If you sell software or a connected device in the EU — an app, a router, a sensor, a dev tool — the Cyber Resilience Act applies to you, wherever your company is based. Big manufacturers have compliance departments. CRA Label is for everyone else.
Get early access Free applicability check · no card requiredVerified against the regulation text and the European Commission — not a vendor's scare chart. Maximum fines: €15,000,000 or 2.5% of worldwide turnover.
Connect your repository or upload your build. Get the paperwork the law asks for — generated, not templated.
Scan your code and dependencies into a CycloneDX and SPDX software bill of materials — the "ingredients label" the regulation requires. Machine-readable plus a human-readable report.
The required technical file, pre-filled from your scan and a set of guided questions. Export and keep it current as your product changes.
When something goes wrong, a guided workflow drafts your early warning in minutes using the official reporting fields — with the 24h/72h/14-day clocks running where you can see them.
Every report is signed with post-quantum ML-DSA signatures (FIPS 204), so your compliance evidence is tamper-evident and provable years later — when an authority asks.
The honest scope — the regulation doesn't cover everyone, and we won't pretend it does.
In scope: desktop and mobile software, dev tools, firmware, IoT and connected hardware, embedded systems — any "product with digital elements" sold into the EU, from any country.
Out of scope: pure SaaS with no shipped product component (that's NIS2 territory), and non-monetized open source. If that's you, you likely don't need us — our free applicability check will tell you either way.
We're onboarding the first 50 companies before the September reporting deadline. The price below is locked for as long as you stay subscribed.