Regulation (EU) 2024/2847 · Cyber Resilience Act

crAIready — Your path through the EU Cyber Resilience Act.

Developed by lawyers & IT experts — for your CRA compliance.

Non-binding initial assessment, not legal advice within the meaning of the German Legal Services Act (RDG).

Hosted in Thayngen, Switzerland.

The core platform and the systems operated by codAIx itself run on our own infrastructure in Thayngen, Switzerland.

Clearly identified external services are used only for the functions described in the privacy policy.

Operated in Thayngen (CH) SaaS available without source-code upload Locally hosted AI

How we protect your data →

11.09.2026
From this date, the reporting obligations under Art. 14 CRA apply. Manufacturers must report actively exploited vulnerabilities and severe incidents having an impact on the security of the product without undue delay, and in any event within 24 hours of becoming aware of them, initially as an early warning.
11.12.2027
Products with digital elements that are newly placed on the market from 11 December 2027 are, as a rule, subject to the CRA requirements, including CE marking. Products placed on the market before that date are covered by the transitional provisions of Art. 69 CRA.
EUR 15 million
Fines under Art. 64(2) CRA: from 11.12.2027 — up to EUR 15 million or 2.5 % of worldwide annual turnover, whichever is higher. The related reporting obligations under Art. 14 CRA apply from 11.09.2026.
up to EUR 30,000
Funding amounts, funding rates and eligibility criteria differ from programme to programme. The funding overview lists the status, deadlines and sources of the programmes considered.
Applicability

Who typically falls under the CRA?

The CRA applies to products with digital elements — software and connected hardware made available in the EU. Three broad groups:

Software manufacturers

Desktop, mobile or installable web applications, agents, plugins as well as APIs and SDKs that are made available on the EU market as a stand-alone product or as a component of a product.

Hardware with software

Embedded/IoT devices, controllers, sensors — hardware that runs software and establishes data or network connections.

Other economic operators

Authorised representatives, importers and distributors also have obligations of their own. Special CRA rules apply to open-source software stewards.

Pure cloud/browser SaaS without a local component usually does not fall directly under the CRA — the free Quick Check can help you draw the line.

  • Borderline case 1 — SaaS with a desktop/agent component

    SaaS with a desktop/agent component: pure cloud SaaS usually does not fall under the CRA — but as soon as a desktop app, an agent or a browser plugin is added, your backend may be covered via the RDPS definition.
    SaaS & CRA: the RDPS boundary (in German)

  • Borderline case 2 — Rolling release / continuous deployment

    Rolling release / continuous deployment: not every commit triggers CRA obligations — what matters is the “substantial modification” (Art. 3(30)); pure security updates do not count as such.
    Rolling release & CRA: substantial modification (in German)

  • Borderline case 3 — Bundles & open source

    Bundles & open source:
    Whoever places a bundle on the market under their own name or trademark bears CRA responsibility for the product as a whole, including the integrated components. For integrated third-party components and open-source components not supplied in the course of a commercial activity, the risk-based due-diligence obligation under Art. 13(5) CRA applies.
    Bundles & open source: components & responsibility (in German)

Sound familiar?

You know the Regulation. You know the clock is ticking. But who is going to implement it now?

This is exactly where most SMEs stand today — somewhere between
“We’ll deal with it next quarter” and “My development team has no time for compliance”.

  • Nobody knows whether you are subject to the CRA at all. Cloud-only? With a desktop component? Drawing the line under Art. 3(2) is not trivial — and “just SaaS” is not a sufficient answer.
  • No SBOM, no CE marking. A software bill of materials in, for example, CycloneDX 1.6 (ECMA-424) or SPDX 3.0.1 is mandatory — and a prerequisite for almost every further compliance requirement.
  • Reports under Art. 14 CRA require a clear internal process. From 11 September 2026, the 24-hour period starts as soon as the manufacturer becomes aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product. The fines under Art. 64 CRA apply from 11 December 2027.
  • External consulting and internal implementation effort can tie up considerable resources. Scope and cost depend in particular on product complexity, maturity level, product class and the security and documentation processes already in place.
  • crAIready brings information and evidence together in one place, versioned and traceable – in line with the documentation requirements of the CRA.
  • Actively exploited vulnerabilities and severe incidents follow separate reporting channels under Art. 14 CRA. crAIready supports preparation, deadline overview and documentation.

What you gain

You keep your focus on your product. crAIready structures the core CRA tasks.

Free initial assessment

In just a few questions, the Quick Check shows whether and how the CRA could affect your product. Non-binding and without a login.

Machine-readable SBOM

crAIready imports SBOMs via upload in common CycloneDX and SPDX formats. Via a connected CI pipeline, bills of materials can also be generated per product and version; managed SBOMs can be exported again in machine-readable formats.

