T-03EU Cyber Resilience Act · Reporting obligationsEarly access
Be ready to report under the CRA before you have something to report.
CRA Incident Readiness helps small software and digital product makers get their house in order for the Cyber Resilience Act reporting obligations: which components you ship, who your security contacts are, where the evidence would come from, and what is missing, mapped into one readiness pack.
HU · Kis szoftver- és digitálistermék-gyártóknak: feltérképezi a komponenseket, biztonsági kapcsolattartókat, bizonyítékforrásokat és hiányokat a Cyber Resilience Act bejelentési kötelezettségeihez.
| Regulation | Cyber Resilience Act, Regulation (EU) 2024/2847 |
|---|---|
| Reporting obligations | Apply from 11 September 2026 |
| For | Small makers of software and products with digital elements |
| Output | Readiness pack with gaps and owners |
Operational tooling, not legal advice. The readiness pack organises your components, contacts, evidence sources and gaps. Whether and how the CRA applies to your product, and what you must report, are legal questions for your counsel.
1Problem
When an incident happens, the clock is already running
- 1.1Nobody is sure which third-party components and versions are inside each product you have on the market.
- 1.2There is no agreed security contact, intake address or on-call owner for vulnerability reports.
- 1.3Logs, release records and customer lists that a report would rely on live in different tools, or nowhere.
- 1.4Small teams find the gaps for the first time in the middle of a real incident.
2How it works
IN
product
URL, repository, short questionnaire
01
component map
from dependency manifests
02
contacts + evidence
security.txt, releases, logs
03
gap analysis
ordered by effort and impact
OUT
readiness pack
gap list, runbook skeleton
2.1
Tell us about your product
Product URL or repository, and a short questionnaire about releases, support and contacts. No production access needed.
2.2
Automated mapping
We read dependency manifests, public security pages (such as security.txt) and release information to map components, contacts and evidence sources.
2.3
Readiness pack and gap list
You get a structured pack with what is in place, what is missing, and a short prioritised list of next steps.
$ cra-ready scan https://github.com/acme/widgetmanifests: package-lock.json, requirements.txt components mapped 142 OKsecurity.txt not found at /.well-known/security.txt GAPvulnerability contact none published GAPrelease records GitHub releases (23) OKincident owner / on-call not defined (questionnaire) GAP gaps: 3 · pack: cra-readiness-acme-widget.pdf3Deliverables
3.1
Component map
Components and versions found in your manifests, as a starting point for an SBOM.
3.2
Security contact check
Whether a reachable vulnerability-reporting contact is published (for example security.txt) and who owns it.
3.3
Evidence source map
Where the information an incident report needs would come from: logs, releases, affected customers, timelines.
3.4
Gap list
What is missing, ordered by effort and impact, written for a small team.
3.5
Incident runbook skeleton
A fill-in-the-blanks internal runbook: who does what, in what order, using which sources.
3.6
Official references
Links to the Commission's CRA pages so your counsel can check the obligations against your product.
4Pricing
Free readiness scan
€0
One product, public information only.
- Security contact check
- Top-level component overview
- First gaps found
Readiness pack
from €49
The full pack for one product.
- Component map and gap list
- Evidence source map
- Incident runbook skeleton
Early access price. Larger product portfolios are quoted before any work starts.
Early access prices, excl. any applicable VAT. No payment is taken on this site.
5FAQ
Is this legal advice?
No. It is operational tooling that organises facts about your product and your processes. Whether the CRA applies to your product and what exactly you must report is for your legal counsel to confirm.
When do the CRA reporting obligations apply?
According to the European Commission, the CRA's reporting obligations apply from 11 September 2026, while most other requirements apply later. See the Commission's Cyber Resilience Act page for the official timeline.
Do you need access to my systems?
No production access. A repository or dependency manifests and a short questionnaire are enough. Private repositories are read only with access you grant.
Who is it for?
Small software companies, independent developers and makers of connected or digital products who do not have a dedicated security or compliance team.
Does it produce a full SBOM?
It produces a component map from your manifests, which is a practical starting point. A complete, signed SBOM for every build is a separate step we can discuss.
7Request
Request the free scan
Tell me where to look. You get the free result first and decide afterwards whether the paid deliverable is worth it.
Built and run by Misak Systems (Ottó Misák, software engineer) · Hungary, EU
Operational tooling, not legal advice.
Other tools
API Sunset Autopilot
Find the deprecated APIs, SDK versions and model IDs your code actually uses, before they break.
Article 50 Release Gate
Check that your customer-facing AI chat, voice and generated content shows the EU AI Act Article 50 disclosure, with screenshot evidence.