Upload your firmware. Get a CRA file you can defend.
From 11 September 2026, an actively exploited vulnerability in a product you sell in the EU means telling ENISA within 24 hours. CRA Kit gives you the SBOM, the monitoring, the documents and a reporting console that already knows what the form asks for.
Thirty minutes, no call. Published prices, card checkout, no demo.
The wizard needs no account and no email address. You get a dated PDF at the end.
We publish this as a live median rather than a claim. There have been 0 measured signups so far, which is too few to report a median honestly. The number appears here as soon as there are three.
Six things a market surveillance authority can ask for
Scope and class
Are you in scope, and are you Default, Important Class I, Class II or Critical? That decides whether you can sign your own paperwork or need to pay a notified body. Free, no signup.
A real SBOM
Upload a .bin, .hex, .elf, squashfs, UBI or OTA image and get a component list back. No source code needed. This is the part cheap tools cannot do, because they assume you have a repo.
Live vulnerability watch
Every component matched against NVD, CISA KEV, EUVD and GitHub Advisory, ranked by whether it is actually being exploited. A short list, not 300 theoretical CVEs.
Article 14 console
The 24h, 72h and final reports, pre-drafted against the field set ENISA published. Rehearsal mode so you can run a fake incident before a real one.
The document set
Vulnerability handling policy, CVD policy, support-period declaration, risk assessment, EU declaration of conformity, technical documentation pack, user instructions. Built from your data, versioned with diffs.
Trust pages
One public link that answers a customer security questionnaire. Current SBOM, declaration, support end date, disclosure contact, VEX history.
You do not have the source. Neither does anyone else.
Standard SBOM tools want a repository and a package manifest. Electronics does not work that way. You have a vendor SDK, an RTOS, and a squashfs image from an ODM who will not give you source.
So we read the image. We unpack it, pull the strings out of every file inside, and match them against a signature pack that knows what BusyBox, lwIP, mbed TLS, OpenSSL, U-Boot, FreeRTOS and a Linux kernel banner look like.
Every component comes back with a confidence level and the evidence that produced it: the file, the offset and the exact string we matched. When we cannot recover a version, we say the component is there and the version is unknown. We never guess a version, because a number you cannot defend is worse than no number at all.
| Component | Version | Confidence |
|---|---|---|
| linux_kernel | 4.4.60 | high |
| busybox | 1.36.1 | high |
| openssl | 1.0.2n | high |
| dropbear | 2019.78 | high |
| lwip | 2.1.2 | high |
| mbedtls | 2.16.0 | high |
| u-boot | 2016.11-rc2 | high |
| realtek_sdk | unknown | low |
Real output from the engine on a test image. Every row carries the file and byte offset the match came from.
Everyone else makes you ask
ONEKEY, Cybellum, Finite State, NetRise and Exein are all demo-only. Regulus and EcoComply put you through a form. In this category that reliably means five figures a year. Here is the number, on the page, where you can read it.
| What | Price | What you get |
|---|---|---|
| Regulus Pro | €15,000 a year | Applicability, classification, templates and a roadmap. |
| A consulting gap assessment | $12,000 one-off | A report. It goes stale the day a component goes end-of-life. |
| CRA compliance for one product line, industry estimate | €20,000 to €50,000 | Documentation, risk analysis and SBOM, per product line. |
| CRA Kit Team | €4,788 a year | Billed monthly at €399, cancel whenever. Binary firmware analysis included. |
Pick a plan and start. There is no call.
USD and GBP available at checkout. Monthly or annual, two months free on annual. Upgrade, downgrade and cancel yourself. VAT and reverse charge handled at checkout.
Shipping into the EU from outside it?
The CRA follows the market, not your head office. A US startup on Crowd Supply, a UK brand, a Taiwanese ODM and a German sensor maker are equally in scope. EU grant programmes are not open to you, and most EU tooling is not written for you.
We price in USD and GBP, and there is a page that covers what you actually need: an EU authorised representative, who signs what, and how the paperwork crosses the border.