The platform

A platform that guides you through your CRA obligations in a structured way.

From structured product set-up through SBOM, vulnerabilities and documentation to the preparation of required reports. Decisions and approvals remain with the responsible company.

The onboarding wizard

Classification in a guided wizard – from your product details to a reasoned recommendation for action.

Which product class does your product fall into? Which conformity assessment procedure could apply to it? The AI-assisted onboarding wizard takes you from the details of your product and its core functionality to a specific recommendation. It takes into account all relevant product categories from Annex III Parts I and II and Annex IV CRA, together with their technical descriptions under Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025.

  • Class check against Annex III Part I – Class I with 19 categories, Annex III Part II – Class II with 4 categories and Annex IV – critical products with 3 categories
  • Recommendation of a product class based on your details
  • Overview of the conformity assessment procedures that could apply to the recommended product class
  • Roadmap with the relevant key dates: reporting obligations from 11 September 2026 and full application of the CRA from 11 December 2027

Transparency notice: the recommendation is based on the product categories of the CRA, Commission Implementing Regulation (EU) 2025/2392 and your inputs. The final legal classification remains the task and responsibility of the manufacturer.

crAIready wizard at the product class step with the demo classification “Default product”
Demo view with synthetic sample data.
SBOM & supply chain

CycloneDX 1.6 + SPDX 3.0.1, automatically from your code if you wish — including due diligence for third-party components.

Software bills of materials are a CRA requirement (Annex I Part II point 1). crAIready imports SBOMs by upload or via a connected CI pipeline, assigns them to product versions and keeps them exportable for the term of the contract. The retention obligation under Art. 13(13) CRA remains an obligation of the manufacturer. For integrated third-party components and open-source components not supplied in the course of a commercial activity, the platform supports the risk-based due diligence under Art. 13(5) CRA.

  • Usable without uploading source code — SBOM import in CycloneDX or SPDX; repository analysis optional
  • Machine-readable: CycloneDX (JSON/XML) and SPDX (JSON/tag-value)
  • Supplier assessment: CVD policy, SBOM availability, response SLA, incident history — or lifecycle check (upstream active, EOL date, release cadence)
  • Versioned & exportable for the term of the contract
Vulnerabilities & CVD

Detect vulnerabilities early, assess them per product and disclose them in a coordinated way.

crAIready regularly matches your SBOM components against OSV, NVD, CISA KEV and EUVD. Findings are prepared for triage with CVSS, EPSS, CWE and KEV status. The Article 14 assessment is carried out separately, because a CVE match does not by itself start a 24-hour deadline. In addition, crAIready supports the CVD process under Annex I Part II points 4–6 CRA.

  • Vulnerability register with triage and status tracking
  • Alerting on new findings and a separate Article 14 assessment
  • Embeddable reporting form for security researchers
  • Generator for a versioned CVD policy
  • Draft security advisories, compatible with CVE JSON 5.0
  • Review and approval before publication
crAIready triage view of a vulnerability with transition to the Article 14 reporting assessment
Demo view of the vulnerability triage with synthetic sample data.
crAIready risk heatmap with synthetic test risks and their distribution across the risk levels
Demo view of the risk heatmap with synthetic sample data.
Reporting obligations & incident response

Prepare Article 14 reporting channels – separately and on time.

crAIready guides you through the different workflows for actively exploited vulnerabilities and severe incidents having an impact on the security of the product. The required information is prepared in a structured way and the applicable deadlines are presented clearly. Review, approval and submission via the official single reporting platform remain with the responsible company.

  • Actively exploited vulnerabilities: 24 h / 72 h / 14 days
  • Severe incidents: 24 h / 72 h / one month
  • Guided workflows with pre-filled fields and a deadline overview
  • PDF and CSAF-compatible exports for further use
  • Information for affected users prepared and documented
  • Incident response plans stored per product
crAIready view for preparing an Article 14 report with staggered reporting deadlines
Demo view with synthetic sample data.
Documentation & conformity

Draft technical documentation under Annex VII and draft EU declaration of conformity – version-specific, ready for your review.

Based on your details, crAIready produces a structured draft of the technical documentation under Annex VII and a draft EU declaration of conformity under Art. 28 in conjunction with Annex V CRA. Review, completion, approval and signature remain with the manufacturer. In addition, the user information under Annex II and the evidence for the applicable conformity assessment procedure are prepared in a structured way.

  • Technical documentation under Annex VII: product description, relevant software versions, architecture and processes, cybersecurity risk assessment, standards applied and test reports
  • Draft EU declaration of conformity under Annex V, generated from your product data
  • User information under Annex II prepared in a structured way
  • Conformity assessment under Annex VIII: Module A, Module B in conjunction with Module C, or Module H – depending on the product class
  • Gap matrix and assigned evidence
  • Consolidated CRA dossier as PDF for internal approvals, requests from market surveillance authorities and – where required – notified bodies
Roles & economic operators

Work through CRA obligations according to your own role.

Manufacturers are not the only ones with obligations under the CRA. crAIready also maps the tasks of authorised representatives, importers and distributors on a per-product basis. Roles, responsibilities, mandates and required evidence are assigned centrally. In addition, the platform supports the assessment of whether an importer, distributor or other person is deemed a manufacturer because it markets or modifies a product.

  • Mandate-based obligations path for authorised representatives under Art. 18
  • Role-specific checklists for importers under Art. 19 and distributors under Art. 20
  • Assessment of a manufacturer role under Art. 21 and 22
  • Per-product assignment of roles, responsibilities, mandates and evidence
Platform foundation

Traceable processing and clear approvals.

The platform logs key processing and approval operations so that decisions and changes remain traceable.

Role-based permissions control access. AI-assisted suggestions remain marked as drafts until expert review and approval.

crAIready audit log as a recorded processing history
Demo view with synthetic sample data.

Your steps with crAIready

Create the product

The product, already assumed to be subject to the CRA, is captured in a structured way in the wizard.

Maintain the SBOM and supply chain

Components and dependencies are assigned to the product.

Handle vulnerabilities and risks

Assessments, measures and responsibilities remain linked to one another.

Prepare reports

Article 14 reporting channels and deadlines are documented separately.

Prepare documents and evidence

Approved product data form the basis for audit-ready documents.

Assign roles and approvals

Responsibilities, decisions and approvals remain traceable.

crAIready dashboard with key figures and Article 14 alerts as an overview
Demo view with synthetic sample data.
Operations

SaaS operated from Switzerland.

The core platform and the systems operated by codAIx itself run on our own infrastructure in Thayngen, Switzerland. Clearly identified external services are used only for the functions described in the privacy policy. crAIready is provided exclusively as SaaS and can be used without uploading your source code. Repository analysis is available as an optional add-on feature.

  • Single-tenant: isolated environment per customer
  • AI runs locally by default, is optional and can be switched off
  • Usable without uploading source code; repository analysis optional
  • Details on hosting and data flows on the security page

Ready for the next step?

Get an initial assessment with the free Quick Check – or start straight away with your CRA roadmap in crAIready.