The Cyber Resilience Act without a lawyer or a security team.
From 11 September 2026 you must report actively exploited vulnerabilities within 24 hours. From 11 December 2027 no software or connected device can be placed on the EU market without CE marking and security documentation. CRAguard watches your dependencies, hosts your mandatory vulnerability-reporting channel and prepares your self-assessment documentation.
For companies that sell software — not for security departments.
Small software companies
Desktop, mobile, on-prem, libraries, plugins. Anything a customer installs or runs themselves.
Device makers
Anything with firmware or a network connection: IoT, industrial, smart home.
Software agencies
Your clients will ask you for SBOMs and security documentation. Deliver it in a day, not a month.
The first deadline isn't in 2027.
Article 14 reporting also applies to products already on the market. You cannot meet the 24-hour deadline without a process in place.
Reporting from 11 September 2026 applies to products already on the market.
Fines up to €15 million or 2.5 % of turnover — and, more realistically, losing tenders when a buyer asks for documentation.
Harmonised standards aren't out yet — self-assessment is done directly against the regulation.
Watches, hosts, prepares. In that order.
Watches your dependencies
An SBOM from your build, daily comparison against OSV, NVD and CISA KEV. One plain-language verdict instead of a hundred CVEs.
Hosts your mandatory channel
A public vulnerability-reporting page, security.txt and advisories. Required by Annex I — set up in a minute, hosted forever.
Contact: https://vasafirma.craguard.eu/report
Policy: https://vasafirma.craguard.eu/cvd
Prepares your documentation
Risk assessment, technical documentation, Declaration of Conformity, CVD policy. In plain language, each referencing the article it satisfies.
Guides you through an incident
The fields ENISA's platform expects, deadline countdowns, a checklist. You file it yourself — the platform has no API.
Three steps. No training.
Upload an SBOM or connect a repository
Syft, Trivy, CycloneDX, SPDX — anything from your build.
CRAguard watches and translates
Turns raw CVEs into a verdict even your CEO understands.
You click the decisions, we write the audit trail
Evidence for the authority and for the buyer who asks.
What CRAguard is not
CRAguard is not legal advice and not a certification. It cannot guarantee completeness or compliance with the regulation. Conformity is declared by the manufacturer. We provide the process and the evidence that back it up.
Subscriptions from €29/month per product.
Join the waitlist — we'll let you know at launch and send you the first steps towards CRA readiness.
Find out in 2 minutes whether the CRA applies to youFAQ
Does the CRA apply to SaaS?
Mostly not — unless it's cloud functionality necessary for a product to work. SaaS falls under NIS2.
Does it apply to products I already sell?
The reporting obligation from 11 September 2026 does. Full requirements apply on substantial modification or a new placement after 11 December 2027.
Do I have to publish my SBOM?
No — it's part of your technical documentation, provided to the authority on request.
Do I need certification?
Most products are "default" class = self-assessment. Only Annex III/IV categories need a notified body or certification.
I'm just an agency — am I affected?
The manufacturer is whoever places the product on the market under their own name — your client. They'll want the documentation from you.
Find out whether the CRA applies to you
Six questions, two minutes, no account. Get your product class and first steps.