Reporting duty starts 11 September 2026

You have 24 hours to report it.
Most small teams have no one watching for the moment it starts.

The EU Cyber Resilience Act gives you 24 hours to report an actively exploited vulnerability in your product. CRA Alert watches your code, catches the moment it matters, and hands you a drafted report ready for your review, so you're not starting from a blank page.

Book a call

Not sure the CRA even applies to you?A 2-minute quiz, based on the official regulation text.

Take the quiz →
The problem

A law with real teeth, and a deadline no one is ready for

Most software companies with 10–100 people have never had to report anything to a regulator in 24 hours. From September 2026, that changes for almost every company selling digital products into the EU.

24h
to send an early warning once you know
2.5%
of global turnover, the ceiling for the most serious violations
245
actively exploited vulnerabilities added to public trackers in 2025
1
person usually responsible for noticing, in a small team
How CRA Alert helps

Three things, done continuously

You connect your repository once. From then on, this runs in the background, and you only hear from us when it actually matters.

Step 1

Know what you're made of

CRA Alert maps every component and library inside your product automatically, and keeps that map current every time your code changes.

Step 2

Watch for the moment it matters

Every component is checked continuously against the public vulnerability trackers. When one of your libraries is flagged as actively exploited, you find out first, not last.

Step 3

Never write a report from scratch

CRA Alert drafts your report the moment the clock starts, with the technical details already filled in. You review it, you send it, and the 24 hours stop being a scramble.

Who it's for

Built for the team without a security department

If you have 10 to 100 people, sell software or a connected device into the EU, and don't have a dedicated compliance hire, this is built around exactly that gap.

Software startups

SaaS products sold to EU customers, where the founder or CTO is currently the entire security team.

IoT & connected devices

Hardware with firmware or embedded software, a category the CRA covers explicitly, and one most compliance tools were never built for.

Growing engineering teams

Companies that have outgrown "we'll just keep an eye on it" but aren't ready to hire a full-time compliance lead.

Pricing

One plan, everything included

No per-seat pricing. No surprise audit fees. One plan, for everything, billed monthly, cancel anytime.

Founding-customer terms for the first 100 companies
  • Unlimited repositories connected
  • Continuous vulnerability monitoring
  • 24h / 72h alert timers
  • Pre-filled report drafts
  • Guided onboarding included

We don't publish a rate card — the right number depends on how many products you're covering. Book a call and we'll walk you through it.

Book a call
Before you ask

A few honest answers

What does CRA Alert actually do?

Three things, continuously: it maps every third-party library in your product, checks that list against public trackers for actively exploited vulnerabilities, and the moment one is found, starts your 24-hour and 72-hour countdown and drafts a report from the actual scan data. You review it and submit it yourself.

How do you monitor libraries, exactly?

We build a bill of materials of every third-party library in your product, and check it continuously against the same public vulnerability trackers that CISA and ENISA use. The moment one of those libraries is confirmed as actively exploited, not just theoretically vulnerable, you get an alert. That distinction matters: most known vulnerabilities never get exploited, and this law is specifically about the ones that do.

How do I connect my code?

A standard OAuth connection to GitHub or GitLab, the same one-click permission you'd grant any CI tool. No code changes, no migration, nothing to install. You choose which repositories to share, and you can revoke access at any time from your own GitHub or GitLab settings, not through us.

Who is this for?

Companies with roughly 10 to 100 people who sell software or a connected device into the EU and don't have a dedicated security or compliance hire, so this usually falls on a founder or CTO who's already doing five other jobs.

Who exactly does the CRA reporting duty apply to?

Manufacturers of a "product with digital elements," meaning software or hardware with software, sold into the EU market, regardless of where the company itself is based. It generally does not cover pure cloud SaaS with no downloadable or embedded component; that tends to fall under separate rules like NIS2 instead. If your product is code someone installs, or hardware with firmware, you're very likely in scope. If it's a browser-only tool with nothing to install, it's worth checking with a lawyer.

Does the 24-hour deadline apply the same way to every company size?

Mostly, but there's one carve-out worth knowing. If you're under 50 employees and under €10M in turnover, you can't be fined specifically for missing the 24-hour early warning on its own. The 72-hour and 14-day deadlines are fully enforceable regardless of size, and once you cross 50 employees, the 24-hour window is too. CRA Alert tracks all three deadlines the same way for every company, so you don't have to keep track of which one currently has a safety net under it.

Is my code safe if I connect a repository?

We ask for read-only access, the same category of permission you'd grant a CI tool. We extract a list of your dependencies, not your business logic, and we don't store a full copy of your source code. Full detail is on our Security page.

What if I'm not sure whether the Cyber Resilience Act applies to me?

That's common, and it's a judgment call about your own business that we can't make for you. What we can do is scan whatever you connect, so the technical side is ready either way, while you (or a lawyer, for the genuinely unclear cases) settle the scope question.

Why not just run the open-source tools myself?

You can. CRA Alert exists for teams that don't have the time to build and maintain that pipeline themselves, and adds the parts most people skip: a live countdown once something is flagged, a report already drafted, and a history you can point back to.

Launching September 2026

Talk to us before the deadline does

We're onboarding a limited number of companies at launch so we can do it properly. Leave your details and we'll reach out to schedule a short call — no pricing page, no sales sequence, just a conversation.

Thanks — we'll reach out within a day or two to schedule a call.
Something went wrong. Try again, or email us directly.