ambolt

EU Cyber Resilience Act

CRA File

Check your product, your SBOM and your security contact against the Cyber Resilience Act, for free and in your browser. The generator for the technical file, the declaration of conformity and the vulnerability reports is next.

An SBOM (software bill of materials) is the list of parts your software is built from: the libraries and their versions. The Act expects you to keep one.

Free. No account. Nothing is uploaded.

Example: checking a software parts list8 of 9 checks passed
  • passMachine-readable format: CycloneDX 1.5
  • passComponents listed: 2 components
  • passComponent name and version: 100 % have both
  • passUnique identifier (package URL): 100 % have a purl
  • missingSupplier name: 50 % name a supplier
  • passDependency relationships: 1 entry describes who depends on whom
  • passAuthor of the SBOM data: cdxgen
  • passTimestamp: 2026-10-05T10:00:00Z
  • passTop-level product identified: my-app
Example on a small sample, 2026-10-05. Your own file never leaves your browser.

The dates that matter

11 Sep 2026

Reporting is live. Manufacturers must report actively exploited vulnerabilities and severe incidents, including for products already on the market: early warning in 24 hours, notification in 72 hours, final report later, to the CSIRT and ENISA through the single reporting platform (Article 14).

11 Dec 2027

The main obligations apply. Technical documentation, the EU declaration of conformity, conformity assessment, CE marking and the vulnerability handling requirements.

Free tools

Repository check

Paste a GitHub repository. No SBOM to prepare: we read the public data and show what is already in place and what is missing.

New · runs in your browser

Licence notices

Drop an SBOM and get a THIRD-PARTY-NOTICES file, a licence overview and the copyleft risks for your project licence.

New · runs in your browser

Product classifier

Five questions: is the product in scope, which category does it fall in, and which conformity route follows.

Annex III and IV, Art. 32

SBOM checker

Drop a CycloneDX or SPDX file and see which minimum elements are missing. Optional lookup of known vulnerabilities.

Runs in your browser

security.txt and policy

The contact file and the coordinated disclosure policy the Regulation expects, ready to publish.

RFC 9116

What the generator will produce

  1. Technical file

    The Annex VII documentation assembled from your SBOM and a few answers.

  2. Declaration of conformity

    The full and the simplified EU declaration, with your product details filled in.

  3. User information

    Support period, security contact and update instructions as Annex II asks.

  4. Report drafts

    The 24-hour, 72-hour and final reports with countdown reminders.

  5. Release updates

    Regenerate the file on every release from the command line or CI, so it never drifts from the product.

  6. Component watch

    A daily check of your components against new vulnerabilities. Only component names are stored.

Planned plans

Not on sale yet. The free tools above stay free.

Free

$0

  • Classifier
  • SBOM checker
  • security.txt and policy

Pro

$29 / month

  • One product
  • Technical file and declaration
  • Report drafts
  • Component watch

Team

$99 / month

  • Ten products
  • CI integration and API
  • Several users

File pack

$199 once

  • One product
  • The documents, no monitoring

Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.