Pricing by CRA deadline
CRA Compliance Platform Pricing
Each row below is one CRA deadline and the tiers that meet it. September 2026 is Article 14 authority reporting. December 2027 is full conformity, from the risk assessment through to the EU Declaration of Conformity.
CRA deadline
11 Sep 2026
Article 14 reporting mandate
Manufacturers must notify ENISA and the national CSIRT of actively exploited vulnerabilities and severe incidents on fixed windows. A 24-hour early warning, a 72-hour full notification, then a final report at 14 days for vulnerabilities and 1 month for incidents.
Forever
Any manufacturer that needs a compliant public disclosure channel today.
- ✓Public vulnerability submission portal
- ✓Submission tracking with unique IDs
- ✓48h acknowledgment SLA tracking
- ✓Published disclosure policy and security contact
- ✓PGP encrypted communication
- ✓Compliance audit trail
- ✓1 team member
Meets this deadline
Billed annually as €1,188
SMEs with products on the EU market that must file from September 2026.
- ✓Article 14 notification workflow (24h / 72h / 14d)
- ✓SRP-ready submission package*
- ✓SBOM registry (SPDX / CycloneDX)
- ✓CVSS 3.1 / 4.0 severity scoring
- ✓Remediation decision and timeline tracking
- ✓CSAF 2.0 advisory export
- ✓NVD and EUVD threat intelligence feeds
- ✓Up to 3 team members
CRA deadline
11 Dec 2027
Full CRA conformity
The whole regulation takes effect. Every product with digital elements needs a cybersecurity risk assessment, the Annex I essential requirements, a technical documentation dossier, the EU Declaration of Conformity, and CE marking before it goes on the EU market.
Meets this deadline
Billed annually as €3,588
SMEs running the CRA self-assessment under Module A ahead of December 2027.***
- ✓Annex I Part I cybersecurity risk assessment
- ✓Product classification and Article 32 route selection
- ✓21-requirement Annex I self-assessment checklist
- ✓Clause 6 and 7 artifact drafting with gap analysis
- ✓EU Declaration of Conformity draft (Annex V)
- ✓Technical documentation export (Annex VII)
- ✓Lifecycle support for 3 products, then €99/mo each
- ✓Up to 5 team members
Portfolio scale
Large product portfolios, SSO and API integration, or notified-body evidence.
- ✓Lifecycle support for 25 products, then €99/mo each
- ✓Notified-body conformity evidence package
- ✓API access with SSO and SAML integration
- ✓Trust portal on your own domain
- ✓Automated SBOM to CVE supply chain alerts
- ✓EUDI Wallet identity verification (eIDAS 2.0)
- ✓Up to 10 team members
- ✓Dedicated account manager and 99.9% uptime SLA
Free on cvdportal.com
Start today at no cost
Download, scan, and plan without an account.
Feature Comparison
Free receives and tracks disclosures. Reporting adds Article 14 filing and the full CRA vulnerability handling process. Compliance adds the CRA self-assessment through to the EU Declaration of Conformity. Enterprise adds scale, integrations, and third-party assurance.
| Capability | Free | Reporting | Compliance | Enterprise |
|---|---|---|---|---|
| Article 14 Reporting: September 2026 | ||||
| Public submission portal with tracking IDs | ||||
| 48h acknowledgment SLA tracking | ||||
| CVD policy (auto-published) | ||||
| Actively exploited vulnerability flagging | ||||
| Severe security incident tracking | ||||
| Submission type classification | ||||
| PGP encrypted communication | ||||
| Compliance audit trail | ||||
| Article 14 notification workflow (24h / 72h / 14d) | — | |||
| SRP-ready submission package* | — | |||
| Vulnerability Handling (Annex I Part II): December 2027 | ||||
| SBOM registry (SPDX / CycloneDX) | — | |||
| Hardware component registry | — | |||
| CVSS 3.1 / 4.0 severity scoring | — | |||
| Remediation decision & timeline tracking | — | |||
| CSAF 2.0 advisory export | — | |||
| NVD / EUVD threat intelligence feeds | — | |||
| Monitoring source configuration | — | |||
| Security test & review scheduling | — | |||
| CRA-CVD obligation matrix (26 articles) | — | |||
| 8 auto-drafted policy documents | — | |||
| Compliance analytics dashboard | — | |||
| Coordinator assignment workflow | — | |||
| Post-release action tracking | — | |||
| CRA Self-Assessment (Compliance): December 2027 | ||||
| Product classification & vertical standards lookup | ||||
| Annex I Part I cybersecurity risk assessment | — | — | ||
| STRIDE threat modelling and control mapping | — | — | ||
| Conformity route selection (Art. 32 modules) | — | — | ||
| 21-requirement Annex I self-assessment checklist | — | — | ||
| ENISA Secure by Design and Default tracker (22 playbooks) | — | — | ||
| Clause 6 and 7 artifact drafting with gap analysis | — | — | ||
| EU Declaration of Conformity draft (Annex V)** | — | — | ||
| Technical documentation index and export (Annex VII) | — | — | ||
| CE marking guidance (Art. 29-30) | — | — | ||
| Annex II user-information sheet and support period | — | — | ||
| Monitoring triggers and immutable assessment snapshots | — | — | ||
| CRA exposure scanner | — | — | ||
| Enterprise Scale & Integrations | ||||
| Notified-body conformity evidence package | — | — | — | |
| AI-assisted vulnerability triage | — | — | — | |
| Automated SBOM ↔ CVE supply chain alerts | — | — | — | |
| API access | — | — | — | |
| Custom branding & whitelabel | — | — | — | |
| EUDI Wallet identity verification (eIDAS 2.0) | — | — | — | |
| Slack, Teams & Discord notifications | — | — | — | |
| Custom webhook integrations | — | — | — | |
| CVE ID assistance | — | — | — | |
| SSO / SAML integration | — | — | — | |
| Customer-facing trust portal | — | — | — | |
| Audit-ready compliance reports | — | — | — | |
| Dedicated account manager | — | — | — | |
| Products covered for vulnerability disclosure | Unlimited | Unlimited | Unlimited | Unlimited |
| Products supported | — | — | 3 included | 25 included |
| Team members | 1 | 3 | 5 | 10 |
* ENISA provides no submission API at this stage. CVD Portal produces an SRP-ready package for one-step manual submission, and automated filing follows once ENISA publishes an API.
