You don't manage this day to day. You connect your repository once, and CRA Alert takes it from there.
A sample of what your dashboard looks like. Each row is one of your products; the number is how many third-party libraries we found inside it; the tag on the right tells you if any of them need attention right now.
A standard, one-click connection to GitHub or GitLab, the same kind of permission you'd grant any developer tool. No code changes required on your side.
CRA Alert scans your codebase and builds a complete, current inventory of every library and component inside it, a "bill of materials" for your software. This updates automatically every time your code changes, not just once.
That inventory is checked against the public vulnerability trackers that security researchers and CISA/ENISA use, around the clock, not on a schedule you have to remember.
You get an alert immediately, with a visible countdown to your 24-hour and 72-hour deadlines, so there's no ambiguity about how much time is left.
The affected component, version, and technical detail are pulled automatically into a pre-filled report. You review it for accuracy, adjust anything specific to your product, and it's ready to submit.
Every scan, every alert, and every report is logged with a timestamp, a running record you can point to if a regulator or a customer ever asks how you handle this.
We monitor your product's components against known, actively exploited vulnerabilities, keep your compliance-relevant documentation current, and draft your reports for your review before your deadline runs out. You always review and submit the final version yourself.
The EU's own reporting portal does not currently offer a system-to-system connection. Submissions are entered manually. CRA Alert prepares everything for you; the final submission is a step you complete by hand until that changes. We're evaluating a done-for-you submission add-on based on demand, see our roadmap.
Whether a specific product of yours falls under the Cyber Resilience Act is a decision you make, based on your own knowledge of your business. CRA Alert scans whatever you connect; it doesn't make that legal call for you.
For most companies, most months will have nothing to report. That's the point. CRA Alert is built to be quiet until the one time it genuinely matters.
Almost every product today is built on dozens or hundreds of third-party libraries, and that's exactly where actively exploited vulnerabilities tend to show up. We track those libraries continuously and tell you the moment one of them is flagged, something that's genuinely hard to keep up with by hand. A vulnerability inside code your own team wrote isn't something we'd catch, that needs a code review or SAST tool, not a dependency scan.