Guides · Updated 30 July 2026
ONEKEY alternative: CRA compliance software with published pricing
CRA Kit is the self-service, published-price option for manufacturers that need the EU Cyber Resilience Act file without an enterprise sales process. Here is the price, the scope and the point where ONEKEY or another product security platform may fit better.
CRA Kit costs €99 a month for Solo, €399 for Team and €1,200 for Fleet. Annual billing costs ten months. Team includes twenty binary firmware scans a month. ONEKEY does not publish a platform price on its site: its buying path is an initial expert call, a personalised demo and then a quote. CRA Kit is the better fit when you need a focused EU Cyber Resilience Act workflow, clear limits and card checkout. ONEKEY is built for a broader product cybersecurity programme across several regulations, standards and services.
The price comparison
A hidden quote cannot be compared with a published price. The table separates facts that are public from questions that still belong in a vendor call. Vendor sites were checked on 30 July 2026.
| Buying question | CRA Kit | ONEKEY |
|---|---|---|
| Can I see the subscription price? | Yes. Free, €99, €399 and €1,200 a month in EUR. | No platform price is published on the pages reviewed. |
| Can I buy without a call? | Yes. Card checkout is self-service. | No. The published path is an expert call, a personalised demo and a quote. |
| Is binary firmware analysis priced in? | Yes. Team includes 20 deep scans a month. Fleet includes 200. | Firmware analysis is part of the platform. Its price and allowance are not public. |
| What is the main scope? | EU Cyber Resilience Act scope, classification, SBOM, vulnerability monitoring, Annex I and VII files, Article 14 reporting and evidence export. | A wider product cybersecurity and compliance platform, including firmware analysis, vulnerability management and several standards and regulations. |
| Can I start free? | Yes. The scope and class wizard needs no signup or email. A Free account can retain one SBOM and monitor it. | The published starting point is a free demo, not a public product tier. |
| What happens if I leave? | SBOM, VEX and document files remain exportable. An account that has paid keeps evidence-bundle download after cancellation. | Ask for the exact export formats, retention terms and post-contract access in the quote. |
Do not compare a €399 Team plan with an enterprise platform by counting feature names. Compare the work you need to finish, the number of products and the evidence you must be able to take away.
What each CRA Kit plan buys
- Free: the scope and class wizard, a dated PDF determination, one retained SBOM, read-only vulnerability monitoring, and CycloneDX and SPDX export.
- Solo, €99 a month: one product, the full document set, Live Watch, VEX drafting, the Article 14 reporting console and a ten-year evidence vault.
- Team, €399 a month: five products, twenty binary firmware scans a month, six CI readers, trust pages, API access, webhooks and ten seats.
- Fleet, €1,200 a month: twenty-five products, two hundred binary scans a month, a portfolio market-surveillance bundle, fifty seats, separate legal entities and priority scanning.
- Annual billing costs ten monthly payments. Ten extra binary scan credits cost €99 and do not expire.
When CRA Kit is the better fit
Pick CRA Kit when the job is the EU Cyber Resilience Act and you want to do it now. It is built for a hardware founder, firmware team or quality manager who needs a classification, an SBOM, current vulnerability matching, the technical file and the Article 14 workflow in one account. You can see the price and product limits before handing over an email address.
It also keeps one distinction visible everywhere: a component with no usable public vulnerability identifier is not a clean component. The product page, trust page and exports name the component and state why it could not be monitored.
When ONEKEY may be the better fit
Pick ONEKEY when you are buying a broader product cybersecurity programme, not only a CRA file. Its public platform covers firmware analysis, SBOM management, vulnerability management, impact assessment, monitoring and compliance across the CRA, IEC 62443, ETSI 303 645 and other frameworks. It also sells expert services and custom integration work.
That breadth is useful when several business units need one product security system, when your buying process already expects an implementation project, or when a named expert service matters more than self-service checkout. The quote should state the product count, firmware allowance, retention, export formats, support, integration work and renewal basis.
The rest of the market follows the same sales path
Cybellum, Finite State, NetRise and Exein also route buyers to a demo or sales contact on the product pages reviewed. None showed a public platform price. Their scope is broader than a CRA-only workflow, so an unpublished price is not proof that the offer is worse. It does mean you cannot compare total cost until each vendor returns a quote with the same product count and work included.
Use one requirements list for every vendor
- Ask what counts as a product, firmware image, scan and seat. Put the expected monthly volume beside each one.
- Ask whether binary analysis opens squashfs, UBI and vendor containers, and how an image that cannot be unpacked is shown.
- Ask how the platform labels a component that has no CPE or other usable vulnerability identifier.
- Ask which vulnerability sources are matched, how often they refresh and whether KEV and EPSS affect priority.
- Ask for the exact SBOM and VEX export formats, the evidence-retention term and what remains downloadable after cancellation.
- Ask which CRA documents are generated, which facts still need human input and whether the Article 14 output matches the current ENISA field set.
- Ask for the full first-year and renewal price, including onboarding, services, extra scans, additional products and support.
Public sources checked
Questions people actually ask
Is CRA Kit cheaper than ONEKEY?
CRA Kit publishes its price. ONEKEY does not publish a platform price, so no honest price comparison is possible until ONEKEY returns a quote for the same number of products, scans, users, services and integrations.
Is CRA Kit a full replacement for ONEKEY?
For a focused EU Cyber Resilience Act workflow, it can be. For a wider product security programme across several standards, custom integrations and expert services, the products are not the same purchase.
How much does CRA compliance software cost?
CRA Kit is free for scope and class work, €99 a month for one-product documentation and monitoring, €399 for five products with twenty binary scans a month, and €1,200 for twenty-five products with two hundred scans. Annual billing costs ten months.
Does the price include firmware SBOM generation?
Team includes twenty deep binary firmware scans a month and Fleet includes two hundred. The resulting component list can be exported as CycloneDX or SPDX. Solo does not include binary scanning but can import an existing SBOM.
What should I ask for in a ONEKEY quote?
Fix the product count, monthly firmware volume, users, retention, export formats, integrations, onboarding, support and renewal price. Ask how failed unpacking and components without a usable vulnerability identifier appear in the output.