CRA Kit vs a lawyer's document pack vs doing it yourself
Four ways a small software vendor can get the Cyber Resilience Act paperwork done. What each one covers, what it costs and where it stops. We sell one of them, so read the last column with that in mind.
| Do it yourself from the free sources | Lawyer-made Word pack | Compliance platform (SaaS) | CRA Kit | |
|---|---|---|---|---|
| Cost | €0 + 1-3 days of reading | Several hundred euros, one-off (public prices seen in September 2026 range from a few hundred to about a thousand euros) | Quote-based; typically priced per product and per year, aimed at teams | Free tools. €79 one-off per product, VAT included |
| Tells you whether you are in scope | You decide after reading Articles 2-3 and the recitals | Sometimes a checklist | Usually assumed, since you are the customer | Yes. 8 questions, written indicative assessment with article references, free |
| SBOM & vulnerability status | Your own tooling (CycloneDX CLI, osv-scanner…) | No | Yes, continuous, often the core of the product | Yes. One run in the browser or in CI (npx crakit, MIT). No continuous monitoring |
| Actively-exploited flag (Article 14 trigger) | Check CISA KEV / vendor advisories yourself | No | Depends on the vendor | Yes. CISA KEV match on every scan |
| Documents personalised with your data | You write them | Templates with blanks to fill by hand | Generated, usually within a workflow you must keep updated | 13 documents generated from a form, EN or FR; regenerate as often as you like |
| Reporting procedure & ENISA-style templates | ENISA guidance is free; you assemble | Usually included | Usually included | Included (24 h / 72 h / final report, templates A-G) |
| Annex VII technical documentation | You draft the structure | Skeleton | Managed inside the platform | Skeleton pre-filled with your product, support dates and SBOM |
| Legal review / advice | None | Sometimes an hour with the firm | Rarely | No. Not legal advice. Every clause names its article, so a review is short |
| Ongoing monitoring & alerts | Your CI | No | Yes. This is where a platform earns its price | No, by design: there is no alert you could miss. Re-run the scan or the CLI in CI |
| Account, data stored | Nothing to store | Files on your disk | Your SBOM and product data on their servers | No account. Everything stays in your browser, apart from the licence key check |
| Best for | Teams with time and a reader who likes regulations | Companies that want a law firm's name on the templates | Vendors with many products, audits, or a security team | 1-20 person vendors who want the September duties and the 2027 paperwork started this week |
Third-party features and price ranges are as publicly displayed in September 2026. They are described generically on purpose, because they change. If we got yours wrong, write to and we will fix it.