One platform to classify your products, scan their code, map every finding to a CRA control and keep an audit-ready SBOM — from first commit to CE marking.
37+
CRA controls catalogued
Annex III/IV
classification engine
SAST + SCA
scanning lanes
AES-256
secrets at rest
Platform
The regulation spans product design, vulnerability handling and documentation. The platform turns each duty into a working feature.
Answer two questions, get the product's CRA tier — default, important class I/II or critical — with the conformity route recorded as evidence.
Connect GitHub or GitLab with a token that is AES-256-GCM encrypted at rest. Pushes, releases and builds flow in as signed webhooks.
Bundle a linked repository or a zip upload and submit it to the compliance engine — SAST today, SCA ready to switch on.
Scanner findings map to the essential requirements of Annex I, giving every product version a per-control pass/fail picture.
A machine-readable bill of materials per version — the component inventory the CRA makes mandatory for vulnerability handling.
Organizations with strict tenant isolation, member invites and nine compliance-specific roles from auditor to incident responder.
Workflow
Create the product, track versions immutably once published, and declare its assets.
The rules engine places it under Annex III/IV and fixes the conformity assessment route.
Link the GitHub/GitLab repository — or upload a hardened zip bundle of the codebase.
The engine scans every version; verdicts land on the CRA control matrix with an SBOM alongside.
Why now
The Cyber Resilience Act applies to virtually every product with digital elements sold in the EU. Breaching the essential requirements, or the Article 13 and 14 duties, carries fines up to €15M or 2.5% of worldwide annual turnover — other infringements carry lower tiers, and products can be barred from the market. Teams that wire compliance into their development flow now won't be scrambling later.
Dec 2024
CRA entered into force
Sep 2026
Reporting obligations apply — 24h alerts for exploited vulnerabilities
Dec 2027
Full application — CE marking requires CRA conformity
Register, add your first product and run a scan — the control matrix does the talking.