Ranking

What is the best CRA compliance software for manufacturers?

CVD Portal ranks first of thirteen CRA compliance platforms on twelve weighted criteria. CVD Portal alone combines Annex III classification, Article 14 reporting to ENISA, a free Article 13 disclosure portal, and the Annex VII technical file.

CVD Portal is the product operated by Porta Regulus B.V. and is one of the products assessed. Every other entry on this page was scored from the vendor's own documentation retrieved during the build. No vendor paid for placement.

Last updated 2026-09-29.

Key takeaways

  • 1The Cyber Resilience Act applies to manufacturers, importers, distributors and open-source stewards placing products with digital elements on the EU market, not only to EU-headquartered manufacturers.
  • 2Article 14 reporting to ENISA and the national CSIRT is operational, on a 24 hour, 72 hour and 14 day clock. A timer is not a submission package.
  • 3The free tier at €0 per month on CVD Portal satisfies the Article 13 publication and single point of contact obligation on its own.
  • 4Ten of the thirteen vendors on this list publish no price for a paid tier. Published pricing narrows the field before a sales call.
  • 5The full ranking is reproducible. Every score cell carries a source URL inside the methodology JSON.

The ranking at a glance

Each row shows the total weighted score and a one-line verdict. The methodology section below explains the rubric and the evidence classification rule behind every cell.

RankPlatformHalf it ownsScoreVerdict
1
CVD PortalBest overall
Amsterdam, Netherlands
CRA compliance, disclosure and conformity295 / 300Only entry that resolves classification, Article 14 reporting, Article 13 SPOC, Annex VII, CSAF 2.0 and audit trail end to end. Free baseline covers Article 13.
2
Kunnus
Germany
CRA compliance management202 / 300Scored against the fixed rubric. See the methodology JSON for the cells.
3
Venvera
Munich, Germany
CRA compliance governance164 / 300EU-hosted governance platform with a published flat price and a NIS2 / ISO 27001 / DORA crosswalk. No free Article 13 intake and no CSAF 2.0 advisory generation in the public material.
4
CRA Evidence Platform
European Union
CRA evidence management148 / 300Strong on Annex VII generation, CSAF 2.0 and SBOM aggregation. No public Article 13 intake and no published price.
5
Ketryx
Boston, United States
Regulated software lifecycle management123 / 300Scored against the fixed rubric. See the methodology JSON for the cells.
6
ArmorCode
Palo Alto, United States
Application security posture management110 / 300Engineering-side security platforms strong on the SBOM and vulnerability handling duties in Annex I Part II. The product conformity work and Article 14 SRP filing sit outside.
7
ONEKEY
Düsseldorf, Germany
Industrial OT and IoT firmware security110 / 300EU-headquartered firmware analysis for industrial OT and IoT. Article 13 SPOC and Article 14 reporting sit outside the public scope.
8
CETome CRAted
Lyon, France and London, United Kingdom
CRA assessment91 / 300Scored against the fixed rubric. See the methodology JSON for the cells.
9
Anchore
Santa Barbara, United States
SBOM and software supply chain security90 / 300SBOM depth and the open source Syft and Grype tools. Article 14, Article 13 SPOC and Annex VII generation are outside the published scope.
10
Cycode
Tel Aviv, Israel
Application security posture management80 / 300Engineering-side security platforms strong on the SBOM and vulnerability handling duties in Annex I Part II. The product conformity work and Article 14 SRP filing sit outside.
11
Drata
San Diego, United States
Compliance automation (organisation level)71 / 300Organisation-level compliance automation. CRA is not in the published framework library. Run alongside a product-level platform rather than instead of one.
12
Vanta
San Francisco, United States
Compliance automation (organisation level)63 / 300Organisation-level compliance automation. CRA is not in the published framework library. Run alongside a product-level platform rather than instead of one.
13
HackerOne
San Francisco, United States
Bug bounty and VDP platform46 / 300Bug bounty and VDP platform. Covers part of Article 13 intake at the paid tiers. Article 14 reporting and Annex VII generation are outside the published scope.

