Ready for the Cyber Resilience Act in one afternoon.
Since 11 September 2026, a vulnerability in your product that is being actively exploited must be reported within 24 hours. CRA Kit tells you if you are in scope, scans your dependencies, and writes the 13 documents a small team needs.
npx crakit-cli . CRA Kit, scan 2026-09-08 10:48 UTC Sources: package-lock.json Components: 5 (3 runtime) Known vulnerabilities: 6 across 3 components CISA KEV catalogue 2026-09-04: 1695 entries None of your dependency vulnerabilities is listed in the KEV catalogue (known active exploitation). [HIGH] [email protected] CVE-2021-23337 → 4.17.21 [MODERATE] [email protected] CVE-2024-29041 → 4.19.2 [MODERATE] [email protected] CVE-2020-28500 → 4.17.21 [LOW] [email protected] CVE-2024-43796 → 4.20.0 SBOM written to sbom.cdx.json
Unedited output of crakit, 8 Sep 2026. The web scan gives the same result, in your browser.
| T+0 | Awareness. Log the time in UTC. |
| T+24 h | Early warning on the ENISA platform. |
| T+72 h | Notification. Start the fix. |
| Fix + 14 d | Final report. |
No law firm. No platform. Your documents, your data.
A team of one to ten needs the text of the Regulation, its own answers, and an afternoon. Your lockfile never leaves your browser. No account, and nothing you type is stored on our side.
Two dates that matter
The Regulation covers software and connected hardware sold or monetised in the EU, including products already on the market (Article 69).
- 11 Sep 2026Article 14
Reporting
Exploited vulnerabilities and severe incidents go to your national CSIRT and ENISA. 24 h, 72 h, then a final report. You inform affected users too.
- 11 Dec 2027Articles 13, 28, 31
Everything else
Security requirements, SBOM, technical documentation, declaration of conformity, CE marking, five years of free updates.
Three tools, in order
-
Scope test free
Eight questions. You get your product class, the conformity route and the dates, with the articles.
In scope · Default product · Self-assessment (Module A) · Article 14 since 11 Sep 2026 -
SBOM & vulnerability scan free
Drop a lockfile. CycloneDX SBOM, OSV.dev vulnerabilities, and the ones in the CISA KEV catalogue. A KEV hit means acting the same day.
sbom.cdx.json · 6 vulnerabilities · 0 KEV · parsed in your browser -
The kit €49 per product
13 documents written with your company, product and contacts. Markdown, HTML and print, English or French.
CVD policy · security.txt · handling and reporting procedures · ENISA templates · support statement · Annex I, II, V and VII drafts · log
What is in the kit
Each document names the article it implements, and is yours to edit. Three are shown in full before you pay.
| Document | Implements | You |
|---|---|---|
| 00 · Your 10-step plan by date | Articles 13, 14, 64 | Keep |
| 01 · Scope & classification memo | Articles 2, 3, Annex III/IV | Keep |
| 02 · Coordinated Vulnerability Disclosure policy | Annex I Part II (5) | Publish |
| security.txt (RFC 9116) | Annex I Part II (6) | Publish |
| 03 · Vulnerability handling procedure | Annex I Part II, Art. 13(6)–(8) | Internal |
| 04 · Reporting procedure, 24 h / 72 h / final | Articles 14, 16 | Internal |
| 05 · Six ENISA templates + user notice | Article 14(2), (4), (8) | When needed |
| 06 · Support period & updates statement | Article 13(8)–(9) | Publish |
| 07 · User information checklist | Annex II | Ship |
| 08 · Cybersecurity risk assessment | Article 13(2)–(4), Annex I | Technical file |
| 09 · Technical documentation skeleton | Article 31, Annex VII | Technical file |
| 10 · EU declaration of conformity draft | Article 28, Annex V/VI | Sign by 2027 |
| 11 · Vulnerability & release log (CSV) | Article 13(7) | Keep 10 years |
CRA Kit, per product
- 13 documents, English or French
- Regenerate as often as you like
- Markdown, HTML, printable, as a ZIP
- Licence key by e-mail, up to 5 browsers
- Free template updates
Sold to professionals only. Unlocking requires you to confirm that you buy in the course of your business and to request immediate delivery (see terms). Not legal advice.
Compared with the alternatives
| Option | Cost | For a team of 1–10 |
|---|---|---|
| Law firm | Quoted | Overkill for now |
| Word template pack | One-off | Generic. You fill every page |
| SBOM platform | Subscription | Built for security teams |
| Free guides | Free | Good reading, nothing to publish |
| CRA Kit | €49 | Written with your data, ready today |
Who is behind this
Questions people ask
Is my SaaS in scope?
Pure SaaS and websites are not products with digital elements (Recital 12). Ship a client whose functions need your back end, and that back end comes into scope with it.
I publish open source. Am I concerned?
Free and open-source software supplied outside a commercial activity is out of scope (Recital 18). Monetisation brings it back in: paid support, dual licensing, a company selling around the project. Stewards have a lighter regime (Article 24).
What exactly happens on 11 September 2026?
Article 14 applies. Learn that a vulnerability in your product is being actively exploited, and you file an early warning in 24 hours, a notification in 72 hours and a final report, through the ENISA platform. Nothing to file if nothing happens, but it has to be ready before it does.
Is this legal advice? Does it make me compliant?
No and no. The kit writes documents from the text of the Regulation and your answers, with the articles so you can check each one. Compliance is what you do with them.
Where do my files and company data go?
Nowhere. The scanner reads your files in the browser and sends only package names and versions to OSV.dev. The form stays in your browser. The one database we run counts anonymous visits, with no cookie, no IP and nothing you type.
Can I get a refund?
You see three documents in full before paying. Sold to professionals, so the 14-day consumer withdrawal right does not apply. If something is broken, write to us and we fix it or refund you.