CRA Kit
Regulation (EU) 2024/2847 · Article 14 applies from 11 Sep 2026 ·

Ready for the Cyber Resilience Act in one afternoon.

Since 11 September 2026, a vulnerability in your product that is being actively exploited must be reported within 24 hours. CRA Kit tells you if you are in scope, scans your dependencies, and writes the 13 documents a small team needs.

npx crakit-cli .
CRA Kit, scan 2026-09-08 10:48 UTC
Sources: package-lock.json
Components: 5 (3 runtime)
Known vulnerabilities: 6 across 3 components
CISA KEV catalogue 2026-09-04: 1695 entries

None of your dependency vulnerabilities is listed
in the KEV catalogue (known active exploitation).

[HIGH] [email protected]  CVE-2021-23337  → 4.17.21
[MODERATE] [email protected]  CVE-2024-29041  → 4.19.2
[MODERATE] [email protected]  CVE-2020-28500  → 4.17.21
[LOW] [email protected]  CVE-2024-43796  → 4.20.0

SBOM written to sbom.cdx.json

Unedited output of crakit, 8 Sep 2026. The web scan gives the same result, in your browser.

04 · Reporting procedure, excerptArticle 14
T+0Awareness. Log the time in UTC.
T+24 hEarly warning on the ENISA platform.
T+72 hNotification. Start the fix.
Fix + 14 dFinal report.

No law firm. No platform. Your documents, your data.

A team of one to ten needs the text of the Regulation, its own answers, and an afternoon. Your lockfile never leaves your browser. No account, and nothing you type is stored on our side.

Two dates that matter

The Regulation covers software and connected hardware sold or monetised in the EU, including products already on the market (Article 69).

Three tools, in order

  1. Scope test free

    Eight questions. You get your product class, the conformity route and the dates, with the articles.

    In scope · Default product · Self-assessment (Module A) · Article 14 since 11 Sep 2026

    Run the scope test →

  2. SBOM & vulnerability scan free

    Drop a lockfile. CycloneDX SBOM, OSV.dev vulnerabilities, and the ones in the CISA KEV catalogue. A KEV hit means acting the same day.

    sbom.cdx.json · 6 vulnerabilities · 0 KEV · parsed in your browser

    Scan now →

  3. The kit

    13 documents written with your company, product and contacts. Markdown, HTML and print, English or French.

    CVD policy · security.txt · handling and reporting procedures · ENISA templates · support statement · Annex I, II, V and VII drafts · log

    Preview the kit →

What is in the kit

Each document names the article it implements, and is yours to edit. Three are shown in full before you pay.

DocumentImplementsYou
00 · Your 10-step plan by dateArticles 13, 14, 64Keep
01 · Scope & classification memoArticles 2, 3, Annex III/IVKeep
02 · Coordinated Vulnerability Disclosure policyAnnex I Part II (5)Publish
security.txt (RFC 9116)Annex I Part II (6)Publish
03 · Vulnerability handling procedureAnnex I Part II, Art. 13(6)–(8)Internal
04 · Reporting procedure, 24 h / 72 h / finalArticles 14, 16Internal
05 · Six ENISA templates + user noticeArticle 14(2), (4), (8)When needed
06 · Support period & updates statementArticle 13(8)–(9)Publish
07 · User information checklistAnnex IIShip
08 · Cybersecurity risk assessmentArticle 13(2)–(4), Annex ITechnical file
09 · Technical documentation skeletonArticle 31, Annex VIITechnical file
10 · EU declaration of conformity draftArticle 28, Annex V/VISign by 2027
11 · Vulnerability & release log (CSV)Article 13(7)Keep 10 years

CRA Kit, per product

€49 one-time · VAT at checkout
  • 13 documents, English or French
  • Regenerate as often as you like
  • Markdown, HTML, printable, as a ZIP
  • Licence key by e-mail, up to 5 browsers
  • Free template updates
Buy a licence key

Sold to professionals only. Unlocking requires you to confirm that you buy in the course of your business and to request immediate delivery (see terms). Not legal advice.

Compared with the alternatives

OptionCostFor a team of 1–10
Law firmQuotedOverkill for now
Word template packOne-offGeneric. You fill every page
SBOM platformSubscriptionBuilt for security teams
Free guidesFreeGood reading, nothing to publish
CRA Kit€49Written with your data, ready today

Full comparison →

Who is behind this

, founder

I built CRA Kit for my own products first. The engine is open source (npx crakit-cli), so you can check what leaves your machine: package names and versions, nothing else. [email protected].

Questions people ask

Is my SaaS in scope?

Pure SaaS and websites are not products with digital elements (Recital 12). Ship a client whose functions need your back end, and that back end comes into scope with it.

I publish open source. Am I concerned?

Free and open-source software supplied outside a commercial activity is out of scope (Recital 18). Monetisation brings it back in: paid support, dual licensing, a company selling around the project. Stewards have a lighter regime (Article 24).

What exactly happens on 11 September 2026?

Article 14 applies. Learn that a vulnerability in your product is being actively exploited, and you file an early warning in 24 hours, a notification in 72 hours and a final report, through the ENISA platform. Nothing to file if nothing happens, but it has to be ready before it does.

Is this legal advice? Does it make me compliant?

No and no. The kit writes documents from the text of the Regulation and your answers, with the articles so you can check each one. Compliance is what you do with them.

Where do my files and company data go?

Nowhere. The scanner reads your files in the browser and sends only package names and versions to OSV.dev. The form stays in your browser. The one database we run counts anonymous visits, with no cookie, no IP and nothing you type.

Can I get a refund?

You see three documents in full before paying. Sold to professionals, so the 14-day consumer withdrawal right does not apply. If something is broken, write to us and we fix it or refund you.