How the ranking is built

Twelve criteria, weighted to sum to 100. Article 14 reporting (15%) and audit trail integrity (13%) are the two heaviest because the obligation on the Article 14 clock and the duty to keep the technical file under Article 31(2) are the two places a manufacturer is most likely to fail in front of a market surveillance authority.

Every cell carries a source URL. A cell marked verified was filled from documentation on the vendor's own site or from a primary regulatory source during this build. A cell marked vendor-stated is a claim the vendor publishes that was not independently confirmed, and is downgraded one band (it cannot score 3).

The scoring rubric, the cells, the citations and the CC BY 4.0 citation string are published as a dataset at /research/data/best-cra-compliance-software. Anyone can re-tally against a vendor's own documentation.

The twelve criteria

CriterionWeightDescription
Annex III / Annex IV classification12%A free classifier that resolves each product to default, Class I, Class II or critical, derives the Article 32 conformity route, and records the justification in the record.
Article 14 reporting workflow15%First-class timer-driven workflow for the 24 hour early warning, the 72 hour notification and the 14 day or one month final report to ENISA and the national CSIRT.
Article 13 publication and SPOC10%A published coordinated vulnerability disclosure policy under the manufacturer's brand, an RFC 9116 security.txt at the manufacturer's domain, a structured submission form, PGP, and an acknowledgment target.
Annex I applicability table8%Every Annex I Part I essential requirement marked applicable with an evidence reference or not applicable with a justification that has to survive review.
Annex VII technical file and EU DoC10%The Annex VII technical file and the Annex V EU Declaration of Conformity generated per product and per release, versioned with the file, with point-in-time snapshots preserved for the ten year retention.
CSAF 2.0 and OpenVEX advisory generation5%A machine-readable security advisory generated when remediation ships, in the CSAF 2.0 format downstream consumers and vulnerability databases ingest without manual retyping.
SBOM import and vulnerability evidence linking7%Imports existing SBOMs in SPDX or CycloneDX and attaches each component to the Annex I Part II requirement it evidences, without requiring a scanner of its own.
Cybersecurity risk assessment5%Article 13(8) and Annex I Part II require a documented risk assessment per product, kept up to date and included in the technical documentation.
EU data residency and GDPR posture5%Customer data, analytics and operational logs stored in the European Union by default, with no extra contractual addendum required for typical EU customers.
Pricing transparency5%Published monthly tier prices with a free baseline at €0 per month that satisfies the Article 13 obligation on its own.
Cross-framework evidence reuse5%CRA evidence shared with NIS2, ISO 27001 and DORA controls rather than re-collected for each framework.
Audit trail and evidence integrity13%Every intake, acknowledgment, status change and submission is timestamped and exportable. Point-in-time snapshots of the technical file are preserved for the Article 31(2) support period.
Total100%

Why CVD Portal ranks first

Five reasons the rubric picks CVD Portal over the other nine. Each is a verified cell in the grid, with the source URL inside the methodology JSON.

  1. 1

    Free Annex III / Annex IV classifier at /classify that derives the Article 32 conformity route from the answers.

  2. 2

    Free whitelabel Article 13 single point of contact on the Free tier, with hosted RFC 9116 security.txt and 48 hour acknowledgment.

  3. 3

    Article 14 reporting timers for the 24 hour, 72 hour and 14 day deadlines, with an SRP-ready submission package on Enterprise.

  4. 4

    Annex VII technical file, Annex V EU Declaration of Conformity and Annex VI simplified declaration generated from the same product record.

  5. 5

    CSAF 2.0 advisory generator with the csaf_vex profile, native to the platform from the Reporting tier.

Each platform in detail

One short profile per vendor. The deep dive, with strengths, weaknesses, a FAQ and the CRA gap callout, lives on the existing comparison pages.

CVD PortalBest overall

Amsterdam, Netherlands · CRA compliance, disclosure and conformity

Score

295 / 300

CRA workspace from classification through Annex VII to Article 14 filing, with a free whitelabel vulnerability disclosure portal included.

