CRA Evidence Platform
The compliance platform for EU manufacturers, importers, and distributors. SBOMs, VEX, vulnerability workflows, ENISA reporting, and technical documentation, all in one place.
Built to integrate with your CI/CD pipeline and cover the product lifecycle obligations under the EU Cyber Resilience Act.
Request a demo
Your SBOMs, validated and versioned
Drop in a CycloneDX or SPDX file. We validate it against BSI TR-03183 quality criteria, score its completeness, and keep audit-ready records for every product version.
Quality Score
Automatic scoring against BSI TR-03183 standard with improvement recommendations.
Dependency Tree
Visualize direct and transitive dependencies with circular dependency detection.
Version Diff
Compare SBOMs across versions. Track what changed and why.
License Check
Identify problematic license combinations across your components.
Fresh CVE intelligence, on a documented cadence
Continuous monitoring surfaces new CVEs as they are disclosed and ranks them by real-world exploit risk, so your team fixes what matters first.
Multiple intelligence feeds are correlated, then checked again through an independent scanner.
KEV and EPSS data surface the findings most likely to become real operational problems.
Automatic rescans keep production and staging versions current while the workflow stays focused on active risk.
Compliance documentation, ready when requested
The CRA requires technical documentation to be kept for at least 10 years, or for the support period if that is longer. We generate the Annex VII packages, certificates, and compliance reports so market surveillance requests don't land cold.
Technical File Export
One ZIP with everything: machine-readable manifest (JSON), SBOMs (CycloneDX/SPDX), attestations, compliance checklist, and attribution reports.
EU Declaration of Conformity
Generate EU DoC documents with proper formatting, versioning, and CE marking tracking.
Compliance Reports
PDF or HTML. Vulnerability summary, component inventory, quality scores, and remediation status in one report you can hand to auditors.
Security Data Sheet
Annex II security datasheet wizard. Draft it, validate it, publish it. Export as PDF, Markdown, or HTML.
Certificates
Certificate lifecycle: draft, issue, revoke. Immutable issued certificates with downloadable PDF generation.
Multi-language Documents
Generate documents in the official EU languages your markets need.
Annex I Readiness
Score your product against CRA Annex I security requirements. Track what you've met and what's missing.
Artifact Signing
Sigstore-based signing for SBOMs and artifacts. Keyless and key-based modes with signature verification for supply chain integrity.
Support Period Tracking
Define and track product support periods, with alerts as they approach end-of-support.
Track every ENISA deadline
The CRA has two reporting tracks with separate deadlines: vulnerabilities and severe incidents. We handle both with structured templates and countdown tracking.
Early Warning
Early warning within 24 hours of becoming aware of an actively exploited vulnerability, sent to the CSIRT coordinator and ENISA. CVE ID, affected products, and attack complexity assessment.
Detailed Notification
Technical analysis with remediation timeline, workarounds, and expanded impact assessment within 72 hours.
Final Report
Resolution confirmation with permanent fix details, deployment timeline, and lessons learned. 14 days after a corrective measure is available for vulnerabilities, one month after the incident notification for incidents.
Built for Products With Hardware Components
Machines, embedded systems, and IoT devices need more than software SBOMs. CRA Evidence supports the full hardware product lifecycle.
Manufacturer, Importer & Distributor Dashboards
The CRA puts different obligations on manufacturers, importers, and distributors. Each role gets its own workspace with the workflows that actually matter to them.
Product & Version Management
Products organized by CRA category: Default, Important Class I/Class II, Critical. Each version tracks its release state, environment, and retention tier.
Full Artifact Pipeline
Upload SBOM, HBOM, and VEX per version. Quality scoring and vulnerability scanning kick in automatically.
Vulnerability & Incident Management
CVE tracking, remediation workflows, ENISA notifications. The security dashboard ranks everything by EPSS score and flags CISA KEV entries.
Technical File Generation
Annex VII export packages your evidence into a ZIP: SBOMs, compliance checklists, attribution reports, and conformity declarations.
