Connect your repository
GitHub or GitLab. CRAcheck reads your manifests (package.json, requirements.txt, go.mod…) — nothing to install.
SBOM, technical documentation and EU declaration — generated and maintained automatically from your repo. CRAcheck prepares and documents your compliance; you review and sign. Without reading 200 pages of regulation.
No credit card · −50% for life for early sign-ups

The EU regulation that sets cybersecurity rules for almost every digital product. We explain the essentials in 2 minutes.
Understand the CRA →The regulation is 200 pages long. You ship code. CRAcheck turns your repository into a complete compliance file — in minutes.
Join early access →GitHub or GitLab. CRAcheck reads your manifests (package.json, requirements.txt, go.mod…) — nothing to install.
Your full software bill of materials in CycloneDX or SPDX format, kept up to date on every build.
The technical file (CRA Annex) and your EU declaration of conformity, pre-filled and ready to sign.
Your vulnerability handling policy, plus the ENISA reporting templates (24h / 72h / 14 days).
First, check in 1 minute whether the CRA applies to your product. Free, no sign-up.
Pick what best describes your main product.
Free · no sign-up · no data sent (the test runs in your browser)
Scope, risk categories and obligations taken from Regulation (EU) 2024/2847 — no guesswork, no AI making things up. Every verdict is grounded in the regulation.
Read the regulationSolo devs, app makers, IoT, commercial open source. Enterprise tools ignore you or charge €500/month. CRAcheck is built for you, at your scale.
See pricingWe prepare and document. We don't pretend to “certify you compliant”: you stay in control, with no false promise or legal jargon.
How it worksOnce your repo is connected, CRAcheck works continuously — even when you don't log in.
You don't have to think about it: we email you the moment something important happens for your compliance. Zero noise, just the essentials.
A board listing everything you must do, in order, with the real deadlines. No more guessing where to start.
A signed certificate + a public page your customers check themselves. Your compliance becomes a selling point.
EU declaration, technical documentation, SECURITY.md — generated from your repo and profile. You review, you sign.
The day a flaw is exploited, the assistant pre-fills your 24h / 72h / 14d reports. No panic.
The CRA score shows on your pull requests like a test that passes or fails. Compliance enters your workflow.
Every scan and document is timestamped in a journal. It's what a regulator or B2B customer will ask for.

€0 — but days of work
€500+ / month
€25 / month
* Doing it yourself is free in money, but costs days of work and a real risk of error.
OSV.dev is the reference open source vulnerability database, fed by Google, GitHub Security Advisories, PyPA, RustSec… On every push, your SBOM is cross-checked against it: a new CVE on one of your dependencies means a recalculated score + an email alert. No black-box scanner — a public, auditable source, cited in your technical documentation.
On September 11, 2026, vulnerability reporting becomes mandatory. The €25/month launch price runs until the end of 2026, then moves to €50. Early adopters keep €25/month — for life.
To get your score and start.
Your compliance generated, monitored and attested continuously — ready to show your customers.
Secure payment via Stripe · no commitment · cancel in one click
Your customers and prospects verify your attestation themselves on cracheck.eu/verify — signed certificate, README badge, real-time status.
A CRA consultant charges €3,000–5,000 for a report that's outdated the day it's delivered. CRAcheck keeps your compliance alive all year — for the price of one lunch a month.
Generally no: cloud-only SaaS falls under the NIS2 directive, not the CRA. The exception: if it ships a component installed on the customer side (agent, plugin, firmware) that's required to operate. The test settles your specific case.
Open source developed outside of a commercial activity is exempt. As soon as a company commercializes it or integrates it into a product it sells, that company carries the CRA responsibility.
No. CRAcheck provides information based on the official text to guide and prepare you. For formal validation, consult a professional.
Vulnerability reporting obligations apply from September 11, 2026. The main obligations (CE marking, EU declaration of conformity) from December 11, 2027.
Up to €15M or 2.5% of worldwide annual turnover for a breach of the essential cybersecurity requirements.
Yes: unlimited, no sign-up, and it runs in your browser. Only the document generator is paid (€25/month).
On September 11, 2026, reporting becomes mandatory. The €25/month launch price runs until the end of 2026, then €50. Go Pro now and keep €25/month for life.
Stripe payment · no commitment · cancel in one click
We tell you honestly what isn't there yet. The product improves every week — and your launch price stays locked for life.
Connect your GitLab projects, in addition to GitHub.
Your CRA score shown in every pull request, like a test that passes or fails.
Scan your Docker images and containers too, not just repositories.
Check your compliance locally and in your CI, straight from the command line.
Automatic scheduled generation and export of your SBOM.
Get your vulnerability and deadline alerts straight into Slack.
ShippedAsk questions and chat directly with our team through live chat.