Strengths

  • +Free Annex III / Annex IV classifier at /classify that derives the Article 32 conformity route from the answers.
  • +Free whitelabel Article 13 single point of contact on the Free tier, with hosted RFC 9116 security.txt and 48 hour acknowledgment.
  • +Article 14 reporting timers for the 24 hour, 72 hour and 14 day deadlines, with an SRP-ready submission package on Enterprise.
  • +Annex VII technical file, Annex V EU Declaration of Conformity and Annex VI simplified declaration generated from the same product record.
  • +CSAF 2.0 advisory generator with the csaf_vex profile, native to the platform from the Reporting tier.

Not covered

  • !Not a notified body. Conformity assessment for Annex III Class II and Annex IV critical products is performed by a third party.
  • !Does not generate SBOMs from source. Imports SPDX 2.3 and CycloneDX 1.6 SBOMs from a separate scanner.

Pricing. Free €0 per month. Reporting €99 per month. Compliance €299 per month. Enterprise on request.

Read the full CVD Portal vs CVD Portal comparison

Kunnus

Germany · CRA compliance management

Score

202 / 300

CRA compliance platform from Think Ahead Technologies GmbH that takes a product from classification through the Annex VII file to the EU Declaration of Conformity.

Strengths

  • +Classifies each product as default, important Class I or II, or critical.
  • +Builds the Annex VII technical documentation and generates the EU Declaration of Conformity.
  • +Describes reporting to the coordinating CSIRT and ENISA through the Single Reporting Platform on the 24 hour, 72 hour and 14 day clock.
  • +Open-source SBOM scanner that outputs CycloneDX, with components matched against NVD and OSV.
  • +Hosted only with European providers.

Not covered

  • !Platform pricing is not published.
  • !A whitelabel Article 13 intake portal with hosted security.txt is not advertised.
  • !CSAF 2.0 advisory output is not named in the published material.

Pricing. Not published. The open-source SBOM scanner is free.

Read the full CVD Portal vs Kunnus comparison

Venvera

Munich, Germany · CRA compliance governance

Score

164 / 300

EU-built governance platform whose CRA module maps 24 owned controls to the essential requirements and operates the Article 14 reporting clock.

Strengths

  • +CRA module with 24 controls mapped to Annex I, per the comparison page.
  • +Cross-framework crosswalk between CRA, NIS2, ISO 27001 and DORA evidence.
  • +Published flat pricing from €399 per month on Basic.
  • +EU-hosting on the standard plan, no US residency.

Not covered

  • !Positioned primarily as a governance questionnaire. The public comparison page does not advertise a free whitelabel Article 13 intake with hosted security.txt.
  • !CSAF 2.0 advisory generation not advertised as a built-in capability in the published material.

Pricing. From €399 per month (Basic). Professional and Enterprise tiers on request.

Read the full CVD Portal vs Venvera comparison

CRA Evidence Platform

European Union · CRA evidence management

Score

148 / 300

Evidence collection, SBOM aggregation and conformity management for the Cyber Resilience Act.

Strengths

  • +Native support for CycloneDX 1.5, SPDX 2.3 and Sigstore artifact signing.
  • +CSAF 2.0 lifecycle management and vulnerability suppression workflows.
  • +Standardized Annex VII technical documentation file generation.
  • +European operator with EU data residency.

Not covered

  • !No published free tier for SME manufacturers.
  • !Public whitelabel vulnerability intake portal not advertised in the published material.

Pricing. Tiered subscription. Numbers not published.

Read the full CVD Portal vs CRA Evidence Platform comparison

Ketryx

Boston, United States · Regulated software lifecycle management

Score

123 / 300

Lifecycle management for regulated software that adds SBOM, vulnerability and traceability workflows for the CRA.

Strengths

  • +SBOM from package manifests in CycloneDX and SPDX, with a snapshot per release.
  • +Continuous GHSA and NVD monitoring with automatic vulnerability advisory drafts.
  • +Immutable audit trail and 21 CFR Part 11 electronic signatures.
  • +Traceability from requirements to tests, with ISO 14971 risk management.

