Frequently asked questions

FAQ — crAIready and the Cyber Resilience Act

Answers to the most frequently asked questions about the CRA, your obligations as a manufacturer and our platform. Non-binding information, not legal advice within the meaning of the German Legal Services Act (RDG); the final assessment is made by a human.

Basics & scope

Who has to comply with the CRA?

Primarily manufacturers of products with digital elements that make those products available on the EU market. Authorised representatives, importers and distributors also have obligations of their own. Which role and which obligations apply in a specific case depends on the product and the distribution model. The free Quick Check provides initial, non-binding guidance.

What applies from when?

The reporting obligations under Art. 14 CRA apply from 11 September 2026. Most of the other obligations under the CRA apply from 11 December 2027.

Does pure SaaS fall under the CRA?

Not automatically. Stand-alone cloud or SaaS services do not fall under the CRA merely because they are provided over the internet. However, a cloud function may form part of a product with digital elements as a “remote data processing solution” if it was developed by the manufacturer or under its responsibility and the product could not perform one of its functions without it. The specific technical and distribution set-up therefore needs to be examined.

What is an SBOM — and why do I need one?

A software bill of materials is a machine-readable overview of the software components used in a product. It supports the identification and handling of vulnerabilities. As part of vulnerability handling, the CRA requires an SBOM in a commonly used machine-readable format, covering at least the top-level dependencies.

In which format is the SBOM provided?

crAIready supports the import and export of commonly used machine-readable formats: CycloneDX JSON/XML and SPDX JSON/Tag-Value. SBOMs can also be generated via a connected CI pipeline and assigned to product versions.

Data & security

What data does crAIready store — and where?

The core systems operated by codAIx itself – marketing website, account portal, platform, customer environments, database, locally operated AI and local backups – run on our own infrastructure in Thayngen, Switzerland. The data processed comprises in particular account, contract, product, documentation, role, approval and log data, insofar as users provide it or it arises during operation. If a customer expressly selects an external AI provider, the respective prompt and the product information required for the function are transmitted to the selected provider. Details are set out in the privacy policy and the DPA. No payment processing currently takes place on the public website.

Does codAIx use my data for AI training?

No. codAIx does not use customer content to train its own or self-operated AI models. When the local AI operated by codAIx is used, the inputs required for the function are processed on infrastructure operated by codAIx in Thayngen; they are not passed on to third-party AI model providers and are not stored beyond processing. If a selectable cloud AI is expressly activated, the terms and privacy notices of the selected provider additionally apply to the content transmitted. Repository analysis is optional; crAIready can also be used without uploading source code.

Does codAIx take the CRA into account for crAIready?

Yes. We comply with the requirements of the Cyber Resilience Act that apply to crAIready and are aligning development and operations with the further requirements at an early stage. codAIx assesses and documents which obligations apply on the basis of the technical design and provision of the platform. This includes in particular the assessment of cybersecurity risks, documented processes for handling vulnerabilities and security updates, and the maintenance of the required technical evidence. New legal and technical requirements are reviewed and taken into account in line with their respective application dates.

What happens to my data when the contract ends?

During the contract term, the data captured by the standard functions can be exported in the available formats. After the contract ends, an appropriate export route generally remains available for a further 30 days. Production data is then deleted or returned in accordance with the DPA; backup copies are overwritten or deleted in the regular backup cycle within a further 30 days at the latest. Statutory retention obligations remain unaffected. Longer-term archiving is provided only where it has been expressly agreed.

Product & process

How do I get started?

Start with the free Quick Check or choose a suitable plan straight away if you already know that your product falls under the CRA. The Quick Check gives you a non-binding initial assessment without a login. After purchase, we set up your platform access. In the guided onboarding wizard, you create your product in a structured way and receive support with classification based on the product categories in Annexes III and IV and with the resulting conformity route. You then work through the relevant obligations and maintain the SBOM, vulnerabilities, decisions and evidence centrally in crAIready. The Quick Check and the platform are separate processes; the information from the Quick Check is not transferred automatically. The final classification, review and approval remain with the responsible manufacturer.

