CRAdarCheck

EU Cyber Resilience Act — Regulation (EU) 2024/2847

The EU just made your software a regulated product.

Apps, games, plugins, dev tools, devices — if EU users can get them, the Cyber Resilience Act applies to you. Fines up to €15M or 2.5% of turnover. CRAdar tells you what applies and automates the rest: SBOMs, vulnerability monitoring, ENISA reporting, CE paperwork.

No signup. No credit card. Instant verdict + fix list.

Until 24h incident reporting becomes law

11 September 2026

Until full compliance + CE marking required

11 December 2027

If you ship any of these to EU users, you're a “manufacturer” now

iOS & Android appsDesktop softwareGames (Steam, mobile, console)WordPress pluginsBrowser extensionsCLI & dev toolsCommercial SDKsIoT devices & firmwareSelf-hosted software

It doesn't matter where your company is. It doesn't matter that you're a solo developer. The law names you — not Apple, not Google, not Steam — as the party responsible. Check your product type →

From “is this even my problem?” to audit-ready

01 — Check

Free Risk Check

Answer ~10 questions. Get your scope verdict, risk class, readiness score 0–100 and a prioritized fix list. Share it with your team.

02 — Fix

Free tools for every gap

Scan your SBOM against real vulnerability data, generate your CVD policy, security.txt and Declaration of Conformity. Each fix moves your score up.

03 — Autopilot

Stay compliant automatically

Connect your repo. SBOM per release, continuous CVE watch, reporting workflow on standby, paperwork always current. From $49/month.

Everything the law asks. Nothing enterprise vendors charge for.

SBOM on every release

Connect your repo and get a CycloneDX SBOM generated per release, stored with a 10-year audit trail — the exact artifact Annex I Part II demands.

Continuous vulnerability watch

Your SBOMs are checked against the OSV database continuously. Known exploited vulnerability in a dependency? You know before the 24-hour clock starts.

ENISA reporting workflow

When something happens: guided 24h early warning → 72h notification → final report, with deadline timers and pre-filled drafts for the Single Reporting Platform.

CE paperwork, generated

Technical documentation file, EU Declaration of Conformity, CVD policy and security.txt — generated from your answers, kept up to date, export any time.

Support-period tracking

Declare support periods per product and version. We track EOL dates and remind you before an unpatched version becomes a liability.

Built for small teams

No sales calls, no 'contact us' pricing, no compliance jargon. Self-serve, from $49/month per product. Cancel any time.

Does the CRA apply to your product?

Straight answers per product type — scope, risk class, obligations, pitfalls.

All 33 product types →

Questions everyone asks

Does the CRA really apply to me? I'm outside the EU.

If EU users can commercially obtain your software (app stores count), the CRA applies to that product regardless of where you are based. The obligations attach to placing the product on the EU market, not to your company's location.

I run a pure SaaS. Am I exempt?

Mostly — pure cloud services fall under NIS2 instead. But any installable component you ship (mobile app, desktop client, CLI, agent, self-hosted version) is in scope on its own. Run the free Risk Check to see where your product lands.

What happens if I ignore it?

Fines up to €15M or 2.5% of global turnover, market-surveillance orders to withdraw the product from the EU market, and public naming. Enforcement starts with the reporting obligations on 11 September 2026 and applies fully from 11 December 2027.

Is this legal advice?

No. We give you the tooling and plain-language guidance to do the engineering side of compliance. For legal questions with real consequences, involve a professional — we tell you exactly when that's the case.

My product is open source. Do I need this?

Non-commercial open source is excluded from the CRA. But if you dual-license, sell support, run a paid cloud or ship an open-core product, you're likely in scope. The Risk Check covers exactly these edge cases.

Three minutes. Straight verdict.

Find out if the CRA applies to you, what class your product is, and exactly what to fix first — before the deadlines decide for you.

Or get the compliance autopilot at launch: