CVD Portal

Pricing by CRA deadline

CRA Compliance Platform Pricing

Each row below is one CRA deadline and the tiers that meet it. September 2026 is Article 14 authority reporting. December 2027 is full conformity, from the risk assessment through to the EU Declaration of Conformity.

CRA deadline

11 Sep 2026

Article 14 reporting mandate

Manufacturers must notify ENISA and the national CSIRT of actively exploited vulnerabilities and severe incidents on fixed windows. A 24-hour early warning, a 72-hour full notification, then a final report at 14 days for vulnerabilities and 1 month for incidents.

Free tier
€0/mo

Forever

Any manufacturer that needs a compliant public disclosure channel today.

  • Public vulnerability submission portal
  • Submission tracking with unique IDs
  • 48h acknowledgment SLA tracking
  • Published disclosure policy and security contact
  • PGP encrypted communication
  • Compliance audit trail
  • 1 team member

Includes 14-day Compliance trial

Reporting tier
€99/mo

Meets this deadline

Billed annually as €1,188

SMEs with products on the EU market that must file from September 2026.

  • Article 14 notification workflow (24h / 72h / 14d)
  • SRP-ready submission package*
  • SBOM registry (SPDX / CycloneDX)
  • CVSS 3.1 / 4.0 severity scoring
  • Remediation decision and timeline tracking
  • CSAF 2.0 advisory export
  • NVD and EUVD threat intelligence feeds
  • Up to 3 team members

14-day free trial · No credit card required

CRA deadline

11 Dec 2027

Full CRA conformity

The whole regulation takes effect. Every product with digital elements needs a cybersecurity risk assessment, the Annex I essential requirements, a technical documentation dossier, the EU Declaration of Conformity, and CE marking before it goes on the EU market.

Compliance tierRecommended
€299/mo

Meets this deadline

Billed annually as €3,588

SMEs running the CRA self-assessment under Module A ahead of December 2027.***

  • Annex I Part I cybersecurity risk assessment
  • Product classification and Article 32 route selection
  • 21-requirement Annex I self-assessment checklist
  • Clause 6 and 7 artifact drafting with gap analysis
  • EU Declaration of Conformity draft (Annex V)
  • Technical documentation export (Annex VII)
  • Lifecycle support for 3 products, then €99/mo each
  • Up to 5 team members

14-day free trial · No credit card required

Enterprise tier
Talk to sales

Portfolio scale

Large product portfolios, SSO and API integration, or notified-body evidence.

  • Lifecycle support for 25 products, then €99/mo each
  • Notified-body conformity evidence package
  • API access with SSO and SAML integration
  • Trust portal on your own domain
  • Automated SBOM to CVE supply chain alerts
  • EUDI Wallet identity verification (eIDAS 2.0)
  • Up to 10 team members
  • Dedicated account manager and 99.9% uptime SLA

Quoted per portfolio · Invoice billing available

Feature Comparison

Free receives and tracks disclosures. Reporting adds Article 14 filing and the full CRA vulnerability handling process. Compliance adds the CRA self-assessment through to the EU Declaration of Conformity. Enterprise adds scale, integrations, and third-party assurance.

CapabilityFreeReportingComplianceEnterprise
Article 14 Reporting: September 2026
Public submission portal with tracking IDs
48h acknowledgment SLA tracking
CVD policy (auto-published)
Actively exploited vulnerability flagging
Severe security incident tracking
Submission type classification
PGP encrypted communication
Compliance audit trail
Article 14 notification workflow (24h / 72h / 14d)
SRP-ready submission package*
Vulnerability Handling (Annex I Part II): December 2027
SBOM registry (SPDX / CycloneDX)
Hardware component registry
CVSS 3.1 / 4.0 severity scoring
Remediation decision & timeline tracking
CSAF 2.0 advisory export
NVD / EUVD threat intelligence feeds
Monitoring source configuration
Security test & review scheduling
CRA-CVD obligation matrix (26 articles)
8 auto-drafted policy documents
Compliance analytics dashboard
Coordinator assignment workflow
Post-release action tracking
CRA Self-Assessment (Compliance): December 2027
Product classification & vertical standards lookup
Annex I Part I cybersecurity risk assessment
STRIDE threat modelling and control mapping
Conformity route selection (Art. 32 modules)
21-requirement Annex I self-assessment checklist
ENISA Secure by Design and Default tracker (22 playbooks)
Clause 6 and 7 artifact drafting with gap analysis
EU Declaration of Conformity draft (Annex V)**
Technical documentation index and export (Annex VII)
CE marking guidance (Art. 29-30)
Annex II user-information sheet and support period
Monitoring triggers and immutable assessment snapshots
CRA exposure scanner
Enterprise Scale & Integrations
Notified-body conformity evidence package
AI-assisted vulnerability triage
Automated SBOM ↔ CVE supply chain alerts
API access
Custom branding & whitelabel
EUDI Wallet identity verification (eIDAS 2.0)
Slack, Teams & Discord notifications
Custom webhook integrations
CVE ID assistance
SSO / SAML integration
Customer-facing trust portal
Audit-ready compliance reports
Dedicated account manager
Products covered for vulnerability disclosureUnlimitedUnlimitedUnlimitedUnlimited
Products supported3 included25 included
Team members13510

* ENISA provides no submission API at this stage. CVD Portal produces an SRP-ready package for one-step manual submission, and automated filing follows once ENISA publishes an API.