Handle vulnerabilities per product

Vulnerability advisories, assessments, measures and responsibilities are traceably assigned to the affected product.

Structured documentation

crAIready brings information and evidence together in one place, versioned and traceable – in line with the documentation requirements of the CRA. Audit-ready evidence for internal approvals and enquiries from authorities.

Prepare Article 14 reports

crAIready supports preparation, deadline overview and documentation. Review, approval and submission via the official single reporting platform remain with the responsible company.

Usable without source-code upload

The core CRA tasks can be handled without uploading source code. Repository analysis is an optional add-on feature.

How it works

The Quick Check is free. Product set-up and further processing take place in the crAIready platform after purchase.

1 · Get an initial assessment

In just a few questions, the Quick Check shows whether the CRA could affect your product, which risk class you fall into, what your CRA readiness score is and what crAIready can offer you. Non-binding and without having to provide your details.

2 · Set up your product in a structured way

In the platform’s onboarding wizard, record the product for which you have purchased crAIready in a structured way. AI assistance can be switched on when required.

3 · Work through obligations and maintain evidence

Plan requirements, document decisions, handle vulnerabilities and prepare the reports under Art. 14 CRA that are required from 11 September 2026.

Technical support

Do you need support?

Do you need technical support? Get in touch with us.

What crAIready can do for you

crAIready is built for roles subject to the CRA, in particular manufacturers, distributors and importers — from SaaS providers with a desktop component, through embedded/IoT manufacturers, to the component business. Three typical paths through the CRA:

Built for companies subject to the CRA

crAIready supports companies in meeting the requirements of the Cyber Resilience Act.

From the free Quick Check to audit-ready evidence for internal approvals and enquiries from authorities. For connected devices and embedded software, too, crAIready supports the core CRA tasks – from recording the product architecture and firmware components, through the consolidated SBOM, to vulnerability handling and technical documentation.

Do it yourself vs. with crAIready

What is the status quo actually costing you?

crAIready bundles product data, SBOM, vulnerability handling, technical documentation and the preparation of Article 14 reports into one traceable workflow.

Reality
Build it yourself
With crAIready
CRA classification of your product
Weeks of in-house research through the jungle of provisions in the Regulation, its annexes and implementing acts
Guided wizard with a product-specific recommendation
SBOM generation & maintenance
Manually maintained lists and scattered documents
Via upload or a connected CI pipeline; managed per product and version
Vulnerability monitoring
Manual CVE screening without automatic matching against SBOM components
OSV + NVD + CISA KEV + EUVD; triage with CVSS, EPSS, CWE and KEV status
Technical documentation under Annex VII CRA
Word template, 80 pages, maintained by hand, quickly outdated
AI-assisted draft with article references, for expert review and approval
Prepare Article 14 reports
Excel template, 24-hour stress, risk
Guided workflows, deadline overview plus PDF and CSAF-compatible exports
Internal implementation effort
70 – 160 person-days
5 – 15 person-days — parts of which may be eligible for funding (programme-specific, usually up to 50 %)

We turn weeks into days — and you stay in control

Evidence for the order of magnitude of the CRA effort: European Commission, impact assessment on the CRA (SWD(2022) 282, 2022) — manufacturers’ compliance costs in the tens of billions across the EU; IW Köln / Mittelstand-Digital “Auswirkungen auf KMU” (2025) — a considerable burden for SMEs. The person-days shown are a non-binding estimate based on our own project experience (reference: 1 product, medium maturity level, standard self-assessment) and are not taken from these studies. Sources:
cep - Cyber Resilience Act PolicyBrief (COM(2022) 454)
IW Köln - Auswirkungen auf KMU (in German)
European Commission - Cyber Resilience Act
see also What is the status quo actually costing you? (in German)

What we stand for

You are not buying a black box. You are buying traceability.

Substance true to the Regulation

Every function can be traced directly to the articles and annexes of Regulation (EU) 2024/2847.
No vague “best practices” — just the text of the Regulation, with column references.

AI with a sense of proportion

Our AI assists with product classification, the assessment of selected vulnerabilities and the creation of drafts. AI output is labelled as AI-assisted and remains a suggestion; decisions of legal or technical significance require human review and approval.

We practise what we preach

As a legal-tech company, we continuously review the security and compliance requirements that apply to us.

Funding

Funding possible — often up to 50 % of the investment.

Funding amounts, funding rates and eligibility criteria are programme-specific. The funding overview is checked every 14 days and updated where necessary.

Knowledge about the CRA

We take the text of the Regulation seriously — and write about it.

Background articles on the RDPS boundary, SBOM practice, the AI Act interface, reporting obligations and high-risk AI. Written for decision-makers who want to know what really applies.

In just a few minutes, you will know what the CRA means for your product.

Free initial assessment: the Quick Check shows you whether and how the CRA could affect your product.

Non-binding guidance