The CRA flight recorder for connected products. Understand, assess, comply: crAcken turns SBOMs, vulnerability findings and security decisions into one traceable release workflow — so when the EU Cyber Resilience Act’s reporting clock starts on 11 September 2026, your organisation can prove what it knew, what it decided, and what it did.
CRA compliance is not a document problem. SBOMs, CVEs and decisions sit siloed across tools and teams, ownership is unclear, and screenshots and emails do not constitute a defensible record. crAcken connects the systems you already use into one product, release, decision and evidence workflow.
The workflow is deterministic by design — no LLM on the critical path. Each stage gates the next, creating an unbroken chain of custody from first signal to final report preview: every step recorded, every decision traceable, nothing assumed.
Register the product family, release version, market status, support period and owner. Upload your CycloneDX or SPDX SBOM: deterministic parsing and component-to-vulnerability matching, with no ambiguity and no LLM on the critical path.
Continuous per-release re-checks detect new or changed findings and severity shifts - not only what the SBOM showed on day one. Alerts trigger a recorded awareness timestamp with a named owner, and the 24h / 72h workflow markers start.
A structured case workflow connects facts, decision and approval. A human-reviewed AI memo lays out facts, missing facts, hypotheses and recommendations - then the evidence bundle assembles approvals, files, manifest and report preview in one place.
Stop reconstructing awareness from tickets, emails and spreadsheets. Every signal, owner and decision lands in one defensible timeline, ready for the 24h and 72h windows.
Findings connected to the exact product, version and support context - across FPGA and SoC platforms, embedded Linux stacks, supplier firmware and field-deployed variants.
An audit-ready evidence bundle and report preview that stands up in front of authorities and notified bodies - proof of what the organisation knew, decided and did.
Use your own CycloneDX or SPDX SBOMs: up to 10 complete analysis runs, 3 products and 3 active releases, with Findings, Release Workspace, Flight Recorder preview and report preview. No credit card required.
For smaller product teams establishing a structured CRA readiness baseline on their first supported releases.
For manufacturers operating multiple supported releases - scheduled monitoring, alerts, integrations and reporting workflows. Enterprise plans available with custom deployment, data residency and support.
Start with a guided CRA Reporting Drill Sprint (€9,500 - 5 to 10 business days): one real product and release, SBOM and vulnerability review, a simulated 24h / 72h reporting workflow, an evidence bundle with executive readiness report, a prioritised remediation roadmap - and six months of Professional access included.