Regulation (EU) 2024/2847 · Cyber Resilience Act

crAIready — Your path through the EU Cyber Resilience Act.

Developed by legal & IT experts — for your CRA compliance.

Non-binding initial assessment, not legal advice within the meaning of the German Legal Services Act (RDG).

Hosted in Thayngen, Switzerland.

The core platform and the systems operated by codAIx itself run on our own infrastructure in Thayngen, Switzerland.

Clearly identified external services are used only for the functions described in the privacy policy.

Operated in Thayngen (CH) SaaS available without source-code upload Locally hosted AI

How we protect your data →

11.09.2026
From this date, the reporting obligations under Article 14 CRA apply. Manufacturers must report actively exploited vulnerabilities and severe incidents having an impact on the security of the product without undue delay, and in any event within 24 hours of becoming aware of them, initially as an early warning.
11.12.2027
Products with digital elements that are newly placed on the market from 11 December 2027 are, as a rule, subject to the CRA requirements, including CE marking. Products placed on the market before that date are covered by the transitional provisions of Article 69 CRA.
EUR 15 million
Fines under Article 64(2) CRA: from 11 December 2027 — up to EUR 15 million or 2.5 % of worldwide annual turnover, whichever is higher. The related reporting obligations under Article 14 CRA apply from 11 September 2026.
up to EUR 30,000
Funding amounts, funding rates and eligibility criteria differ from programme to programme. The funding overview lists the status, deadlines and sources of the programmes considered.
Applicability

Who typically falls under the CRA?

The CRA applies to products with digital elements — software and connected hardware made available in the EU. Three broad groups:

Software manufacturers

Desktop, mobile and installable web applications, as well as independently supplied agents, plugins, APIs and SDKs.

Hardware with software

Embedded and IoT devices, controllers and sensors that run software and connect directly or indirectly to devices or networks.

Other economic operators

Authorised representatives, importers and distributors also have duties. Specific rules apply to open-source software stewards.

Pure cloud or browser-based SaaS without a local component usually does not fall directly under the CRA — the free Quick Check can help you draw the line.

  • Borderline case 1 — SaaS with a desktop application or agent

    Cloud-only SaaS generally does not fall directly within the scope of the CRA. However, if the offering includes a desktop application, agent or browser plugin, the related back-end services may qualify as a remote data processing solution (RDPS) and may therefore fall within scope.
    SaaS & CRA: the RDPS boundary (in German)

  • Borderline case 2 — Rolling releases and continuous deployment

    Not every software update triggers a new conformity assessment under the CRA. The key question is whether an update constitutes a substantial modification within the meaning of Article 3(30). Security updates that solely reduce cybersecurity risk and do not change the intended purpose or introduce new risks generally do not constitute such a modification.
    Rolling release & CRA: substantial modification (in German)

  • Responsibility case — Software bundles and open-source components

    A company that places a software bundle on the market under its own name or trademark is responsible under the CRA for the product as a whole, including its integrated components. When integrating third-party components or open-source components that are not made available in the course of a commercial activity, the company must exercise risk-based due diligence under Article 13(5) CRA.
    Bundles & open source: components & responsibility (in German)

Sound familiar?

You know the Regulation. You know the clock is ticking. But who is going to implement it now?

This is exactly where most SMEs stand today — somewhere between
“We’ll deal with it next quarter” and “My development team has no time for compliance”.

  • Not sure whether your product falls within the scope of the CRA? Cloud-only? With a desktop component? Drawing the line under Article 3(2) is not trivial — and “just SaaS” is not a sufficient answer.
  • No SBOM, no CE marking. A software bill of materials in, for example, CycloneDX 1.6 (ECMA-424) or SPDX 3.0.1 is mandatory — and a prerequisite for almost every further compliance requirement.
  • Reports under Article 14 CRA require a clear internal process. From 11 September 2026, the 24-hour period starts as soon as the manufacturer becomes aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product. The fines under Article 64 CRA apply from 11 December 2027.
  • External consulting and internal implementation effort can tie up considerable resources. Scope and cost depend in particular on product complexity, maturity level, product class and the security and documentation processes already in place.
  • crAIready brings information and evidence together in one place, versioned and traceable – in line with the documentation requirements of the CRA.
  • Actively exploited vulnerabilities and severe incidents follow separate reporting workflows under Article 14 CRA. crAIready supports report preparation, deadline tracking and documentation.

