We're looking for 10 vendors to test CRAcheck on real software
CRAcheck helps small teams prepare their Cyber Resilience Act compliance from a GitHub repository. You test the Pro version for free on your project; in exchange, we ask for honest feedback in a 15-minute conversation.
3 months of free Pro · no commitment · ~30–45 min of testing · reply within 48h

A team that supports you, not just a tool
The Cyber Resilience Act puts heavy obligations on vendors who have neither a lawyer nor a CISO. We're building the tool we wish we'd had: clear, concrete, starting from your repository rather than from the legal text.
During the tester program, you're never left alone with a form. We support you from the first scan through to your generated documents, and every piece of feedback you give goes straight into the roadmap.

Hands-on support
We guide you from connecting the repo to generating your documents. Ask a question, get an answer — no ticket lost in the void.
Reply within 2 business days
Every application is read and gets an answer, whether it's a yes or a no. No radio silence.
Your feedback comes first
Fixes and requests raised by testers are handled before the rest of the roadmap.
CRAcheck analyses dependencies from these ecosystems
What CRAcheck does today
So you know exactly what you're signing up for before applying — here's the current scope of the product.
CRA score & action plan
A clear readiness score, recomputed on every push, with actions ranked by priority.
CycloneDX SBOM
Your dependency inventory in the standard format, exportable, required by the CRA.
Vulnerabilities & alerts
Detection via OSV.dev (GitHub Advisories, PyPA, RustSec…) and email alerts when a critical flaw appears.
Editable CRA documents
EU declaration, technical documentation (Annex VII), SECURITY.md — pre-filled from your repo, completable in-app.
ENISA reporting
The full Art. 14 flow: compliant 24h / 72h / 14d PDFs, tracked deadlines, timestamped submissions.
Public attestation
A signed summary + public verification page to share. This is not a regulatory certification.
CRA file in one zip
All your documents organised and downloadable in one click, with instructions.
Evidence journal
Every scan, document and report timestamped — what a B2B customer or an audit will ask for.
CRA calendar
The regulation's deadlines (Sep 11, 2026, Dec 11, 2027) and where you stand against them.
What we'll ask of you
- 1Connect a GitHub repository (read-only).
- 2Run the analysis and look at your CRA score.
- 3Review the SBOM and the suggested actions.
- 4Generate at least one document.
- 5Give us 15 minutes of feedback (call or written).
No public post or testimonial is required. If you like the tool and agree to leave one, great — but it's not a condition.
What you receive
- Free Pro access for 3 months — activated with a promo code
- Direct support from our team during the test
- Your CRA documents generated for your own project
- Priority on the fixes and requests you raise
- If you continue afterwards: the −50% launch price kept, with no obligation
Pro access is activated with a promo code: nothing is charged to you during the 3 months of the program. No commitment, cancel at any time.
What you'll be able to test
You'll test the current version of CRAcheck on a real repository, not a mock-up.
- Dependency analysis of your repository
- SBOM in CycloneDX format
- Known-vulnerability detection (OSV.dev)
- CRA action plan and score
- EU declaration, technical documentation, SECURITY.md
- ENISA reporting flow (Art. 14 PDFs)
- Public attestation — this is not a regulatory certification

Your repository stays under your control
- Read-only repo access, only the repos you choose
- Your source code is neither read nor stored — only dependency manifests are analysed
- Application data hosted in the European Union
- Permissions revocable and data deletable at any time
The program is a fit if
- You develop or publish a software product (app, SaaS with a product component, SDK, IoT…)
- You sell it — or plan to sell it — in the EU
- You can test on a real GitHub repository
- You're available for 15 minutes of feedback
For the test to be useful, you need to be able to run CRAcheck on a real repository. We simply check the profile of each application.
Apply to the program
2 minutes. We read every application and reply to everyone within 2 business days — whether it's a yes or a no.
- Free Pro access for 3 months, no commitment
- Guaranteed reply within 2 business days
- Your info is only used to contact you back
Who are you?
So I know who I'm talking to and can reply.
Your product
To check the CRA really applies to you — that's the only criterion.
Your test
What you expect from the test — so I can support you usefully.
Reply within 2 business days · 3 months of free Pro for selected testers · your info is only used to contact you