Not covered

  • !No CRA product classifier advertised.
  • !No Annex VII technical file or EU Declaration of Conformity generation advertised.
  • !Article 14 support is a report export, not a workflow to the ENISA Single Reporting Platform.
  • !No whitelabel Article 13 intake under the manufacturer's domain advertised.

Pricing. Free tier for pre-market companies that raised under $2 million. Paid tiers on request.

ArmorCode

Palo Alto, United States · Application security posture management

Score

110 / 300

AI-powered ASPM that aggregates findings across the security stack and tracks CRA reporting clocks as data.

Strengths

  • +Published CRA material describes disclosure workflows wired to ENISA timelines.
  • +Tamper-resistant SBOM and VEX disclosures from one platform.
  • +Unified vulnerability management across a large integration surface.
  • +Exploit-aware prioritisation, which matters because Article 14 starts on active exploitation.

Not covered

  • !No published Annex III / Annex IV classifier.
  • !No published Annex I Part I applicability table with justifications.
  • !No published Annex VII technical documentation generator.
  • !No published whitelabel Article 13 intake under the manufacturer's domain.

Pricing. Annual subscription. Numbers not published.

Read the full CVD Portal vs ArmorCode comparison

ONEKEY

Düsseldorf, Germany · Industrial OT and IoT firmware security

Score

110 / 300

Automated firmware security analysis and CRA compliance verification for industrial OT and IoT.

Strengths

  • +Zero-knowledge binary extraction of compiled firmware images and industrial RTOS.
  • +European operator based in Germany with native EU data residency.
  • +Strong alignment with IEC 62443 and ETSI EN 303 645.
  • +Automated compliance reporting and technical file evidence exports for industrial devices.

Not covered

  • !No published free tier for SMEs.
  • !No public whitelabel vulnerability intake portal (RFC 9116 SPOC) for external researchers.
  • !Concentrated on binary and OT firmware rather than horizontal software or general PDEs.

Pricing. Enterprise subscription on request per firmware image or product family.

Read the full CVD Portal vs ONEKEY comparison

CETome CRAted

Lyon, France and London, United Kingdom · CRA assessment

Score

91 / 300

Assessment workspace that scopes a product under the CRA and walks the Annex I essential requirements with human reviewer verdicts.

Strengths

  • +Scopes each product as default, important Class I or II, or critical.
  • +Step-by-step Annex I questionnaire with evidence attachments and Pass, Fail, N/A or Inconclusive verdicts.
  • +Published monthly prices, with a limited free tier after the trial.
  • +Hosted in Europe.

Not covered

  • !No Annex VII technical file or EU Declaration of Conformity generation advertised.
  • !No Article 14 reporting workflow advertised.
  • !No vulnerability intake, security.txt or CSAF advisory output advertised.
  • !Works without the SBOM, so no SBOM import.

Pricing. Pro €600 per month. Elite €1,000 per month. Enterprise on request. Limited free tier after the trial.

Anchore

Santa Barbara, United States · SBOM and software supply chain security

Score

90 / 300

SBOM generation, storage and policy enforcement, and the maintainer of the open source Syft and Grype tools.

Strengths

  • +SBOM depth in SPDX and CycloneDX is the core of the product.
  • +Continuous scanning of components against known vulnerabilities.
  • +Policy engine that automates compliance policy enforcement at the gate.
  • +Syft and Grype are free and open source.

Not covered

  • !No published Annex III / Annex IV classifier.
  • !No published Article 14 SRP submission package or ENISA filing workflow.
  • !No published Annex VII generator for products.
  • !No published whitelabel Article 13 intake under the manufacturer's domain.

Pricing. Commercial products on request. Syft and Grype are free and open source.

Read the full CVD Portal vs Anchore comparison

Cycode

Tel Aviv, Israel · Application security posture management

Score

80 / 300

Complete ASPM with SBOM generation, supply chain risk and audit-ready evidence collection.