What you gain

You keep your focus on your product. crAIready structures the core CRA tasks.

Free initial assessment

The free Quick Check indicates whether and how the CRA may apply to your product — without login or commitment.

Machine-readable SBOM

SBOMs can be imported, managed by product and exported in common CycloneDX and SPDX formats.

Manage vulnerabilities by product

Vulnerability notices, assessments, measures and responsibilities are assigned to the affected product in a traceable manner.

Structured documentation

crAIready maintains a central, version-controlled record of information, decisions and evidence for internal approvals and regulatory requests.

Article 14 reporting workflow

crAIready supports deadline tracking, preparation and documentation. Review, approval and submission remain your company’s responsibility.

No source code upload required

Core CRA tasks can be completed without uploading source code. Repository analysis remains optional.

How it works

The Quick Check is free. Product setup and further processing take place in the crAIready platform after purchase.

1 · Initial assessment

The free Quick Check indicates whether and how the CRA may apply to your product — without login or commitment.

2 · Set up your product

Use the platform wizard to create a structured record for the product covered by your crAIready plan. AI assistance can be enabled if needed.

3 · Manage obligations and evidence

Plan the required work, document decisions, handle vulnerabilities and prepare Article 14 reports in one structured workflow.

Technical support

Do you need support?

Do you need technical support? Get in touch with us.

Do it yourself vs. with crAIready

What is the status quo actually costing you?

crAIready bundles product data, SBOM, vulnerability handling, technical documentation and the preparation of Article 14 reports into one traceable workflow.

Task
Build it yourself
With crAIready
CRA classification of your product
Weeks of in-house research across the Regulation, its annexes and the relevant implementing acts
Guided wizard with a product-specific recommendation
SBOM generation & maintenance
Manually maintained lists and scattered documents
Via upload or a connected CI pipeline; managed per product and version
Vulnerability monitoring
Manual CVE screening without automatic matching against SBOM components
OSV + NVD + CISA KEV + EUVD; triage with CVSS, EPSS, CWE and KEV status
Technical documentation under Annex VII CRA
Word template, 80 pages, maintained by hand, quickly outdated
AI-assisted draft with article references, for expert review and approval
Prepare Article 14 reports
Manual spreadsheets under 24-hour deadlines; higher risk of error.
Guided workflows, deadline tracking plus PDF and CSAF-compatible exports
Internal implementation effort
70–160 person-days
5–15 person-days¹

¹ Some associated costs may be eligible for funding, depending on the programme and its conditions.

We turn weeks into days — and you stay in control

Evidence for the order of magnitude of the CRA effort: European Commission, impact assessment on the CRA (SWD(2022) 282, 2022) — manufacturers’ compliance costs in the tens of billions across the EU; IW Köln / Mittelstand-Digital “Auswirkungen auf KMU” (2025) — a considerable burden for SMEs. The person-days shown are a non-binding estimate based on our own project experience (reference: 1 product, medium maturity level, standard self-assessment) and are not taken from these studies. Sources:
cep - Cyber Resilience Act PolicyBrief (COM(2022) 454)
IW Köln - Auswirkungen auf KMU (in German)
European Commission - Cyber Resilience Act
see also What is the status quo actually costing you? (in German)

What we stand for

You are not buying a black box. You are buying traceability.

Grounded in the Regulation

Each function is linked to the relevant articles and annexes of the CRA, making both the requirements and their implementation traceable.

Responsible use of AI

AI supports selected tasks. Its outputs remain proposals; decisions with legal or technical significance require human review and approval.

We practise what we preach

We apply the same security and compliance principles to our own processes and review them continuously.

Funding

Funding possible — often up to 50 % of the investment.

Funding amounts, funding rates and eligibility criteria are programme-specific. The funding overview is checked every 14 days and updated where necessary.

Knowledge about the CRA

We explain the Regulation carefully and in practical terms.

In-depth articles on distinguishing remote data processing solutions (RDPS) from stand-alone SaaS, SBOM practice, the AI Act, reporting obligations and high-risk AI. Written for decision-makers who want to know what really applies.

In just a few minutes, you will know what the CRA means for your product.

Free initial assessment: the Quick Check shows you whether and how the CRA could affect your product.

Non-binding guidance