Built for EU Regulation 2024/2847

Ship products that pass the Cyber Resilience Act

One platform to classify your products, scan their code, map every finding to a CRA control and keep an audit-ready SBOM — from first commit to CE marking.

  • Annex I essential requirements, checked by a real scanning engine
  • Tokens encrypted at rest — AES-256-GCM, never shown twice
  • Strict per-organization tenant isolation

37+

CRA controls catalogued

Annex III/IV

classification engine

SAST + SCA

scanning lanes

AES-256

secrets at rest

Platform

Everything the CRA asks of a manufacturer

The regulation spans product design, vulnerability handling and documentation. The platform turns each duty into a working feature.

Annex III / IV classification

Answer two questions, get the product's CRA tier — default, important class I/II or critical — with the conformity route recorded as evidence.

Repository & CI/CD integrations

Connect GitHub or GitLab with a token that is AES-256-GCM encrypted at rest. Pushes, releases and builds flow in as signed webhooks.

Security scanning

Bundle a linked repository or a zip upload and submit it to the compliance engine — SAST today, SCA ready to switch on.

CRA control matrix

Scanner findings map to the essential requirements of Annex I, giving every product version a per-control pass/fail picture.

SBOM

A machine-readable bill of materials per version — the component inventory the CRA makes mandatory for vulnerability handling.

Multi-tenant teams & RBAC

Organizations with strict tenant isolation, member invites and nine compliance-specific roles from auditor to incident responder.

Workflow

From product to proof in four steps

  1. 01

    Register the product

    Create the product, track versions immutably once published, and declare its assets.

  2. 02

    Classify it

    The rules engine places it under Annex III/IV and fixes the conformity assessment route.

  3. 03

    Connect the code

    Link the GitHub/GitLab repository — or upload a hardened zip bundle of the codebase.

  4. 04

    Scan & prove

    The engine scans every version; verdicts land on the CRA control matrix with an SBOM alongside.

Why now

The deadlines are already set

The Cyber Resilience Act applies to virtually every product with digital elements sold in the EU. Breaching the essential requirements, or the Article 13 and 14 duties, carries fines up to €15M or 2.5% of worldwide annual turnover — other infringements carry lower tiers, and products can be barred from the market. Teams that wire compliance into their development flow now won't be scrambling later.

CRA timeline
  1. Dec 2024

    CRA entered into force

  2. Sep 2026

    Reporting obligations apply — 24h alerts for exploited vulnerabilities

  3. Dec 2027

    Full application — CE marking requires CRA conformity

Make CRA compliance part of the pipeline

Register, add your first product and run a scan — the control matrix does the talking.