CRA Compliance

Which Cyber Resilience Act compliance tools are free?

By CVD Portal
Last updated 2026-09-247 min read

CVD Portal gives every manufacturer a free vulnerability disclosure portal, CRA classification, scoping tools and a training course. Article 14 reporting costs €99 per month, the Module A self-assessment €299 per month, and Enterprise is quoted per portfolio.

Key takeaways

  • The free CVD Portal account covers the Article 13 disclosure channel with a public submission portal, 48-hour acknowledgment tracking and a published disclosure policy.
  • The public CVD Portal tools need no account and cover scope, classification, maturity scoring, CVSS scoring, and SBOM and CSAF validation.
  • The CVD Portal Reporting tier adds the Article 14 notification workflow and the vulnerability handling records of Annex I Part II.
  • The CVD Portal Compliance tier adds the risk assessment, the Annex I checklist, the EU Declaration of Conformity draft and the Annex VII technical documentation.
  • The CVD Portal Enterprise tier is quoted per portfolio and adds scale, API access, SSO and the notified-body conformity evidence package.

What can a manufacturer use without an account?

The public tools on cvdportal.com run without an account. Each one covers one early readiness step.

  • The CRA scope page explains which products the regulation covers.
  • The product classifier matches a product description against the Annex III and Annex IV categories.
  • The CRA maturity assessment rates 25 practices across five domains. The tool runs in the browser and stores nothing on our servers.
  • The CRA readiness checklist takes one product through the obligations.
  • The article-by-article CRA guide explains each article. The worked examples page quotes the examples that the Commission published in its guidance.
  • The templates page holds CRA policy and document templates.
  • The free tools include CVSS 3.1 and 4.0 calculators, a CSAF validator, an SBOM validator, an Article 14 timeline, a reportability check and a security.txt generator.
  • The standards hub tracks the EN 40000 series and the vertical standards, and links to the free CRA workshops that the standards bodies run for SMEs.
  • The CRA training course teaches the regulation module by module.
  • The CRA tracker records each regulatory event, and the newsletter sends the updates.

What does the free account include?

A free account gives the manufacturer the disclosure channel that Article 13 requires. The Free tier costs €0 and has no end date.

  • A public submission portal on the company's own cvdportal.com subdomain, with a tracking ID for each report.
  • Tracking of the 48-hour acknowledgment target.
  • A published disclosure policy and security contact, with an RFC 9116 security.txt for the portal.
  • PGP encrypted communication with the reporter.
  • A flag for actively exploited vulnerabilities and a record for each severe security incident.
  • A compliance audit trail.
  • The product classification and vertical standards lookup.
  • Unlimited products for vulnerability disclosure, and one team member.

Each new account includes a 14-day Compliance trial.

What does the Reporting tier add?

The Reporting tier costs €99 per month, or €1,188 billed annually. The tier adds the Article 14 reporting workflow and the vulnerability handling records that Annex I Part II requires.

Article 14 has applied since 11 September 2026. Manufacturers must notify ENISA and the national CSIRT of actively exploited vulnerabilities and severe incidents. The windows are a 24-hour early warning, a 72-hour full notification, then a final report at 14 days for vulnerabilities and 1 month for incidents.

  • The Article 14 notification workflow for the 24-hour, 72-hour and 14-day reports.
  • An SRP-ready submission package. ENISA provides no submission API at this stage, so CVD Portal produces a package for one-step manual submission to the single reporting platform.
  • An SBOM registry for SPDX and CycloneDX files, and a hardware component registry.
  • CVSS 3.1 and 4.0 severity scoring on each report.
  • Remediation decision and timeline tracking.
  • CSAF 2.0 advisory export.
  • NVD and EUVD threat intelligence feeds.
  • Up to 3 team members.

What does the Compliance tier add?

The Compliance tier costs €299 per month, or €3,588 billed annually. The tier adds the CRA self-assessment, from the risk assessment to the EU Declaration of Conformity. The CRA applies in full from 11 December 2027.