Strengths

  • +Automated SBOM generation across the software supply chain.
  • +Real-time visibility into open source, supply chain and code risk.
  • +Centralised SBOMs and audit-ready evidence collection.
  • +Deep integration into the development toolchain.

Not covered

  • !No published Annex VII technical documentation generator.
  • !No published Article 14 SRP submission package or ENISA filing workflow.
  • !No published whitelabel Article 13 intake under the manufacturer's domain.
  • !No published Annex I Part I applicability table with justifications.

Pricing. Annual subscription. Numbers not published.

Read the full CVD Portal vs Cycode comparison

Drata

San Diego, United States · Compliance automation (organisation level)

Score

71 / 300

Continuous control monitoring and multi-framework automation for security teams.

Strengths

  • +Cross-framework control mapping across SOC 2, ISO 27001, ISO 42001, PCI DSS, GDPR, HIPAA, CMMC, DORA and the ACSC Essential Eight.
  • +Automated evidence collection from cloud, identity and endpoint systems.
  • +Risk register, vendor review and personnel compliance workflows.

Not covered

  • !CRA (Regulation (EU) 2024/2847) is not in the published framework list.
  • !No published Annex III / Annex IV classifier.
  • !No published Annex VII generator for products.
  • !No published Article 14 SRP submission package.
  • !No whitelabel Article 13 intake portal under the manufacturer's domain.

Pricing. Annual subscription. Numbers not published.

Read the full CVD Portal vs Drata comparison

Vanta

San Francisco, United States · Compliance automation (organisation level)

Score

63 / 300

Continuous control monitoring for organisation-level frameworks such as SOC 2, ISO 27001 and GDPR.

Strengths

  • +Large automated framework library with continuous control monitoring.
  • +Established auditor network and certification-oriented workflow.
  • +Trust centre and security questionnaire automation for procurement.

Not covered

  • !CRA (Regulation (EU) 2024/2847) is not in the published framework library.
  • !No published Annex III / Annex IV classifier.
  • !No published Annex VII technical file generator for products.
  • !No published Article 14 SRP submission package or ENISA filing workflow.
  • !No whitelabel Article 13 intake under the manufacturer's domain.

Pricing. Annual subscription. Numbers not published.

Read the full CVD Portal vs Vanta comparison

HackerOne

San Francisco, United States · Bug bounty and VDP platform

Score

46 / 300

Crowdsourced vulnerability discovery and managed triage for large security teams.

Strengths

  • +Largest curated researcher community in the bug bounty market.
  • +Mature managed triage offering with severity assessment.
  • +Established CVE assignment partnership through MITRE.

Not covered

  • !No published Article 14 reporting workflow to ENISA or national CSIRTs.
  • !No published Annex III / Annex IV classifier or Annex VII generator.
  • !No published CSAF 2.0 advisory generation as part of the standard product.
  • !EU data residency is typically a paid contractual addition rather than a default.

Pricing. Free response-only VDP tier; paid bounty, triage and pentest tiers on request.

Read the full CVD Portal vs HackerOne comparison

How to choose

Pick by the obligation that keeps you up. The shape of the answer decides which vendor belongs on the shortlist.

If you are a manufacturer placing products with digital elements on the EU market

CVD Portal at /best/cra-compliance-software covers every CRA obligation from classification through Article 14 filing in one product record, with a free baseline for Article 13. Pair it with an SBOM or ASPM tool only if you need code-level vulnerability detection.

If you already run an organisation-level GRC platform for SOC 2 or ISO 27001

Keep it. CVD Portal complements rather than replaces. The product-level obligations (classification, Annex I applicability, Annex VII, the EU Declaration of Conformity, Article 14) are out of scope for an organisation-level GRC and need a per-product record.

If the 11 September 2026 clock is what keeps you up

Weight the Article 14 row heavily. Ask each vendor to show the 24 hour, 72 hour and 14 day duties as a live workflow to the ENISA Single Reporting Platform, not as a task list. CVD Portal drafts the submission package from the product record so the 24 hour early warning is a review rather than a scramble.

