{
  "name": "Best CRA compliance software ranking (2026): ten platforms across twelve weighted criteria",
  "description": "A reproducible ranking of ten platforms that help a manufacturer, importer, distributor or open-source software steward meet Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA). Each platform is scored 0 to 3 on twelve weighted criteria summing to 100. Every cell carries a primary-source URL.",
  "url": "https://cvdportal.com/best/cra-compliance-software",
  "file": "best-cra-compliance-software.json",
  "publisher": "CVD Portal, Porta Regulus B.V.",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "lastReviewed": "2026-09-16",
  "citation": "CVD Portal, \"Best CRA compliance software ranking (2026): ten platforms across twelve weighted criteria\", 2026-09-16. https://cvdportal.com/best/cra-compliance-software (CC BY 4.0)",
  "methodology": {
    "audience": "Any manufacturer, importer, distributor, or open-source steward placing products with digital elements on the Union market under Regulation (EU) 2024/2847. Geographic location of the operator is not a scope question; the regulation follows the product's route to market.",
    "rankingRule": "For each criterion the platform is scored 0, 1, 2 or 3. A score of 3 means the platform delivers the requirement end to end with primary-source evidence the buyer can cite. The total is a weighted sum, with weights summing to 100. Tiebreakers in order: audit-trail score, Article 14 score.",
    "evidenceRule": "Every cell carries a source URL retrieved during the build. A cell labelled \"verified\" was filled from vendor documentation or from a primary regulatory source. A cell labelled \"vendor-stated\" is a claim the vendor publishes that was not independently confirmed, and is downgraded one band (it cannot score 3).",
    "vendorSet": "Ten platforms drawn from src/lib/competitors.ts, the editorial source for every /compare page on CVD Portal. Adding or retiring a vendor follows the same rule: re-tally against the evaluation-stage questions in docs/geo-question-map.md and act on evidence.",
    "operatorDisclosure": "CVD Portal is the product operated by Porta Regulus B.V. and is one of the products assessed. The score for CVD Portal follows from the same rubric and the same evidence rule as every other vendor.",
    "overclaimGuard": "Where a vendor claims a feature that is not advertised on its own documentation, the cell is set to 0. Where a feature is described in marketing copy but not in the published documentation, the cell is set to 1 (vendor-stated, capped at 2)."
  },
  "criteria": [
    {
      "id": "classification",
      "name": "Annex III / Annex IV classification",
      "weight": 12,
      "description": "A free classifier that resolves each product to default, Class I, Class II or critical, derives the Article 32 conformity route, and records the justification in the record.",
      "ruleSource": "src/lib/cra-classification.ts"
    },
    {
      "id": "article-14",
      "name": "Article 14 reporting workflow",
      "weight": 15,
      "description": "First-class timer-driven workflow for the 24 hour early warning, the 72 hour notification and the 14 day or one month final report to ENISA and the national CSIRT.",
      "ruleSource": "Regulation (EU) 2024/2847, Article 14 (EUR-Lex CELEX 32024R2847); src/app/(public)/enisa-srp/"
    },
    {
      "id": "article-13",
      "name": "Article 13 publication and SPOC",
      "weight": 10,
      "description": "A published coordinated vulnerability disclosure policy under the manufacturer's brand, an RFC 9116 security.txt at the manufacturer's domain, a structured submission form, PGP, and an acknowledgment target.",
      "ruleSource": "RFC 9116; Regulation (EU) 2024/2847, Article 13; src/lib/security-txt.ts"
    },
    {
      "id": "annex-i-applicability",
      "name": "Annex I applicability table",
      "weight": 8,
      "description": "Every Annex I Part I essential requirement marked applicable with an evidence reference or not applicable with a justification that has to survive review.",
      "ruleSource": "Regulation (EU) 2024/2847, Annex I, Part I; src/lib/cra-articles.ts"
    },
    {
      "id": "annex-vii",
      "name": "Annex VII technical file and EU DoC",
      "weight": 10,
      "description": "The Annex VII technical file and the Annex V EU Declaration of Conformity generated per product and per release, versioned with the file, with point-in-time snapshots preserved for the ten year retention.",
