crAIready — Your path through the EU Cyber Resilience Act.
Developed by legal & IT experts — for your CRA compliance.
Non-binding initial assessment, not legal advice within the meaning of the German Legal Services Act (RDG).
Hosted in Thayngen, Switzerland.
The core platform and the systems operated by codAIx itself run on our own infrastructure in Thayngen, Switzerland.
Clearly identified external services are used only for the functions described in the privacy policy.
Who typically falls under the CRA?
The CRA applies to products with digital elements — software and connected hardware made available in the EU. Three broad groups:
Software manufacturers
Desktop, mobile and installable web applications, as well as independently supplied agents, plugins, APIs and SDKs.
Hardware with software
Embedded and IoT devices, controllers and sensors that run software and connect directly or indirectly to devices or networks.
Other economic operators
Authorised representatives, importers and distributors also have duties. Specific rules apply to open-source software stewards.
Pure cloud or browser-based SaaS without a local component usually does not fall directly under the CRA — the free Quick Check can help you draw the line.
- Borderline case 1 — SaaS with a desktop application or agent
Cloud-only SaaS generally does not fall directly within the scope of the CRA. However, if the offering includes a desktop application, agent or browser plugin, the related back-end services may qualify as a remote data processing solution (RDPS) and may therefore fall within scope.
SaaS & CRA: the RDPS boundary (in German) - Borderline case 2 — Rolling releases and continuous deployment
Not every software update triggers a new conformity assessment under the CRA. The key question is whether an update constitutes a substantial modification within the meaning of Article 3(30). Security updates that solely reduce cybersecurity risk and do not change the intended purpose or introduce new risks generally do not constitute such a modification.
Rolling release & CRA: substantial modification (in German) - Responsibility case — Software bundles and open-source components
A company that places a software bundle on the market under its own name or trademark is responsible under the CRA for the product as a whole, including its integrated components. When integrating third-party components or open-source components that are not made available in the course of a commercial activity, the company must exercise risk-based due diligence under Article 13(5) CRA.
Bundles & open source: components & responsibility (in German)
You know the Regulation. You know the clock is ticking. But who is going to implement it now?
This is exactly where most SMEs stand today — somewhere between
“We’ll deal with it next quarter” and “My development team has no time for compliance”.
- Not sure whether your product falls within the scope of the CRA? Cloud-only? With a desktop component? Drawing the line under Article 3(2) is not trivial — and “just SaaS” is not a sufficient answer.
- No SBOM, no CE marking. A software bill of materials in, for example, CycloneDX 1.6 (ECMA-424) or SPDX 3.0.1 is mandatory — and a prerequisite for almost every further compliance requirement.
- Reports under Article 14 CRA require a clear internal process. From 11 September 2026, the 24-hour period starts as soon as the manufacturer becomes aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product. The fines under Article 64 CRA apply from 11 December 2027.
- External consulting and internal implementation effort can tie up considerable resources. Scope and cost depend in particular on product complexity, maturity level, product class and the security and documentation processes already in place.
- crAIready brings information and evidence together in one place, versioned and traceable – in line with the documentation requirements of the CRA.
- Actively exploited vulnerabilities and severe incidents follow separate reporting workflows under Article 14 CRA. crAIready supports report preparation, deadline tracking and documentation.
What you gain
You keep your focus on your product. crAIready structures the core CRA tasks.
Free initial assessment
The free Quick Check indicates whether and how the CRA may apply to your product — without login or commitment.
Machine-readable SBOM
SBOMs can be imported, managed by product and exported in common CycloneDX and SPDX formats.
Manage vulnerabilities by product
Vulnerability notices, assessments, measures and responsibilities are assigned to the affected product in a traceable manner.
Structured documentation
crAIready maintains a central, version-controlled record of information, decisions and evidence for internal approvals and regulatory requests.
Article 14 reporting workflow
crAIready supports deadline tracking, preparation and documentation. Review, approval and submission remain your company’s responsibility.
No source code upload required
Core CRA tasks can be completed without uploading source code. Repository analysis remains optional.
How it works
The Quick Check is free. Product setup and further processing take place in the crAIready platform after purchase.
1 · Initial assessment
The free Quick Check indicates whether and how the CRA may apply to your product — without login or commitment.
2 · Set up your product
Use the platform wizard to create a structured record for the product covered by your crAIready plan. AI assistance can be enabled if needed.
3 · Manage obligations and evidence
Plan the required work, document decisions, handle vulnerabilities and prepare Article 14 reports in one structured workflow.
Do you need support?
Do you need technical support? Get in touch with us.
What is the status quo actually costing you?
crAIready bundles product data, SBOM, vulnerability handling, technical documentation and the preparation of Article 14 reports into one traceable workflow.
¹ Some associated costs may be eligible for funding, depending on the programme and its conditions.
We turn weeks into days — and you stay in control
Evidence for the order of magnitude of the CRA effort: European Commission, impact assessment on the CRA (SWD(2022) 282, 2022) — manufacturers’ compliance costs in the tens of billions across the EU; IW Köln / Mittelstand-Digital “Auswirkungen auf KMU” (2025) — a considerable burden for SMEs. The person-days shown are a non-binding estimate based on our own project experience (reference: 1 product, medium maturity level, standard self-assessment) and are not taken from these studies. Sources:
cep - Cyber Resilience Act PolicyBrief (COM(2022) 454)
IW Köln - Auswirkungen auf KMU (in German)
European Commission - Cyber Resilience Act
see also What is the status quo actually costing you? (in German)
You are not buying a black box. You are buying traceability.
Grounded in the Regulation
Each function is linked to the relevant articles and annexes of the CRA, making both the requirements and their implementation traceable.
Responsible use of AI
AI supports selected tasks. Its outputs remain proposals; decisions with legal or technical significance require human review and approval.
We practise what we preach
We apply the same security and compliance principles to our own processes and review them continuously.
Funding possible — often up to 50 % of the investment.
Funding amounts, funding rates and eligibility criteria are programme-specific. The funding overview is checked every 14 days and updated where necessary.
We explain the Regulation carefully and in practical terms.
In-depth articles on distinguishing remote data processing solutions (RDPS) from stand-alone SaaS, SBOM practice, the AI Act, reporting obligations and high-risk AI. Written for decision-makers who want to know what really applies.
In just a few minutes, you will know what the CRA means for your product.
Free initial assessment: the Quick Check shows you whether and how the CRA could affect your product.
Non-binding guidance