crAIready — Your path through the EU Cyber Resilience Act.
Developed by lawyers & IT experts — for your CRA compliance.
Non-binding initial assessment, not legal advice within the meaning of the German Legal Services Act (RDG).
Hosted in Thayngen, Switzerland.
The core platform and the systems operated by codAIx itself run on our own infrastructure in Thayngen, Switzerland.
Clearly identified external services are used only for the functions described in the privacy policy.
Who typically falls under the CRA?
The CRA applies to products with digital elements — software and connected hardware made available in the EU. Three broad groups:
Software manufacturers
Desktop, mobile or installable web applications, agents, plugins as well as APIs and SDKs that are made available on the EU market as a stand-alone product or as a component of a product.
Hardware with software
Embedded/IoT devices, controllers, sensors — hardware that runs software and establishes data or network connections.
Other economic operators
Authorised representatives, importers and distributors also have obligations of their own. Special CRA rules apply to open-source software stewards.
Pure cloud/browser SaaS without a local component usually does not fall directly under the CRA — the free Quick Check can help you draw the line.
- Borderline case 1 — SaaS with a desktop/agent component
SaaS with a desktop/agent component: pure cloud SaaS usually does not fall under the CRA — but as soon as a desktop app, an agent or a browser plugin is added, your backend may be covered via the RDPS definition.
SaaS & CRA: the RDPS boundary (in German) - Borderline case 2 — Rolling release / continuous deployment
Rolling release / continuous deployment: not every commit triggers CRA obligations — what matters is the “substantial modification” (Art. 3(30)); pure security updates do not count as such.
Rolling release & CRA: substantial modification (in German) - Borderline case 3 — Bundles & open source
Bundles & open source:
Whoever places a bundle on the market under their own name or trademark bears CRA responsibility for the product as a whole, including the integrated components. For integrated third-party components and open-source components not supplied in the course of a commercial activity, the risk-based due-diligence obligation under Art. 13(5) CRA applies.
Bundles & open source: components & responsibility (in German)
You know the Regulation. You know the clock is ticking. But who is going to implement it now?
This is exactly where most SMEs stand today — somewhere between
“We’ll deal with it next quarter” and “My development team has no time for compliance”.
- Nobody knows whether you are subject to the CRA at all. Cloud-only? With a desktop component? Drawing the line under Art. 3(2) is not trivial — and “just SaaS” is not a sufficient answer.
- No SBOM, no CE marking. A software bill of materials in, for example, CycloneDX 1.6 (ECMA-424) or SPDX 3.0.1 is mandatory — and a prerequisite for almost every further compliance requirement.
- Reports under Art. 14 CRA require a clear internal process. From 11 September 2026, the 24-hour period starts as soon as the manufacturer becomes aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product. The fines under Art. 64 CRA apply from 11 December 2027.
- External consulting and internal implementation effort can tie up considerable resources. Scope and cost depend in particular on product complexity, maturity level, product class and the security and documentation processes already in place.
- crAIready brings information and evidence together in one place, versioned and traceable – in line with the documentation requirements of the CRA.
- Actively exploited vulnerabilities and severe incidents follow separate reporting channels under Art. 14 CRA. crAIready supports preparation, deadline overview and documentation.
What you gain
You keep your focus on your product. crAIready structures the core CRA tasks.
Free initial assessment
In just a few questions, the Quick Check shows whether and how the CRA could affect your product. Non-binding and without a login.
Machine-readable SBOM
crAIready imports SBOMs via upload in common CycloneDX and SPDX formats. Via a connected CI pipeline, bills of materials can also be generated per product and version; managed SBOMs can be exported again in machine-readable formats.
Handle vulnerabilities per product
Vulnerability advisories, assessments, measures and responsibilities are traceably assigned to the affected product.
Structured documentation
crAIready brings information and evidence together in one place, versioned and traceable – in line with the documentation requirements of the CRA. Audit-ready evidence for internal approvals and enquiries from authorities.
Prepare Article 14 reports
crAIready supports preparation, deadline overview and documentation. Review, approval and submission via the official single reporting platform remain with the responsible company.
Usable without source-code upload
The core CRA tasks can be handled without uploading source code. Repository analysis is an optional add-on feature.
How it works
The Quick Check is free. Product set-up and further processing take place in the crAIready platform after purchase.
1 · Get an initial assessment
In just a few questions, the Quick Check shows whether the CRA could affect your product, which risk class you fall into, what your CRA readiness score is and what crAIready can offer you. Non-binding and without having to provide your details.
2 · Set up your product in a structured way
In the platform’s onboarding wizard, record the product for which you have purchased crAIready in a structured way. AI assistance can be switched on when required.
3 · Work through obligations and maintain evidence
Plan requirements, document decisions, handle vulnerabilities and prepare the reports under Art. 14 CRA that are required from 11 September 2026.
Do you need support?
Do you need technical support? Get in touch with us.
crAIready is built for roles subject to the CRA, in particular manufacturers, distributors and importers — from SaaS providers with a desktop component, through embedded/IoT manufacturers, to the component business. Three typical paths through the CRA:
Built for companies subject to the CRA
crAIready supports companies in meeting the requirements of the Cyber Resilience Act.
From the free Quick Check to audit-ready evidence for internal approvals and enquiries from authorities. For connected devices and embedded software, too, crAIready supports the core CRA tasks – from recording the product architecture and firmware components, through the consolidated SBOM, to vulnerability handling and technical documentation.
What is the status quo actually costing you?
crAIready bundles product data, SBOM, vulnerability handling, technical documentation and the preparation of Article 14 reports into one traceable workflow.
We turn weeks into days — and you stay in control
Evidence for the order of magnitude of the CRA effort: European Commission, impact assessment on the CRA (SWD(2022) 282, 2022) — manufacturers’ compliance costs in the tens of billions across the EU; IW Köln / Mittelstand-Digital “Auswirkungen auf KMU” (2025) — a considerable burden for SMEs. The person-days shown are a non-binding estimate based on our own project experience (reference: 1 product, medium maturity level, standard self-assessment) and are not taken from these studies. Sources:
cep - Cyber Resilience Act PolicyBrief (COM(2022) 454)
IW Köln - Auswirkungen auf KMU (in German)
European Commission - Cyber Resilience Act
see also What is the status quo actually costing you? (in German)
You are not buying a black box. You are buying traceability.
Substance true to the Regulation
Every function can be traced directly to the articles and annexes of Regulation (EU) 2024/2847.
No vague “best practices” — just the text of the Regulation, with column references.
AI with a sense of proportion
Our AI assists with product classification, the assessment of selected vulnerabilities and the creation of drafts. AI output is labelled as AI-assisted and remains a suggestion; decisions of legal or technical significance require human review and approval.
We practise what we preach
As a legal-tech company, we continuously review the security and compliance requirements that apply to us.
Funding possible — often up to 50 % of the investment.
Funding amounts, funding rates and eligibility criteria are programme-specific. The funding overview is checked every 14 days and updated where necessary.
We take the text of the Regulation seriously — and write about it.
Background articles on the RDPS boundary, SBOM practice, the AI Act interface, reporting obligations and high-risk AI. Written for decision-makers who want to know what really applies.
In just a few minutes, you will know what the CRA means for your product.
Free initial assessment: the Quick Check shows you whether and how the CRA could affect your product.
Non-binding guidance