Beta We closed the beta. Join the waitlist to know when we reopen again.

If you'd like priority access, please contact us.

CRA Evidence is a comprehensive EU Cyber Resilience Act (CRA) compliance platform that helps manufacturers, importers, and distributors achieve compliance before the December 2027 deadline. Key features include: SBOM management (CycloneDX, SPDX formats), HBOM management, vulnerability scanning with CVE monitoring and EPSS prioritization, technical file generation for CE marking, ENISA incident reporting tools, and multi-language support across 12 EU and Asian languages. CRA Evidence helps teams assess CRA readiness and maintain audit-ready compliance evidence.

CRA Evidence: EU Cyber Resilience Act Compliance Platform

We help manufacturers, importers, and distributors put verifiable proof of conformity behind every product they ship.

Generate your EU Declaration of Conformity, risk assessment, and technical file for every release
Run compliance checks automatically inside your CI/CD pipeline
Catch new CVEs as they emerge with our Vulnerability Knowledge Base (VKB)
Generate VEX statements automatically, or author them yourself
CycloneDX 1.6 Supported
SPDX 2.2.1+ Supported
TR-03183 BSI TR-03183 checks
Long-term Document Retention

Built on open, authoritative vulnerability intelligence

  • CVE List
  • OSV.dev
  • CISA KEV
  • EPSS · FIRST.org
  • ENISA EUVD
Key dates you need to know

CRA Compliance Timeline

11 September 2026
Within 24 hours

Vulnerability reporting via the ENISA Single Reporting Platform begins for all manufacturers. Report actively exploited vulnerabilities within 24 hours.

11 December 2027
Full enforcement

Full CRA enforcement for new products. Products already on the market before this date are grandfathered unless substantially modified.

10+ Years
Documentation retention

Documentation retention period. Technical files must be kept for at least 10 years, or for the support period if that is longer.

Does the CRA Apply to Your Product?

Answer 6 simple questions to find out if your product falls under the EU Cyber Resilience Act scope. Get your result in under 2 minutes.

6 questions About 2 minutes No signup
Check Now
The platform

Everything You Need: SBOMs, Vulnerability Scanning, Automated VEX & Technical Documentation

One platform to manage your entire Cyber Resilience Act readiness workflow, from SBOMs to Digital Product Passports

Automated SBOM Validation

Upload and validate CycloneDX artifacts (SBOM, HBOM, VEX). Track software and hardware components, licenses, and vulnerabilities across all your products.

CRA Technical File Generation

Manage all CRA-required documents: risk assessments, EU Declaration of Conformity, user documentation, and vulnerability policies.

Vulnerability Tracking

Vulnerability Knowledge Base syncs the CVE List (cvelistV5) hourly and OSV.dev and CISA KEV daily, with EPSS exploit probability scoring. Auto-generate VEX statements from triage decisions. Track remediation and ENISA reporting deadlines per version.

Product Versioning

Organize products and versions with full traceability. Link artifacts (SBOM, HBOM, VEX), documents, and vulnerabilities to specific releases.

Audit-Ready Export Packages

Generate audit-ready technical file bundles with all required documentation. Ready for regulators and market surveillance.

Compliance in Your CI/CD Pipeline

API-first design with support for automated artifact uploads from your build pipeline. GitHub Actions, GitLab CI, and more.

Role-Specific Workflows

Tailored dashboards for manufacturers, importers, and distributors. Each role gets the workflows that matter to them.

Automated Vulnerability Scanning

Scan SBOMs against our Vulnerability Knowledge Base covering the CVE List (cvelistV5), OSV.dev, and CISA KEV. EPSS risk scoring helps you prioritize what to fix first.

API & Webhooks

REST API and webhook notifications for all platform events. Connect with Jira, Slack, GitHub, or any tool in your workflow.

Digital Product Passports

Generate dynamic, publicly accessible Digital Product Passports for software and hardware products. QR codes for physical labeling, JSON-LD, and PDF export, multi-language and machine-readable.

Conformity Assessment

Score your product against CRA Annex I security requirements. Track what you've met, what's missing, and generate your EU Declaration of Conformity.

Multi-Language Documents

Generate technical documentation, compliance reports, and Digital Product Passports in the official EU languages your markets need.

Workflow

How It Works

Get audit-ready before December 2027

1
Set Up Your Organization

Create your workspace, invite your team, classify products by CRA category (Default, Important Class I/Class II, Critical).

2
Upload Artifacts & Evidence

SBOMs, technical documents, risk assessments, and compliance evidence per product version. Auto-validated against TR-03183.

3
Scan & Monitor Vulnerabilities

Own Vulnerability Knowledge Base syncing the CVE List (cvelistV5) hourly and OSV.dev and CISA KEV daily. Production versions automatically rescanned when new CVEs appear.

4
Generate CRA Audit-Ready Documentation

CRA technical documentation, EU Declarations of Conformity, compliance reports, and ENISA notification templates.

5
Stay Audit-Ready

Durable retention, full audit trails, and exportable evidence packages for market surveillance authorities.

1
Register Your Supply Chain

Add manufacturers and their products. Track contacts, EU representatives, and compliance metadata.

2
Verify Manufacturer Compliance

Step-by-step importer checklist: CE marking, EU DoC, user-information review, importer ID on product, final sign-off.

3
Monitor & Act

Reverification triggers when new vulnerabilities appear or review dates approach. Stop-ship decisions when needed.

1
Add Products to Your Portfolio

Register the connected products you distribute. Upload CE marking evidence and manufacturer documentation.

2
Complete Due Care Checks

Distributor checklist: product ID, CE marking, EU declaration, manufacturer contacts, anomaly detection.

3
Generate Verification Certificates

PDF records documenting due-care checks, with unique verification numbers and audit logging.

Implementation services

Need someone to lead it with your team?

Three fixed-scope engagements led by infrastructure engineers. Tool-agnostic, scoped on a 30-minute roadmap call.

Get Started

Ready to Get CRA-Ready?

Join companies already preparing for CRA 2027. Start your free trial today.

Start Free Trial