The archive · Developer & Business Tools · Strategic decision · 2021–2026
Endor Labs bets EU Cyber Resilience Act makes dependency security a must-buy
Endor Labs bets supply-chain attacks plus the EU Cyber Resilience Act make dependency security a must-buy; $163M raised, 30x ARR growth by 2025.
Endor Labs
What the business is
Endor Labs is an AI-native application security platform that maps open-source dependencies, surfaces reachable and exploitable vulnerabilities, generates SBOMs, and scans AI-generated code for flaws via plugins for Cursor and GitHub Copilot.
Starting capital:$163M total raised through the April 2025 Series B (TechCrunch).
How it started
Founded in 2021 by Varun Badhwar (RedLock, acquired by Palo Alto Networks) and Dimitri Stiliadis (Aporeto), who watched developers at Palo Alto struggle to know which open-source components were safe to update. The SolarWinds (2020) and Log4j (2021) breaches, plus the resulting policy push — US Executive Order 14028, the Securing Open Source Software Act, and later the EU Cyber Resilience Act — convinced them supply-chain security was becoming regulated, not optional.
What happened
Endor emerged from stealth in October 2022 with $25M from Lightspeed, Dell Technologies Capital and others, and closed a $70M Series A (Lightspeed, Coatue) in August 2023. It then expanded from dependency security into AI-generated-code security with plugins for Cursor and GitHub Copilot. In April 2025 it closed a $93M Series B led by DFJ Growth with Salesforce Ventures, reporting 30x ARR growth, 5M+ applications protected and 1M+ weekly scans. The EU CRA entered into force on December 10, 2024, with reporting obligations from September 11, 2026 and main obligations from December 2027.
How it ended up
Still scaling. The CRA obligations Endor markets against began taking effect in September 2026 (vulnerability reporting), with main product obligations in December 2027 — the regulatory bet is entering its payoff window as of September 2026.
Background
Endor Labs, founded in 2021 by security veterans Varun Badhwar and Dimitri Stiliadis, sells an AI-native application security platform for the software supply chain: it maps an organization's open-source dependencies, shows which vulnerable packages are actually reachable and exploitable, generates software bills of materials, and scans AI-generated code through plugins for Cursor and GitHub Copilot.
The founding bet was that supply-chain attacks — SolarWinds in 2020, Log4j in 2021 — would turn into regulation, making dependency security a compliance purchase rather than an engineering nicety. The company emerged from stealth in October 2022 with $25M, closed a $70M Series A in August 2023, and expanded into AI-code security as that market emerged. By April 2025 it reported 30x ARR growth since 2023, 5M+ applications protected, 1M+ weekly scans, and customers including OpenAI, Rubrik, Peloton, Snowflake, Egnyte and Dropbox.
The regulatory tailwind arrived on schedule: the EU Cyber Resilience Act entered into force December 10, 2024, making manufacturers responsible for vulnerability management and mandatory SBOMs across the product lifecycle, with reporting obligations applying from September 11, 2026 and main obligations from December 2027. Endor explicitly markets its platform as the path to CRA readiness, pointing to 24-hour disclosure windows for actively exploited vulnerabilities and penalties in the millions.
As of September 2026, Endor Labs is still scaling with roughly $163M raised; the CRA reporting regime it was built for is just beginning, so the payoff window for its regulatory bet is opening rather than closed.
What has to be true
- The bet was timed to a visible policy trend: after SolarWinds and Log4j, both Washington and Brussels moved from advisories to mandates like EO 14028 and the CRA.
- The product addressed the compliance evidence problem directly — reachability analysis and SBOMs are exactly what CRA audits ask for.
- The expansion into AI-generated-code security caught a second wave: the CRA liability model applies to third-party components, and AI code multiplied those components.
- The funding sequence (25M, 70M, 93M) with 30x ARR growth showed investors were paying for the regulatory thesis, not just the tech.
What can be applied
Regulation turns an incident-driven category into a purchase order, but only if you sell the evidence — SBOMs, reachability, documentation — the compliance officer needs, not just a better scanner.
Aftermath
As of September 2, 2026, Endor Labs is still scaling: $163M raised through the April 2025 Series B, 5M+ applications protected and 1M+ weekly scans, with product expansion into AI-generated-code security (Cursor and GitHub Copilot plugins). The EU CRA's vulnerability reporting obligations took effect September 11, 2026, and its main product obligations apply from December 11, 2027 — the compliance window Endor's CRA material targets, including mandatory SBOMs and 24-hour disclosure of actively exploited vulnerabilities. No further funding or acquisition is reflected in the sources reviewed.
Sources
- Cyber Resilience Act
- Endor Labs, which helps companies secure their open source packages, raises $70M
- Endor Labs, which builds tools to scan AI-generated code for vulnerabilities, lands $93M
- Why We Raised a $93M Series B (In This Market)
- The EU Cyber Resilience Act and the Software Supply Chain: Why Compliance Can't Wait
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card