Can I try crAIready before buying?

The Quick Check can be used free of charge and without a login. General free access to the full platform is not currently offered. Platform access is set up once the contract has been concluded and the account has been activated.

Do I need a notified body?

That depends on the CRA product category and the applicable conformity assessment procedure. For products not classified as important or critical, internal control under Module A is generally possible. For important products of Class I, an external assessment may become necessary if the relevant harmonised standards, common specifications or suitable certification schemes are not applied, or are applied only in part. Stricter procedures apply to important products of Class II and to critical products. crAIready supports classification and preparation; the binding selection and performance of the procedure remain with the manufacturer and, where applicable, a notified body. The Quick Check can provide initial, non-binding guidance.

Does crAIready generate the notification to the authorities automatically?

No. crAIready supports preparation, an overview of deadlines and documentation. Review, approval and submission via the official single reporting platform remain with the responsible company. For actively exploited vulnerabilities, the general deadlines are 24 hours for the early warning, 72 hours for the vulnerability notification and, at the latest, 14 days after a corrective or mitigating measure becomes available for the final report. For severe incidents having an impact on the security of the product, the general deadlines are 24 hours for the early warning, 72 hours for the incident notification and one month after the 72-hour notification for the final report.

Is an on-premises solution available?

No. crAIready is currently offered exclusively as SaaS.

Is this legal advice?

No. crAIready provides technical and organisational support, but no case-specific legal advice or guarantee of conformity. The legal and technical assessment as well as the necessary decisions and approvals remain with the responsible company.

Pricing & funding

What is free, and what costs money?

The Quick Check and the non-binding initial assessment it contains are free of charge. Use of the platform, management of products and the available evidence and export functions are subject to a charge and depend on the plan selected.

How much does crAIready cost?

The current net prices on the pricing page apply, generally per product. Variants that are largely identical in technical and regulatory terms can be managed as one product family; for open-source software stewards, one supported open-source project counts as the billing unit. Customers in Germany are billed in EUR and customers in Switzerland in CHF; the numerical amount is the same. Statutory taxes are added.

Is funding available?

Funding opportunities depend on where the company is based, the specific project, the time of application and the conditions of the respective programme. codAIx does not promise any particular funding, funding rate or approval. The standard crAIready offer is currently aimed exclusively at companies in Germany and Switzerland.

Depending on the programme and region, grants of up to EUR 30,000 may be available. Eligibility, funding rate and approval are governed by the conditions of the respective programme.

Go to the funding overview →

Obligations & deadlines

How long do I have to keep records?

Manufacturers must generally keep the technical documentation and the EU declaration of conformity for at least ten years after the product has been placed on the market or for the support period – whichever is longer. crAIready keeps the records captured during the contract term exportable; the customer must save any required exports in good time.

How long must security updates be provided?

The support period must reflect the expected period of use of the product and is generally at least five years. If the product is expected to be in use for less than five years, the support period may correspond to that shorter expected period of use. Where a longer period of use is expected, a longer support period may be required.

Do I face fines?

The reporting obligations under Art. 14 CRA apply from 11 September 2026. The fines framework under Art. 64(2) CRA applies from 11 December 2027. For infringements of the essential cybersecurity requirements or the obligations under Art. 13 and 14 CRA, it provides for administrative fines of up to EUR 15 million or, in the case of undertakings, up to 2.5 % of the total worldwide annual turnover for the preceding financial year, whichever is higher. Whether and in what amount a penalty is imposed depends on the individual case and the applicable procedure.

Source for the legal information: Regulation (EU) 2024/2847 (Cyber Resilience Act), in particular Art. 3, 13, 14, 32 and 64 and Annex I. Non-binding general information, not legal advice; the case-specific legal and technical assessment remains with the responsible company. Last updated: 2 September 2026.