** No CRA harmonised standard is cited in the Official Journal yet, so no presumption of conformity is available. Compliance produces the documented evidence the regulation requires you to hold.
*** Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
Features evolve with EU regulatory requirements (CRA, NIS2, eIDAS 2.0). Feature availability may change as legislation is clarified or updated by the European Commission.
Frequently Asked Questions
Answers to common questions about CRA tiers, product limits, and compliance obligations.
What exactly must I comply with by 11 September 2026?
Article 14 of the CRA mandates that manufacturers notify ENISA of actively exploited vulnerabilities and severe security incidents via the Single Reporting Platform. You must submit an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days (vulnerabilities) or 1 month (incidents). This applies to products with digital elements in CRA scope, including ones still within their support lifecycle. The Free tier receives and tracks the disclosures behind these obligations, and the SRP-ready filing package is on Reporting.
Do the product limits restrict which products researchers can disclose vulnerabilities for?
No. Vulnerability intake is unlimited on every tier, including Free. Any product you sell can receive disclosures through your portal, with no per-product limit. The '3' and '25' figures count the products you can take through the guided self-assessment workspace, where each one goes through classification, risk assessment and its EU Declaration of Conformity. A product on a third-party route uses the same workspace to prepare its technical file.
What does the Free tier cover?
The Free tier receives and tracks vulnerability disclosures. It gives you a public submission portal, submission tracking, acknowledgment SLA tracking, secure communication, and an audit trail. When you need to file under Article 14, Reporting adds the SRP-ready submission package for the 24h, 72h and final notifications.
When do I need the Reporting tier?
Reporting is where Article 14 filing happens. It adds the SRP-ready submission package for the 24h, 72h and final notifications, alongside the full CRA vulnerability handling that takes effect on 11 December 2027, covering SBOM management, security testing, remediation tracking and CSAF advisories. We recommend upgrading to Reporting well before you need to file.
When do I need the Compliance tier?
Compliance is the CRA self-assessment tier for the 11 December 2027 deadline. It takes each product through the Annex I Part I risk assessment, product classification, the technical documentation, the conformity assessment route and the EU Declaration of Conformity under Module A. It includes lifecycle support for 3 products, then €99 per product each month. Enterprise covers 25.
Does Article 14 apply to products already on the market?
Yes. Reporting obligations apply to all products with digital elements falling within the CRA scope, including products placed on the market before 11 December 2027. If your product is still on the market and within its support lifecycle, you must notify actively exploited vulnerabilities from 11 September 2026.
Why is Free really free?
CVD Portal is free for receiving and tracking vulnerability disclosures because we want to be the disclosure layer for thousands of EU manufacturers. We make money when companies upgrade to file under Article 14 and run the full CRA workflow, with the SRP-ready submission package, SBOM management, security testing and CSAF advisories. That is the entire model. We do not sell data, run ads, or harvest vulnerability disclosures.
How does the Free tier pricing work?
The Free tier is permanently free for receiving and tracking vulnerability disclosures. There are no hidden fees and no time limit on the intake portal, tracking, SLA tracking and audit trail. Article 14 filing with the SRP-ready submission package is on Reporting.
Who owns the disclosure data?
You do. You own every disclosure your portal receives. Full export in CSV and JSON is available on every plan, including Free, so you can take your data with you at any time.
What happens if I cancel?
Your portal stays read-only and your export stays available. You keep access to your submission history and audit trail, and you can download everything before you go.
Can I file under Article 14 on the Free tier?
The Free tier receives and tracks disclosures with the submission portal, SLA tracking and an audit trail. Filing under Article 14 is on Reporting, which adds the SRP-ready submission package for the 24h, 72h and final notifications plus the full CRA vulnerability handling for the December 2027 deadline.
Which products can complete CRA compliance entirely within CVD Portal?
Default-class products (over 90% of connected devices and software) can complete their entire CRA compliance journey in CVD Portal using the Module A internal control procedure, from risk assessment to the EU Declaration of Conformity. For Important (Class I/II) and Critical products, the CRA requires conformity assessment by a third-party Notified Body or EUCC certification, along with compliance with category-specific vertical standards. For those products, CVD Portal prepares the technical documentation and risk assessment to submit to your Notified Body, but does not replace the third-party auditor.
How do I know if my product requires vertical standards or a Notified Body?
You can use our free Product Classifier (/classify) with no account. It evaluates your product against Annex III and Annex IV, determines your Article 32 conformity assessment route, and identifies any draft ETSI EN 304 or CENELEC vertical standards applicable to your product category.
What payment methods do you accept?
We accept all major credit cards. Enterprise is quoted per portfolio and can be paid by invoice. You can upgrade, downgrade, or cancel at any time.