The CRA conformity workspace, from classification to CE marking.
Classify each product under Annex III and IV, run the risk assessment, close the Annex I gaps, and draft your technical file and EU Declaration of Conformity. Vulnerability handling and Article 14 authority reporting run in the same workspace. Fines for breaching the essential obligations reach €15 million or 2.5% of worldwide turnover.
New accounts include 14 days of the Compliance plan. The disclosure portal stays free.
Or run the free CRA exposure scan on your domainThe price of doing nothing is written into the law.
Up to €15 million or 2.5% of worldwide turnover
Breaching the essential cybersecurity obligations carries administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher (Art. 64(2)).
Products can be restricted or pulled from the EU market
Market surveillance authorities can require corrective action, restrict availability, or prohibit a non-compliant product on the EU market.
Enterprise buyers ask for CRA conformity evidence
Procurement and security teams increasingly ask for a documented CRA position, a chosen conformity assessment route, and a published disclosure process before they sign.
The Compliance plan takes you through the self-assessment. Report intake and acknowledgment stay free. Here is what each plan covers.
From first login to a documented CRA position.
Classify your products
Add a product and answer the Annex III and IV classification questions. The engine determines the product class and your Article 32 conformity assessment route.
Assess and close the gaps
Run the STRIDE risk assessment, work through the 22 Annex I essential requirements, and follow the gap analysis to remediation guidance for every open item.
Produce the evidence
Draft the technical documentation and EU Declaration of Conformity, then publish your disclosure portal so vulnerability reports and Article 14 notifications run through one system.
One workspace per product, from classification to conformity.
Every product gets its own workspace. The classification drives the Article 32 route, the risk assessment feeds the Annex I checklist, and gap analysis shows exactly what is open. Evidence accumulates per requirement, and the technical documentation and EU Declaration of Conformity are drafted from the recorded state instead of written from scratch. Where the classification puts a product on a third-party route, that same recorded state is the file the notified body assesses.

The whole compliance workspace, live and clickable.
Open a read-only demo of Aurelia Devices B.V., a fictional manufacturer running the full platform. Walk the compliance dashboard, a worked product risk assessment, the generated conformity documents, and the vulnerability disclosure register, all with real sample data. Open it instantly, no signup.

Everything the Cyber Resilience Act asks of a manufacturer
One workspace covering all five CRA obligation areas, from product classification and risk assessment through documentation, vulnerability handling, and authority reporting.
Disclosure intake and acknowledgment are free. The self-assessment suite is on the Compliance plan, covering Module A for default-class products and the technical file for products that need a notified body.
Product Classification and Conformity Route
Answer the Annex III and IV questions for each product. The engine determines whether the product is default, important, or critical and which Article 32 conformity assessment route applies.
STRIDE Risk Assessment
A structured threat model per product with likelihood and impact scoring across 33 security objectives, feeding directly into the Annex I requirements work.
Essential Requirements and Gap Analysis
Work through the 22-row Annex I essential requirements checklist. Gap analysis shows what is open and remediation guidance shows how to close it.
Technical File and Declaration of Conformity
Draft artifacts clause by clause with AI assistance across 88 CRA clause artifacts, then generate the EU Declaration of Conformity, the Annex VII documentation index, and the Annex II user information sheet, with CE marking guidance.
Disclosure Portal and Article 14 Reporting
A branded intake portal on your own subdomain with structured submissions, PGP, security.txt, and a full audit trail. Article 14 milestones to ENISA/CSIRT run on fixed deadlines with SRP-ready packages.
Partners, Trust Portal, and Integrations
Assess supply chain partners with CVD scanning, VEX, and SBOM matching. Share conformity documents with approved external viewers through a trust portal, with API access and SAML SSO.
Are You CRA Ready?
EU buyers and market surveillance authorities increasingly expect manufacturers to show a documented CRA position. CVD Portal gives you a structured assessment, the technical file to back it, and a published disclosure process.
CRA Published
Regulation (EU) 2024/2847 enters into force
Article 14 Reporting Begins
Vulnerability notification obligations apply to products in scope
Full Conformity Deadline
Annex I essential requirements, technical documentation, and CE marking apply
Start your CRA self-assessment before the deadlines arrive
Article 14 reporting obligations apply from 11 September 2026 and full conformity, including Annex I and CE marking, applies from 11 December 2027. Every new account starts with 14 days of the Compliance plan. New to the regulation? Read the EU Cyber Resilience Act regulation guide first.