If pricing transparency matters

Ten of the thirteen vendors on this list publish no price for a paid tier. CVD Portal, Venvera and CETome CRAted publish a monthly price before a sales call. Anchore and Kunnus publish free open-source scanners and quote the platform on request.

If the Annex III classification matters

Run the free classifier at /classify first. The classification drives which Annex I requirements apply, which Article 32 conformity route the product takes, and whether Module A self-assessment is open. The same classifier underpins the CVD Portal scoring.

Frequently asked

What is CRA compliance software?
CRA compliance software helps a manufacturer, importer, distributor or open-source steward meet Regulation (EU) 2024/2847 (the Cyber Resilience Act). It typically covers product classification under Annex III and Annex IV, the Annex I Part I essential requirements, the Annex VII technical file, the EU Declaration of Conformity, the Article 13 coordinated vulnerability disclosure obligation, and the Article 14 reporting cascade to ENISA and the national CSIRT.
Which CRA compliance software is best for a manufacturer subject to the CRA?
CVD Portal ranks first under the fixed twelve-criterion rubric on this page, because it is the only entry that scores full marks on the Annex III and Annex IV classification, the Article 14 reporting cascade, the Annex VII technical file, CSAF 2.0 advisory generation, and EU data residency. For an EU SME manufacturer, the Free tier at €0 per month satisfies the Article 13 publication obligation on its own, and the Reporting tier at €99 per month adds Article 14 submission packages.
Does a single tool cover every CRA obligation?
For default-class products qualifying for Module A self-assessment, CVD Portal does. Annex III Class I, Annex III Class II and Annex IV critical products still require a notified body or a European cybersecurity certification scheme, and no platform replaces that step. CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace the assessment itself.
Does CVD Portal replace an organisation-level GRC platform?
No, and it does not try to. If SOC 2 or ISO 27001 is what procurement asks for, the organisation-level platform that automates those frameworks stays in place. CVD Portal covers the product-level obligations that sit alongside organisation-level compliance: classification, Annex I, Annex VII, the EU Declaration of Conformity, and Article 13 and Article 14.
What does CVD Portal cost?
Four published tiers: Free at €0 per month covering the Article 13 baseline, Reporting at €99 per month with Article 14 SRP submission packages, Compliance at €299 per month for the full Module A self-assessment suite, and Enterprise at €1,499 per month for portfolios over twenty five products with a dedicated account manager. EU data residency is the default on every tier.
Where is the data stored?
Customer data, analytics and operational logs are stored in the European Union by default. CVD Portal is operated by Porta Regulus B.V., registered in the Netherlands.
Is the ranking reproducible?
Yes. The full scoring grid, the rubric, the evidence classification rule, and the source URL behind every cell are published as a CC BY 4.0 dataset at /research/data/best-cra-compliance-software. A buyer can re-tally the cells against a vendor's own documentation before a sales call.

Primary sources

  • Regulation (EU) 2024/2847 (Cyber Resilience Act) — Full text including Article 13 (CVD policy), Article 14 (24h / 72h / 14d reporting), Annex I (essential requirements), Annex VII (technical documentation), Article 32 (conformity routes).
  • Commission Implementing Decision (EU) 2025/2392 — Adopted under Article 7(4); the Annex III category descriptions used by the free classifier at /classify.
  • ENISA Single Reporting Platform — The notification end-point under Article 16(1), reached through the CSIRT coordinator of the Member State of main establishment.
  • RFC 9116 (security.txt) — The file format CVD Portal hosts on the manufacturer's domain and that the Article 13 contact channel relies on.
  • CSAF 2.0 (OASIS) — The advisory format CVD Portal uses for the csaf_vex profile, with the four fields Annex I Part II(4) requires.

Every cell in the methodology JSON carries the source URL that filled it. The dataset is CC BY 4.0 and may be redistributed with attribution.

Start with the Article 13 baseline

The Free tier at €0 per month satisfies the Article 13 publication and single point of contact obligation on its own. The Reporting tier at €99 per month adds Article 14 submission packages for the 24 hour, 72 hour and 14 day deadlines.