The EU Cyber Resilience Act gives you 24 hours to report an actively exploited vulnerability in your product. CRA Alert watches your code, catches the moment it matters, and hands you a drafted report ready for your review, so you're not starting from a blank page.
Book a callNot sure the CRA even applies to you?A 2-minute quiz, based on the official regulation text.
Take the quiz →Most software companies with 10–100 people have never had to report anything to a regulator in 24 hours. From September 2026, that changes for almost every company selling digital products into the EU.
You connect your repository once. From then on, this runs in the background, and you only hear from us when it actually matters.
CRA Alert maps every component and library inside your product automatically, and keeps that map current every time your code changes.
Every component is checked continuously against the public vulnerability trackers. When one of your libraries is flagged as actively exploited, you find out first, not last.
CRA Alert drafts your report the moment the clock starts, with the technical details already filled in. You review it, you send it, and the 24 hours stop being a scramble.
If you have 10 to 100 people, sell software or a connected device into the EU, and don't have a dedicated compliance hire, this is built around exactly that gap.
SaaS products sold to EU customers, where the founder or CTO is currently the entire security team.
Hardware with firmware or embedded software, a category the CRA covers explicitly, and one most compliance tools were never built for.
Companies that have outgrown "we'll just keep an eye on it" but aren't ready to hire a full-time compliance lead.
No per-seat pricing. No surprise audit fees. One plan, for everything, billed monthly, cancel anytime.
We don't publish a rate card — the right number depends on how many products you're covering. Book a call and we'll walk you through it.
Book a callThree things, continuously: it maps every third-party library in your product, checks that list against public trackers for actively exploited vulnerabilities, and the moment one is found, starts your 24-hour and 72-hour countdown and drafts a report from the actual scan data. You review it and submit it yourself.
We build a bill of materials of every third-party library in your product, and check it continuously against the same public vulnerability trackers that CISA and ENISA use. The moment one of those libraries is confirmed as actively exploited, not just theoretically vulnerable, you get an alert. That distinction matters: most known vulnerabilities never get exploited, and this law is specifically about the ones that do.
A standard OAuth connection to GitHub or GitLab, the same one-click permission you'd grant any CI tool. No code changes, no migration, nothing to install. You choose which repositories to share, and you can revoke access at any time from your own GitHub or GitLab settings, not through us.
Companies with roughly 10 to 100 people who sell software or a connected device into the EU and don't have a dedicated security or compliance hire, so this usually falls on a founder or CTO who's already doing five other jobs.
Manufacturers of a "product with digital elements," meaning software or hardware with software, sold into the EU market, regardless of where the company itself is based. It generally does not cover pure cloud SaaS with no downloadable or embedded component; that tends to fall under separate rules like NIS2 instead. If your product is code someone installs, or hardware with firmware, you're very likely in scope. If it's a browser-only tool with nothing to install, it's worth checking with a lawyer.
Mostly, but there's one carve-out worth knowing. If you're under 50 employees and under €10M in turnover, you can't be fined specifically for missing the 24-hour early warning on its own. The 72-hour and 14-day deadlines are fully enforceable regardless of size, and once you cross 50 employees, the 24-hour window is too. CRA Alert tracks all three deadlines the same way for every company, so you don't have to keep track of which one currently has a safety net under it.
We ask for read-only access, the same category of permission you'd grant a CI tool. We extract a list of your dependencies, not your business logic, and we don't store a full copy of your source code. Full detail is on our Security page.
That's common, and it's a judgment call about your own business that we can't make for you. What we can do is scan whatever you connect, so the technical side is ready either way, while you (or a lawyer, for the genuinely unclear cases) settle the scope question.
You can. CRA Alert exists for teams that don't have the time to build and maintain that pipeline themselves, and adds the parts most people skip: a live countdown once something is flagged, a report already drafted, and a history you can point back to.
We're onboarding a limited number of companies at launch so we can do it properly. Leave your details and we'll reach out to schedule a short call — no pricing page, no sales sequence, just a conversation.