CRA Direct Platform
Centralized workspace combining a deterministic 79-task CRA compliance roadmap, automated document generation, and continuous audit-ready compliance operations across your product portfolio.
The sovereign platform to run your CRA compliance roadmap (79 tasks, phases P0-P6), generate your 27 document templates, manage SBOMs, and secure your Article 14 reporting under 24h.
The EU Cyber Resilience Act turns product cybersecurity into an operational obligation. Manufacturers now need evidence, reporting workflows, and audit discipline before the 2026 and 2027 deadlines.
The regulation applies across the EU. All digital product manufacturers must launch their compliance program immediately.
Manufacturers must report actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform, including an early warning within 24 hours after becoming aware.
Products with digital elements placed on the EU market must meet the applicable CRA cybersecurity, conformity-assessment, technical-documentation, and CE-marking requirements.
For serious infringements, penalties can reach up to 15 million euros or 2.5% of total global annual turnover. Market-surveillance authorities may also require corrective action, restriction, withdrawal, or recall where applicable.
One CRA lifecycle suite for scope, classification, Annex I controls, technical documentation, SBOM evidence, vulnerability operations, Article 14 workflows, remediation, and audit trails.
Centralized workspace combining a deterministic 79-task CRA compliance roadmap, automated document generation, and continuous audit-ready compliance operations across your product portfolio.
Scope evaluation, product classification, conformity route, and Annex I control assessment mapping all 197 controls to a structured, deterministic compliance roadmap.
Manage Article 14 reporting workflows (24h/72h/final) with human-in-the-loop approval gates, automated draft validation, and stuck-mitigation monitoring.
Ingest, validate, store, and monitor Software Bills of Materials (CycloneDX & SPDX) with immutable baselines, S3 evidence locking, and automated dependency mapping.
Monitor OSV, KEV, EPSS, and EUVD exploit intelligence in real-time, generate automated impact deltas on new threats, and preserve append-only evidence chains.
Organize and generate the document catalog using 27 prefilled templates, editable DOCX downloads, Word XML placeholder checks, and compliance reminder schedules.
Deploy on your own servers or private cloud. Your compliance data never leaves your controlled environment. Built around the highest EU standards.
The Cyber Resilience Act (CRA) is the most important EU regulation ever adopted regarding digital product cybersecurity. It imposes mandatory security requirements on all manufacturers of products with digital elements on the EU market.
The CRA applies to any manufacturer, importer, or distributor of products with digital elements on the European market — whether based in Europe or not. This includes SaaS providers, IoT manufacturers, app developers, hardware builders.
Three key dates: 10 December 2024 — the CRA entered into force. 11 September 2026 — Article 14 reporting obligations apply. 11 December 2027 — the CRA applies in full, including conformity assessment and CE-marking obligations for products placed on the EU market.
An SBOM (Software Bill of Materials) is an inventory of software components. Under the CRA, manufacturers need component and vulnerability-handling evidence to support supply-chain traceability, security maintenance, technical documentation, and ongoing vulnerability operations.
Yes. CRA Direct is available as an on-premises or private cloud deployment for organizations that require 100% data sovereignty. Your compliance evidence — SBOMs, vulnerability data, incident reports, audit trails — stays entirely within your controlled environment, behind your own security perimeter.
Duration varies by product complexity, classification, evidence maturity, and whether third-party conformity assessment is needed. A readiness assessment can usually identify the scope, classification, evidence gaps, and roadmap within 2 weeks.
Don't wait for the deadline. Every month of delay reduces your room for maneuver. Contact us for a free consultation or platform demo.