  • The Annex I Part I cybersecurity risk assessment, with STRIDE threat modelling and control mapping.
  • Product classification and the Article 32 conformity route selection.
  • The Annex I self-assessment checklist.
  • The ENISA Secure by Design and Default tracker.
  • Artifact drafting with a gap analysis. How do you run a Cyber Resilience Act gap analysis? describes the method.
  • The EU Declaration of Conformity draft for Annex V.
  • The technical documentation index and export for Annex VII.
  • A supplier register that checks each supplier domain for a security.txt and a disclosure policy.
  • Lifecycle support for 3 products, and up to 5 team members.

Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

What does the Enterprise tier add?

CVD Portal quotes the Enterprise tier per portfolio. Ask for a quote through the sales form. The tier is for large product portfolios, SSO and API integration, or notified-body evidence.

  • Lifecycle support for 25 products.
  • A notified-body conformity evidence package.
  • API access with SSO and SAML integration.
  • A customer-facing trust portal on the company's own domain.
  • Automated SBOM to CVE supply chain alerts.
  • AI-assisted vulnerability triage.
  • EUDI Wallet identity verification under eIDAS 2.0.
  • Slack, Teams and Discord notifications, and custom webhook integrations.
  • CVE ID assistance.
  • Up to 10 team members, a dedicated account manager and a 99.9% uptime SLA.

Which tier covers each CRA readiness need?

The rows follow the support needs that CRA readiness surveys ask manufacturers to rate. The free column needs no payment. The paid column names the lowest tier that adds to the free resource.

Readiness needFreePaid tier
Clear guidance on CRA requirementsCRA guide and CRA trackerReporting adds the CRA-CVD obligation matrix
Practical guidance and toolsFree tools, templates and the readiness checklistCompliance applies the steps to each product
Examples and best practicesWorked examples from Commission guidanceNo paid add-on
Scope assessmentCRA scope page and product classifierNo paid add-on
Product classificationProduct classifier and the classification lookup in the free accountCompliance adds the Article 32 route selection
Cybersecurity risk assessmentMaturity assessment for the organisationCompliance adds the Annex I Part I risk assessment with STRIDE
Harmonised standardsStandards hub and the vertical standards lookup in the free accountNo paid add-on
Conformity assessmentProduct classes and notified bodiesCompliance adds the Annex V and Annex VII documents. Enterprise adds the notified-body evidence package
Vulnerability and incident managementDisclosure portal, acknowledgment tracking, exploited vulnerability flags and incident recordsReporting adds the Article 14 workflow, the SRP-ready package and CSAF export
Technical documentationTemplatesCompliance adds the Annex VII index and export
Third-party components and suppliersSBOM validator in the free toolsReporting adds the SBOM registry. Compliance adds the supplier register. Enterprise adds SBOM to CVE alerts
Access to expertsContact formEnterprise adds a dedicated account manager
Training and workshopsCRA training course and the workshop links on the standards hubNo paid add-on

What is the next step?

Start with the obligation that applies first. Article 14 reporting applies today, and full conformity applies from 11 December 2027.

Sources

Regulation (EU) 2024/2847 has the CELEX identifier 32024R2847.

Frequently asked questions

Which CRA compliance tools are free?

CVD Portal gives every manufacturer a free vulnerability disclosure portal with 48-hour acknowledgment tracking, a product classifier, a CRA maturity assessment, policy and document templates, CVSS calculators, SBOM and CSAF validators, and a CRA training course.

What does the CVD Portal Reporting tier add?

The Reporting tier costs €99 per month. It adds a workflow for Article 14 notifications, an SRP-ready submission package, an SBOM registry, CSAF 2.0 advisory export, remediation tracking, and NVD and EUVD threat intelligence feeds.

How much does the CVD Portal Enterprise tier cost?

CVD Portal quotes the Enterprise tier per portfolio, and the price comes from the sales team. The Enterprise tier covers 25 products, API access with SSO and SAML, a trust portal and a notified-body conformity evidence package.

Stay compliant with the Cyber Resilience Act

Check your readiness with the CRA Readiness Checklist, or compare plans on pricing.

Create my free CVD portalCreate your free CVD portal

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.