Everything you need for CRA CVD compliance
Professional vulnerability disclosure portal with all the features manufacturers selling into the EU need, from free tier to enterprise.
Core Features (every tier, including Free)
Unlimited Products for Reporting
Receive vulnerability reports for every product you sell, with no per-product limit on any tier. The affected product is a field on each report. This is separate from the CRA product assessments that Compliance and Enterprise cap.
Whitelabel Email
Get [email protected] - a professional email address specifically for vulnerability reports. All submissions are automatically forwarded to your registered email.
Submission Portal
A branded public portal where researchers can submit vulnerability reports. Includes your company branding and CVD policy display.
48-Hour Acknowledgment Tracking
Automated tracking of your acknowledgment SLA, 48 hours by default and configurable. The CRA sets no acknowledgment deadline. BSI TR-03183-3 expects a reply written by a person within five working days, so the tracker covers that clock too. Separate alerts ensure you also meet the mandatory 24h early warning and 72h full report deadlines under Article 14.
CVD Policy Template
Professional vulnerability disclosure policy template ready to customize. Clear guidelines for researchers on how to report issues.
Dashboard
Manage all your vulnerability submissions in one place. View details, update status, and track progress.
PGP Support
Allow researchers to encrypt submissions using your PGP key for maximum security and confidentiality.
Reporting (Article 14 filing + vulnerability handling)
SRP-ready submission package
An SRP-ready Article 14 submission package for the relevant CSIRT and ENISA Single Reporting Platform. Covers both trigger conditions (actively exploited vulnerabilities and significant incidents) across all three mandatory milestones, the 24-hour early warning, the 72-hour detailed report, and the final report (+14 days / 1 month). ENISA provides no submission API at this stage, so the package is built for one-step manual submission and automated filing follows once ENISA publishes an API. The Free tier receives and tracks reports, and the SRP-ready package generation is available from Reporting.
Enhanced Dashboard
Advanced analytics and reporting. View trends, response times, and generate compliance reports.
SBOM & CSAF Advisories
SBOM registry (SPDX / CycloneDX), CVSS 3.1 / 4.0 severity scoring, remediation tracking, and machine-readable CSAF 2.0 advisory export for the full CRA vulnerability-handling workflow.
Priority Support
Faster response times for support requests. Direct access to our security team.
Compliance (CRA self-assessment, Module A, default-class products)
Cybersecurity Risk Assessment
Annex I Part I risk assessment with STRIDE threat modelling and control mapping for each product with digital elements.
Product Classification
Classify each product (default / Class I / II / critical) and select the conformity route under Article 32.
EU Declaration of Conformity
Draft the EU Declaration of Conformity (Annex V) and the Annex VII technical documentation index, with a 21-requirement Annex I self-assessment checklist and gap analysis, with the notified-body route prepared as a technical file where Module A does not apply.
CRA Exposure Scanner
Probe your public surface for security.txt and CVD-policy readiness against CRA expectations.
CRA Product Assessments
Compliance includes 3 CRA product assessments, then €99 per assessment each month. Enterprise includes 25.
Enterprise (scale, integrations, assurance)
API Access
Integrate with your internal systems. Automate workflows and sync with issue trackers.
Custom Branding & Domain
Full white-label control. Add your logo, colors, and use your own domain: security.yourcompany.com instead of yourcompany.cvdportal.com.
CVE Assistance
Expert help with CVE assignment and coordination with MITRE.
SSO Integration
Single sign-on with your existing identity provider (SAML, OAuth).
Dedicated Support
Priority SLA with dedicated account manager and on-call security support.
Audit Reports
Detailed compliance documentation for regulatory audits and certifications.
Comparing options? Read the CRA compliance and reporting solution buyer's guide.