A sample of what your dashboard looks like. Each row is one of your products; the number is how many third-party libraries we found inside it; the tag on the right tells you if any of them need attention right now.

payments-api — 214 libraries trackedAll clear
device-firmware-v3 — 88 libraries tracked1 under review
customer-portal — 341 libraries trackedAll clear
internal-billing — actively exploited library foundReport drafted, 21h 40m left
Step by step

What actually happens after you sign up

1

Connect your repository

A standard, one-click connection to GitHub or GitLab, the same kind of permission you'd grant any developer tool. No code changes required on your side.

2

We map what your product is built from

CRA Alert scans your codebase and builds a complete, current inventory of every library and component inside it, a "bill of materials" for your software. This updates automatically every time your code changes, not just once.

3

Every component is checked, continuously

That inventory is checked against the public vulnerability trackers that security researchers and CISA/ENISA use, around the clock, not on a schedule you have to remember.

4

The moment something is flagged as actively exploited

You get an alert immediately, with a visible countdown to your 24-hour and 72-hour deadlines, so there's no ambiguity about how much time is left.

5

A report is already drafted for you

The affected component, version, and technical detail are pulled automatically into a pre-filled report. You review it for accuracy, adjust anything specific to your product, and it's ready to submit.

6

You keep a full history

Every scan, every alert, and every report is logged with a timestamp, a running record you can point to if a regulator or a customer ever asks how you handle this.

Good to know

What CRA Alert is, and isn't

What we do

We monitor your product's components against known, actively exploited vulnerabilities, keep your compliance-relevant documentation current, and draft your reports for your review before your deadline runs out. You always review and submit the final version yourself.

What we don't do yet

The EU's own reporting portal does not currently offer a system-to-system connection. Submissions are entered manually. CRA Alert prepares everything for you; the final submission is a step you complete by hand until that changes. We're evaluating a done-for-you submission add-on based on demand, see our roadmap.

We don't replace a lawyer

Whether a specific product of yours falls under the Cyber Resilience Act is a decision you make, based on your own knowledge of your business. CRA Alert scans whatever you connect; it doesn't make that legal call for you.

We work quietly, most of the time

For most companies, most months will have nothing to report. That's the point. CRA Alert is built to be quiet until the one time it genuinely matters.

We monitor your dependencies, not your own code

Almost every product today is built on dozens or hundreds of third-party libraries, and that's exactly where actively exploited vulnerabilities tend to show up. We track those libraries continuously and tell you the moment one of them is flagged, something that's genuinely hard to keep up with by hand. A vulnerability inside code your own team wrote isn't something we'd catch, that needs a code review or SAST tool, not a dependency scan.

See it before September

Book a call and we'll walk you through it directly.

Book a call