Regulation (EU) 2024/2847 · Cyber Resilience Act

CRA compliance you can prove.

AnnexProof takes manufacturers of devices and software from risk assessment and SBOM, through 24-hour reporting, to technical documentation with evidence for every Annex I requirement.

Reporting mandatory since 11 Sep 2026Full application in 437 days

App view · demo data

§ 01 · Deadlines

The clock is already ticking.

The CRA applies in stages. Reporting has been mandatory since 11 September 2026, including for products placed on the market earlier.

  1. Entry into force

    The transition period starts for manufacturers, importers and distributors.

  2. Notified bodies

    Rules on notifying conformity assessment bodies apply.

  3. Reporting

    Actively exploited vulnerabilities and severe incidents: 24 h, 72 h, final report.

  4. Full application

    Essential requirements, conformity assessment and CE marking.

Early warning
24 hfrom becoming aware
Notification
72 hfull information
Support period
5 yrsat least, as a rule
Maximum fine
2.5%of turnover or EUR 15 m

Articles 13(8), 14, 64(2) and 71 of Regulation (EU) 2024/2847. Fine: the higher of EUR 15 million or 2.5% of total worldwide annual turnover.

Not sure which deadlines apply to your product?

Take the readiness check

§ 02 · Article 14

An actively exploited vulnerability. You have 24 hours.

AnnexProof counts the deadlines from the moment you became aware and assembles each package from data already in the system.

since becoming aware

  1. T+24 hEarly warningProduct, vulnerability, whether it is actively exploited and the Member States where the product is made available.PendingPackage readySubmitted
  2. T+72 hVulnerability notificationGeneral product information, the nature of the exploit and the vulnerability, corrective measures and advice for users.PendingPackage readySubmitted
  3. T+14 dFinal reportDescription with severity and impact, plus details of the security update, no later than 14 days after the fix is available.PendingPackage readySubmitted

Article 14(1) and (2) of Regulation (EU) 2024/2847. An authorised person submits the packages via the Single Reporting Platform to the coordinating CSIRT and ENISA.

See what a real CRA case looks like in AnnexProof.

Book a demo

§ 03 · Annex I

Requirement. Control. Evidence.

Every essential requirement has a control, and every control has reviewed evidence. Gaps are visible at once.

RequirementControlEvidence
I.1(2)(c)Security updates
PS-04Authenticated software updates
Atlas 4.9: release noterelease-recordGapCurrent
I.1(2)(d)Protection from unauthorised access
AC-02MFA for the admin console
Atlas 4.8: penetration testtest-reportGapCurrent
I.2(1)Component identification and SBOM
SB-01SBOM for every release
Atlas 4.8.2: component inventorysbomGapCurrent

Annex I coverage

100%

Relationship suggestions run locally on rules: no AI model and no data leaves the workspace. A person always decides.

Want to see Annex I coverage for your own product?

Join the programme

§ 05 · SBOM

Every component. Checked every day.

Import CycloneDX and SPDX straight from CI. Daily checks against OSV, CISA KEV and the European ENISA EUVD database, with reasoned VEX decisions.

  • pkg:generic/linux@6.12.47Update required
  • pkg:generic/busybox@1.36.1Checked
  • pkg:generic/openssl@3.0.13VEX decision needed
  • pkg:generic/u-boot@2024.01Checked
  • pkg:generic/mbedtls@3.6.0VEX: not affected
  • pkg:generic/zlib@1.3.1Checked
  • pkg:npm/express@4.19.2Checked
  • pkg:pypi/cryptography@42.0.5EUVD · under analysis
  • pkg:golang/golang.org/x/net@0.24.0Checked
  • pkg:cargo/rustls@0.23.5Checked
  • pkg:maven/org.eclipse.paho/mqtt@1.2.5VEX: code not reachable
  • pkg:npm/ws@8.17.1Checked
Sources
OSV
CISA KEV
ENISA EUVD
Formats
CycloneDX
SPDX
CSAF 2.0
CycloneDX VEX

Illustrative data

Already generate an SBOM in CI? We connect it in the first session.

Book a call

Don’t wait for the first incident.

Reporting is already mandatory. Check where you stand in 3 minutes, or let’s talk about your product.

§ 07 · Readiness check

Where are you with the CRA?

10 questions, 3 minutes. You see your score and the biggest gaps right away. No email required.

  1. 01Do you know whether your product falls under the CRA and which category it is in (default, important class I or II, critical)?
  2. 02Do you have a documented cybersecurity risk assessment for the product?
  3. 03Do you generate an SBOM for every release?
  4. 04Do you continuously monitor your components for vulnerabilities?
  5. 05Do you have a reporting procedure: early warning in 24 h, notification in 72 h, final report?
  6. 06Do you have a public coordinated vulnerability disclosure policy and a contact for researchers?
  7. 07Have you set the support period and how free security updates are delivered?
  8. 08Does every Annex I essential requirement have a control and evidence assigned?
  9. 09Do you have technical documentation (Annex VII) you could show a market surveillance authority?
  10. 10Do you know which conformity assessment procedure you will use and whether you need a notified body?
Answered: 0 of 10
The check is indicative and is not legal advice.

§ 08 · Design partners

Five places. We take your first product through together.

We are looking for manufacturers of devices and software who want to get through the CRA now and shape the product.

Places in the programme
5
Product end to end
1from applicability to dossier
Feedback
30 minevery two weeks

What you get

  • Onboarding led personally by the founder
  • Your first product taken through the whole process
  • Preferential launch terms
  • Direct influence on the roadmap

What we ask

  • Regular feedback
  • A case study after rollout (can be anonymous)

§ 09 · Questions

Frequently asked questions

01Does the CRA apply to my company?

The CRA covers manufacturers, importers and distributors of products with digital elements made available on the EU market: from IoT devices and network equipment to software sold as a product. Medical devices and vehicles covered by their own rules are among the exclusions. The readiness check gives a first indication.

02Does AnnexProof replace a lawyer or a notified body?

No. AnnexProof organises the work and the evidence, tracks deadlines and generates documentation. Legal decisions and third-party assessment stay with the people and bodies responsible for them.

03Does AnnexProof submit reports to ENISA for me?

It prepares complete 24-hour, 72-hour and final packages and tracks the deadlines. The submission via the Single Reporting Platform is done by an authorised person in your company.

04We already have an SBOM and a vulnerability scanner. Why AnnexProof?

A scanner tells you what is vulnerable. The CRA asks for more: reasoned decisions, reporting deadlines, VEX, documentation and evidence for every requirement. AnnexProof takes the data from your tools and turns it into compliance.

05Where is the data stored?

In the European Union. Access is protected by multi-factor authentication, and each organisation’s data is isolated from the others.

06Can I export my data?

Yes. SBOM, VEX, documentation and release snapshots can be downloaded, and key data is also available through the REST API.

07How much does it cost?

We are setting pricing together with our first customers in the design partner programme. Let us talk about your scale: number of products and releases per year.

§ 10 · Contact

Let’s talk about your product.

30 minutes: we go through your product, the CRA deadlines and the biggest gaps. No commitment.

Or write tokontakt@annexproof.com

I am interested in

The data controller is Michał Kosiorek. See the privacy policy for details.

3-min checkBook a demo