** No CRA harmonised standard is cited in the Official Journal yet, so no presumption of conformity is available. Compliance produces the documented evidence the regulation requires you to hold.

*** Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

Features evolve with EU regulatory requirements (CRA, NIS2, eIDAS 2.0). Feature availability may change as legislation is clarified or updated by the European Commission.

Frequently Asked Questions

Answers to common questions about CRA tiers, product limits, and compliance obligations.

What exactly must I comply with by 11 September 2026?

Article 14 of the CRA mandates that manufacturers notify ENISA of actively exploited vulnerabilities and severe security incidents via the Single Reporting Platform. You must submit an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days (vulnerabilities) or 1 month (incidents). This applies to products with digital elements in CRA scope, including ones still within their support lifecycle. The Free tier receives and tracks the disclosures behind these obligations, and the SRP-ready filing package is on Reporting.

Do the product limits restrict which products researchers can disclose vulnerabilities for?

No. Vulnerability intake is unlimited on every tier, including Free. Any product you sell can receive disclosures through your portal, with no per-product limit. The '3' and '25' figures count the products you can take through the guided self-assessment workspace, where each one goes through classification, risk assessment and its EU Declaration of Conformity. A product on a third-party route uses the same workspace to prepare its technical file.

What does the Free tier cover?

The Free tier receives and tracks vulnerability disclosures. It gives you a public submission portal, submission tracking, acknowledgment SLA tracking, secure communication, and an audit trail. When you need to file under Article 14, Reporting adds the SRP-ready submission package for the 24h, 72h and final notifications.

When do I need the Reporting tier?

Reporting is where Article 14 filing happens. It adds the SRP-ready submission package for the 24h, 72h and final notifications, alongside the full CRA vulnerability handling that takes effect on 11 December 2027, covering SBOM management, security testing, remediation tracking and CSAF advisories. We recommend upgrading to Reporting well before you need to file.

When do I need the Compliance tier?

Compliance is the CRA self-assessment tier for the 11 December 2027 deadline. It takes each product through the Annex I Part I risk assessment, product classification, the technical documentation, the conformity assessment route and the EU Declaration of Conformity under Module A. It includes lifecycle support for 3 products, then €99 per product each month. Enterprise covers 25.

Does Article 14 apply to products already on the market?

Yes. Reporting obligations apply to all products with digital elements falling within the CRA scope, including products placed on the market before 11 December 2027. If your product is still on the market and within its support lifecycle, you must notify actively exploited vulnerabilities from 11 September 2026.

Why is Free really free?

CVD Portal is free for receiving and tracking vulnerability disclosures because we want to be the disclosure layer for thousands of EU manufacturers. We make money when companies upgrade to file under Article 14 and run the full CRA workflow, with the SRP-ready submission package, SBOM management, security testing and CSAF advisories. That is the entire model. We do not sell data, run ads, or harvest vulnerability disclosures.

How does the Free tier pricing work?

The Free tier is permanently free for receiving and tracking vulnerability disclosures. There are no hidden fees and no time limit on the intake portal, tracking, SLA tracking and audit trail. Article 14 filing with the SRP-ready submission package is on Reporting.

Who owns the disclosure data?

You do. You own every disclosure your portal receives. Full export in CSV and JSON is available on every plan, including Free, so you can take your data with you at any time.

What happens if I cancel?

Your portal stays read-only and your export stays available. You keep access to your submission history and audit trail, and you can download everything before you go.

Can I file under Article 14 on the Free tier?

The Free tier receives and tracks disclosures with the submission portal, SLA tracking and an audit trail. Filing under Article 14 is on Reporting, which adds the SRP-ready submission package for the 24h, 72h and final notifications plus the full CRA vulnerability handling for the December 2027 deadline.

Which products can complete CRA compliance entirely within CVD Portal?

Default-class products (over 90% of connected devices and software) can complete their entire CRA compliance journey in CVD Portal using the Module A internal control procedure, from risk assessment to the EU Declaration of Conformity. For Important (Class I/II) and Critical products, the CRA requires conformity assessment by a third-party Notified Body or EUCC certification, along with compliance with category-specific vertical standards. For those products, CVD Portal prepares the technical documentation and risk assessment to submit to your Notified Body, but does not replace the third-party auditor.

How do I know if my product requires vertical standards or a Notified Body?

You can use our free Product Classifier (/classify) with no account. It evaluates your product against Annex III and Annex IV, determines your Article 32 conformity assessment route, and identifies any draft ETSI EN 304 or CENELEC vertical standards applicable to your product category.

What payment methods do you accept?

We accept all major credit cards. Enterprise is quoted per portfolio and can be paid by invoice. You can upgrade, downgrade, or cancel at any time.