The CRA's 24-hour reporting duty has applied since 11 September 2026. Check whether it reaches you

Software and SaaSAll of the EU

The certificate your customers ask for. And the CRA file for what you ship.

ISO 27001 for the security questionnaires, the Cyber Resilience Act for software you place on the market, and ISO 42001 if you build with AI. One system runs them together, with the evidence read from your tools every day.

Example data

Your clocks

What applies, and from when

  1. CRA reporting

    24 hours to send an early warning about an actively exploited vulnerability, for products already on the market too.

  2. The CRA in full

    Essential requirements, conformity assessment and CE marking for products placed on the market from this date.

The frameworks

Each one, and where to read about it

Two ways to start

Run it all, or buy one file

The platform

€249/mo · excl. VAT

ISO 27001, Cyber Resilience Act and ISO 42001 in one system, evidence read from your tools every day, every framework and every feature included.

  • Every framework and every feature
  • Unlimited users, auditors included
  • 14 days free, no card, no sales call

CRA technical file

List price €3,000

€2,000 once, excl. VAT
33% off the list price, introductory, until 31 Oct 2026

The Annex VII technical documentation for one product: 11 controlled documents, drafted the moment you pay. No subscription needed.

This page in:DeutschFrançaisNederlandsEspañolDansk