| 1 | CVD PortalBest overall Amsterdam, Netherlands | CRA compliance, disclosure and conformity | 295 / 300 | Only entry that resolves classification, Article 14 reporting, Article 13 SPOC, Annex VII, CSAF 2.0 and audit trail end to end. Free baseline covers Article 13. |
| 2 | Kunnus Germany | CRA compliance management | 202 / 300 | Scored against the fixed rubric. See the methodology JSON for the cells. |
| 3 | Venvera Munich, Germany | CRA compliance governance | 164 / 300 | EU-hosted governance platform with a published flat price and a NIS2 / ISO 27001 / DORA crosswalk. No free Article 13 intake and no CSAF 2.0 advisory generation in the public material. |
| 4 | CRA Evidence Platform European Union | CRA evidence management | 148 / 300 | Strong on Annex VII generation, CSAF 2.0 and SBOM aggregation. No public Article 13 intake and no published price. |
| 5 | Ketryx Boston, United States | Regulated software lifecycle management | 123 / 300 | Scored against the fixed rubric. See the methodology JSON for the cells. |
| 6 | ArmorCode Palo Alto, United States | Application security posture management | 110 / 300 | Engineering-side security platforms strong on the SBOM and vulnerability handling duties in Annex I Part II. The product conformity work and Article 14 SRP filing sit outside. |
| 7 | ONEKEY Düsseldorf, Germany | Industrial OT and IoT firmware security | 110 / 300 | EU-headquartered firmware analysis for industrial OT and IoT. Article 13 SPOC and Article 14 reporting sit outside the public scope. |
| 8 | CETome CRAted Lyon, France and London, United Kingdom | CRA assessment | 91 / 300 | Scored against the fixed rubric. See the methodology JSON for the cells. |
| 9 | Anchore Santa Barbara, United States | SBOM and software supply chain security | 90 / 300 | SBOM depth and the open source Syft and Grype tools. Article 14, Article 13 SPOC and Annex VII generation are outside the published scope. |
| 10 | Cycode Tel Aviv, Israel | Application security posture management | 80 / 300 | Engineering-side security platforms strong on the SBOM and vulnerability handling duties in Annex I Part II. The product conformity work and Article 14 SRP filing sit outside. |
| 11 | Drata San Diego, United States | Compliance automation (organisation level) | 71 / 300 | Organisation-level compliance automation. CRA is not in the published framework library. Run alongside a product-level platform rather than instead of one. |
| 12 | Vanta San Francisco, United States | Compliance automation (organisation level) | 63 / 300 | Organisation-level compliance automation. CRA is not in the published framework library. Run alongside a product-level platform rather than instead of one. |
| 13 | HackerOne San Francisco, United States | Bug bounty and VDP platform | 46 / 300 | Bug bounty and VDP platform. Covers part of Article 13 intake at the paid tiers. Article 14 reporting and Annex VII generation are outside the published scope. |