EU Cyber Resilience Act
CRA File
Check your product, your SBOM and your security contact against the Cyber Resilience Act, for free and in your browser. The generator for the technical file, the declaration of conformity and the vulnerability reports is next.
An SBOM (software bill of materials) is the list of parts your software is built from: the libraries and their versions. The Act expects you to keep one.
Free. No account. Nothing is uploaded.
- passMachine-readable format: CycloneDX 1.5
- passComponents listed: 2 components
- passComponent name and version: 100 % have both
- passUnique identifier (package URL): 100 % have a purl
- missingSupplier name: 50 % name a supplier
- passDependency relationships: 1 entry describes who depends on whom
- passAuthor of the SBOM data: cdxgen
- passTimestamp: 2026-10-05T10:00:00Z
- passTop-level product identified: my-app
The dates that matter
Reporting is live. Manufacturers must report actively exploited vulnerabilities and severe incidents, including for products already on the market: early warning in 24 hours, notification in 72 hours, final report later, to the CSIRT and ENISA through the single reporting platform (Article 14).
The main obligations apply. Technical documentation, the EU declaration of conformity, conformity assessment, CE marking and the vulnerability handling requirements.
Free tools
Repository check
Paste a GitHub repository. No SBOM to prepare: we read the public data and show what is already in place and what is missing.
New · runs in your browser
Licence notices
Drop an SBOM and get a THIRD-PARTY-NOTICES file, a licence overview and the copyleft risks for your project licence.
New · runs in your browser
Product classifier
Five questions: is the product in scope, which category does it fall in, and which conformity route follows.
Annex III and IV, Art. 32
SBOM checker
Drop a CycloneDX or SPDX file and see which minimum elements are missing. Optional lookup of known vulnerabilities.
Runs in your browser
security.txt and policy
The contact file and the coordinated disclosure policy the Regulation expects, ready to publish.
RFC 9116
What the generator will produce
Technical file
The Annex VII documentation assembled from your SBOM and a few answers.
Declaration of conformity
The full and the simplified EU declaration, with your product details filled in.
User information
Support period, security contact and update instructions as Annex II asks.
Report drafts
The 24-hour, 72-hour and final reports with countdown reminders.
Release updates
Regenerate the file on every release from the command line or CI, so it never drifts from the product.
Component watch
A daily check of your components against new vulnerabilities. Only component names are stored.
Planned plans
Not on sale yet. The free tools above stay free.
Free
$0
- Classifier
- SBOM checker
- security.txt and policy
Pro
$29 / month
- One product
- Technical file and declaration
- Report drafts
- Component watch
Team
$99 / month
- Ten products
- CI integration and API
- Several users
File pack
$199 once
- One product
- The documents, no monitoring
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.