Q2 2026

Research & product design

Mapped the CRA reporting requirements in detail, evaluated the open-source vulnerability tooling landscape, and designed the core monitoring pipeline.

Q3 2026

Core product build

Repository connection, automated component mapping, and continuous actively-exploited-vulnerability matching built and tested against real codebases.

August 2026

Private beta with early companies

A small group of companies we've spoken with gets early access to test the full flow (connect, monitor, alert, report) before the reporting deadline hits.

September 2026

Public launch

CRA Alert opens to every company we've talked to, at founding-customer terms, launching the same month the CRA reporting duty itself becomes active.

Late 2026

Assisted submission (planned)

If ENISA's reporting platform opens up system-level access, or based on direct demand from customers, we plan to offer a done-for-you submission service as an add-on.

2027

Beyond CRA (exploring)

We're watching whether the same monitoring core is worth extending toward adjacent EU obligations, like NIS2. No commitment yet, and we'd rather do one thing well first.

Follow along from the start

Everyone we talk to hears about every milestone first.

Book a call