Customer Notifications
Vulnerability notification system for downstream customers. Multi-language templates with distribution list management.
Trust Badges
Embeddable compliance trust badges for your product pages. Link to public verification of your CRA compliance status.
Conformity Assessment Tracking
Track the right conformity assessment route for each product category, from self-assessment to notified-body certification.
Digital Product Passports
Generate dynamic, publicly accessible Digital Product Passports for each version. QR codes, JSON-LD, and PDF export — multi-language and machine-readable.
Multi-Language Documents
Generate technical documentation, compliance reports, and Digital Product Passports in 8 EU languages.
Importer Verification Workflow
Step-by-step checklist covering importer duties: CE marking check, Annex II review, importer ID on product, EU DoC collected, final sign-off.
Manufacturer Registry
Keep track of your manufacturers: contacts, EU representatives, CVD/CSAF metadata. Set how often each one needs reverification.
Stop-Ship Decisions
Reason to believe a product is not in conformity? Block it and record your justification. If it poses a significant cybersecurity risk, notify the manufacturer and the market surveillance authorities. Actions are tracked.
Reverification Triggers
New vulnerability found? Major update released? Review date coming up? You'll get an alert to reverify.
Clone Verifications
Reviewing a new version of the same product? Clone the previous verification. Checklist state and manufacturer data carry over.
Verification Dashboard
See where everything stands at a glance: how many products are verified, pending, blocked, or due for reverification.
Distributor Due Care Checklist
The distributor due-care checks, in one list: product ID and traceability, CE marking, EU declaration, manufacturer contacts, anomaly detection.
CE Evidence Upload
Upload your CE marking evidence: photos, scans, certificates. File type and size checks are built in, and everything is audit-logged.
Verification Certificates
Generate PDF certificates proving due care compliance. Includes distributor details, scope, date, and unique verification number.
Stop-Ship Actions
Something's wrong? Stop distribution. The justification is recorded, and authorities and manufacturers are notified.
Portfolio View
See all your verifications in one place. Filter by status, product, or completion date to find what needs attention.
Compliance Progress
Visual progress bars per product. You can see at a glance how far along each verification is and what's left.
Fits into your build pipeline
There's a CLI and a REST API. Upload SBOMs, trigger scans, and gate releases from CI. Works with GitHub Actions, GitLab CI, or anything that can run a shell command.
$ docker run --rm \
-e CRA_EVIDENCE_API_KEY="cra_xxx" \
-v /var/run/docker.sock:/var/run/docker.sock \
craevidence/cli:latest \
upload-sbom \
--product my-app \
--version 2.1.0 \
--image my-app:2.1.0 \
--scan --fail-on high
Upload successful!
Product my-app (created new)
Version 2.1.0 (created new)
Components 142
Quality Score 87%
Vulnerabilities
Critical 0
High 0
Medium 3
Low 1
Works with what you already use
Built to be trusted with your compliance data
Role-Based Access
Owner, Admin, Member, Viewer roles. Scoped API keys with fine-grained permissions.
SSO & MFA
SAML 2.0, Google & Microsoft OAuth, SCIM provisioning. TOTP multi-factor.
Encryption
AES-256 at rest, TLS 1.2 or higher in transit. Argon2id password hashing.
Multi-Tenancy
Tenant isolation by design: queries are scoped to the owning organisation.
Audit Logging
Full traceability of all actions. Queryable audit trail with CSV export.
Rate Limiting
Sliding window rate limiting on login, API, and upload endpoints.
Content Security
Strict CSP headers, CSRF protection, HTML sanitization, and HSTS.
Long-Term Retention
Tier-based long-term retention, aligned with the CRA documentation duties your products carry.
Not sure if the CRA applies to you?
Figure out your obligations before signing up for anything. These tools are free and don't require an account.
CRA Compliance Platform
See it in action: generate your first SBOM in minutes
14-day free trial. No credit card required. Cancel anytime.