Everything you need for CRA CVD compliance

Professional vulnerability disclosure portal with all the features manufacturers selling into the EU need, from free tier to enterprise.

Core Features (every tier, including Free)

Unlimited Products for Reporting

Receive vulnerability reports for every product you sell, with no per-product limit on any tier. The affected product is a field on each report. This is separate from the CRA product assessments that Compliance and Enterprise cap.

FreeReportingComplianceEnterprise

Whitelabel Email

Get [email protected] - a professional email address specifically for vulnerability reports. All submissions are automatically forwarded to your registered email.

FreeReportingComplianceEnterprise

Submission Portal

A branded public portal where researchers can submit vulnerability reports. Includes your company branding and CVD policy display.

FreeReportingComplianceEnterprise

48-Hour Acknowledgment Tracking

Automated tracking of your acknowledgment SLA, 48 hours by default and configurable. The CRA sets no acknowledgment deadline. BSI TR-03183-3 expects a reply written by a person within five working days, so the tracker covers that clock too. Separate alerts ensure you also meet the mandatory 24h early warning and 72h full report deadlines under Article 14.

FreeReportingComplianceEnterprise

CVD Policy Template

Professional vulnerability disclosure policy template ready to customize. Clear guidelines for researchers on how to report issues.

FreeReportingComplianceEnterprise

Dashboard

Manage all your vulnerability submissions in one place. View details, update status, and track progress.

FreeReportingComplianceEnterprise

PGP Support

Allow researchers to encrypt submissions using your PGP key for maximum security and confidentiality.

FreeReportingComplianceEnterprise

Reporting (Article 14 filing + vulnerability handling)

SRP-ready submission package

An SRP-ready Article 14 submission package for the relevant CSIRT and ENISA Single Reporting Platform. Covers both trigger conditions (actively exploited vulnerabilities and significant incidents) across all three mandatory milestones, the 24-hour early warning, the 72-hour detailed report, and the final report (+14 days / 1 month). ENISA provides no submission API at this stage, so the package is built for one-step manual submission and automated filing follows once ENISA publishes an API. The Free tier receives and tracks reports, and the SRP-ready package generation is available from Reporting.

ReportingComplianceEnterprise

Enhanced Dashboard

Advanced analytics and reporting. View trends, response times, and generate compliance reports.

ReportingComplianceEnterprise

SBOM & CSAF Advisories

SBOM registry (SPDX / CycloneDX), CVSS 3.1 / 4.0 severity scoring, remediation tracking, and machine-readable CSAF 2.0 advisory export for the full CRA vulnerability-handling workflow.

ReportingComplianceEnterprise

Priority Support

Faster response times for support requests. Direct access to our security team.

ReportingComplianceEnterprise

Compliance (CRA self-assessment, Module A, default-class products)

Cybersecurity Risk Assessment

Annex I Part I risk assessment with STRIDE threat modelling and control mapping for each product with digital elements.

ComplianceEnterprise

Product Classification

Classify each product (default / Class I / II / critical) and select the conformity route under Article 32.

ComplianceEnterprise

EU Declaration of Conformity

Draft the EU Declaration of Conformity (Annex V) and the Annex VII technical documentation index, with a 21-requirement Annex I self-assessment checklist and gap analysis, with the notified-body route prepared as a technical file where Module A does not apply.

ComplianceEnterprise

CRA Exposure Scanner

Probe your public surface for security.txt and CVD-policy readiness against CRA expectations.

ComplianceEnterprise

CRA Product Assessments

Compliance includes 3 CRA product assessments, then €99 per assessment each month. Enterprise includes 25.

ComplianceEnterprise

Enterprise (scale, integrations, assurance)

API Access

Integrate with your internal systems. Automate workflows and sync with issue trackers.

Enterprise

Custom Branding & Domain

Full white-label control. Add your logo, colors, and use your own domain: security.yourcompany.com instead of yourcompany.cvdportal.com.

Enterprise

CVE Assistance

Expert help with CVE assignment and coordination with MITRE.

Enterprise

SSO Integration

Single sign-on with your existing identity provider (SAML, OAuth).

Enterprise

Dedicated Support

Priority SLA with dedicated account manager and on-call security support.

Enterprise

Audit Reports

Detailed compliance documentation for regulatory audits and certifications.

Enterprise