory bet is opening rather than closed.

What has to be true

  • The bet was timed to a visible policy trend: after SolarWinds and Log4j, both Washington and Brussels moved from advisories to mandates like EO 14028 and the CRA.
  • The product addressed the compliance evidence problem directly — reachability analysis and SBOMs are exactly what CRA audits ask for.
  • The expansion into AI-generated-code security caught a second wave: the CRA liability model applies to third-party components, and AI code multiplied those components.
  • The funding sequence (25M, 70M, 93M) with 30x ARR growth showed investors were paying for the regulatory thesis, not just the tech.

What can be applied

Regulation turns an incident-driven category into a purchase order, but only if you sell the evidence — SBOMs, reachability, documentation — the compliance officer needs, not just a better scanner.

Aftermath

As of September 2, 2026, Endor Labs is still scaling: $163M raised through the April 2025 Series B, 5M+ applications protected and 1M+ weekly scans, with product expansion into AI-generated-code security (Cursor and GitHub Copilot plugins). The EU CRA's vulnerability reporting obligations took effect September 11, 2026, and its main product obligations apply from December 11, 2027 — the compliance window Endor's CRA material targets, including mandatory SBOMs and 24-hour disclosure of actively exploited vulnerabilities. No further funding or acquisition is reflected in the sources reviewed.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases