141 days until CRA enforcement begins

Be CRAready before
September 11, 2026.

The EU Cyber Resilience Act starts fining software vendors €15M or 2.5% of global turnover for missed vulnerability reports. CRAready generates your SBOM, tracks vulnerabilities, and files the 24-hour report — automatically.

By joining, you agree to our Privacy Policy and Terms. Unsubscribe anytime.

Early-access users get lifetime 50% off. No credit card required.

If you ship software to the EU,
three things just became mandatory.

Not guidance. Not best practice. Mandatory regulation with enforceable fines.

📋

SBOM Mandate

Every dependency, every version, kept current. If you can't produce a machine-readable Software Bill of Materials on 48-hour notice from a market-surveillance authority, you're non-compliant.

24-Hour Vuln Reporting

Active exploits in your product must be reported to ENISA and national CSIRTs within 24 hours. Miss it once — regulators remember.

€15M Fines

Up to €15M or 2.5% of global turnover per violation. ENISA already has the Single Reporting Platform built. The fines are not theoretical.

CRAready is the entire workflow,
on autopilot.

15 minutes from connection to audit-ready.

1

Connect your repo

GitHub or GitLab OAuth. Every push generates a fresh SBOM in CycloneDX or SPDX format. Automatic, versioned, audit-ready.

2

Watch your dependencies

Continuous vulnerability enrichment from NVD, OSV, and GHSA. Know the moment a CVE drops in a library you're using — before attackers do.

3

One-click ENISA report

When an exploitable vulnerability hits, CRAready pre-fills the 24-hour ENISA report with your SBOM data, CVE details, and mitigation steps. You review. One click. Filed.

Built for the 99% of software vendors
enterprise tools ignore.

Existing tools are priced for 500-person enterprises. CRAready is priced for the team that ships.

CRAreadyLegacy enterprise SBOM toolsTraditional SCA scannersDev-first security platforms
Starter price$79/mo$40K+/yr$15–65K/yr$25K+/yr (seats)
CRA-specific workflow✓ Built-inAdd-on moduleGenericGeneric
24h ENISA reporting✓ One-clickManualManualManual
Setup time15 minutesWeeksWeeksDays
For <200 FTE companies✓ Designed forMid-market+Enterprise-firstPriced out

SCA = Software Composition Analysis. SBOM = Software Bill of Materials.

Start covered. Scale when you're ready.

14-day free trial on every plan. Cancel anytime. Annual saves 20%.

Starter

$79/mo

For solo devs and early-stage teams

  • 1 repository
  • Monthly SBOM generation
  • Vulnerability monitoring
  • Manual ENISA report export
  • Email support
Join waitlist →
Most Popular

Pro

$199/mo

For growing product teams

  • 5 repositories
  • Weekly SBOM generation
  • Automated vuln alerts
  • One-click ENISA filing
  • Team workspace (3 seats)
  • Priority email support
Join waitlist →

Growth

$499/mo

For serious operators

  • Unlimited repositories
  • Continuous SBOM
  • VEX automation
  • 24h ENISA automation
  • Unlimited team seats
  • SSO + audit log
  • SOC 2 report sharing
  • Dedicated support
Join waitlist →

For the team that can't afford a full compliance department.

If you're a software vendor under 200 people — founder, engineering lead, or security-conscious developer — CRAready fits. You don't need a dedicated compliance team or a six-figure consulting engagement. Connect your repo, answer a few setup questions, and you're CRAready in 15 minutes.

Frequently asked questions

Does the EU Cyber Resilience Act apply to my company?

If you sell, license, or make available software with digital elements on the EU market — yes. This includes SaaS tools, downloadable software, libraries, IoT devices, and embedded software. It does not matter where your company is legally based.

When does enforcement start?

Vulnerability reporting to ENISA becomes mandatory on September 11, 2026. Full SBOM and technical documentation requirements kick in on December 11, 2027.

What's an SBOM?

A Software Bill of Materials — a machine-readable list of every software component (libraries, frameworks, dependencies) your product uses. CRA requires it in CycloneDX or SPDX format. CRAready generates it automatically from your repository.

What if I'm based outside the EU?

The CRA applies extraterritorially. Non-EU manufacturers must appoint an authorised representative in the EU. CRAready is planning guided integrations with EU representative services (available Q3 2026).

Can I use open-source tools like Syft and Grype myself?

Yes. If you have the DevSecOps capacity to maintain the pipeline, handle vulnerability enrichment, track regulatory changes, and file ENISA reports manually — absolutely. CRAready is for teams who'd rather spend that time shipping product.

Do you store my source code?

No. CRAready reads repository metadata and dependency manifests only. Your code never leaves GitHub/GitLab.

Is CRAready itself CRA-compliant?

Yes — we eat our own dog food. Our SBOM is public, vulnerability handling is ENISA-ready, and we pursue SOC 2 Type 1 certification in Q3 2026.

Can I cancel anytime?

Yes. Monthly plans cancel anytime, no questions. Annual plans prorate.

The clock doesn't stop. Start now.

ENISA starts accepting 24-hour reports on September 11, 2026. If your vulnerability handling process isn't built, documented, and tested by then, you're not CRA-ready.

By joining, you agree to our Privacy Policy and Terms. Unsubscribe anytime.

141 days remaining · No credit card required · Early-access invites begin April 29