      "ruleSource": "Regulation (EU) 2024/2847, Annexes V, VI and VII; src/app/(public)/cra-self-assessment/"
    },
    {
      "id": "csaf",
      "name": "CSAF 2.0 and OpenVEX advisory generation",
      "weight": 5,
      "description": "A machine-readable security advisory generated when remediation ships, in the CSAF 2.0 format downstream consumers and vulnerability databases ingest without manual retyping.",
      "ruleSource": "Regulation (EU) 2024/2847, Annex I Part II(4); src/lib/csaf/"
    },
    {
      "id": "sbom-import",
      "name": "SBOM import and vulnerability evidence linking",
      "weight": 7,
      "description": "Imports existing SBOMs in SPDX or CycloneDX and attaches each component to the Annex I Part II requirement it evidences, without requiring a scanner of its own.",
      "ruleSource": "Regulation (EU) 2024/2847, Annex I Part II(1); src/lib/sbom-conformance.ts, src/lib/sbom-minimum-elements.ts"
    },
    {
      "id": "risk-assessment",
      "name": "Cybersecurity risk assessment",
      "weight": 5,
      "description": "Article 13(8) and Annex I Part II require a documented risk assessment per product, kept up to date and included in the technical documentation.",
      "ruleSource": "Regulation (EU) 2024/2847, Article 13(8) and Annex I Part II; src/lib/cra/risk-assessment.ts"
    },
    {
      "id": "eu-residency",
      "name": "EU data residency and GDPR posture",
      "weight": 5,
      "description": "Customer data, analytics and operational logs stored in the European Union by default, with no extra contractual addendum required for typical EU customers.",
      "ruleSource": "src/lib/db.ts, src/lib/competitors.ts (eu_residency notes)"
    },
    {
      "id": "pricing",
      "name": "Pricing transparency",
      "weight": 5,
      "description": "Published monthly tier prices with a free baseline at €0 per month that satisfies the Article 13 obligation on its own.",
      "ruleSource": "src/lib/plan.ts (PLAN_PRICING), src/app/(public)/pricing"
    },
    {
      "id": "cross-framework",
      "name": "Cross-framework evidence reuse",
      "weight": 5,
      "description": "CRA evidence shared with NIS2, ISO 27001 and DORA controls rather than re-collected for each framework.",
      "ruleSource": "src/lib/competitors.ts (GRC_ROWS, comparison_intro); Regulation (EU) 2022/2555 (NIS2), Regulation (EU) 2022/2554 (DORA)"
    },
    {
      "id": "audit-trail",
      "name": "Audit trail and evidence integrity",
      "weight": 13,
      "description": "Every intake, acknowledgment, status change and submission is timestamped and exportable. Point-in-time snapshots of the technical file are preserved for the Article 31(2) support period.",
      "ruleSource": "Regulation (EU) 2024/2847, Article 31(2); src/lib/audit.ts, src/lib/cra/state-merge.ts"
    }
  ],
  "scoringBands": {
    "0": "Not advertised, no public evidence",
    "1": "Vendor-stated but not independently verifiable, or partial coverage that leaves a documented gap",
    "2": "Verified in vendor documentation, covers the requirement end to end",
    "3": "Verified end to end and ships with primary-source evidence the buyer can cite to an authority"
  },
  "scores": [
    {
      "slug": "cvdportal",
      "name": "CVD Portal",
      "hq": "Amsterdam, Netherlands",
      "category": "CRA compliance, disclosure and conformity",
      "isWinner": true,
      "cells": {
        "classification": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/classify", "note": "Free interactive classifier at /classify" },
        "article-14": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/cra-article-14-compliance", "note": "Article 14 workflow with 24h / 72h / final timers and SRP package" },
        "article-13": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/vulnerability-disclosure-platform", "note": "Whitelabel SPOC, RFC 9116 security.txt, PGP, 48h target on Free" },
        "annex-i-applicability": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/cra-compliance-platform", "note": "Clause-by-clause applicability with justified not-applicable decisions" },
        "annex-vii": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/cra-self-assessment", "note": "Annex VII index, Annex V DoC and Annex VI simplified declaration" },
        "csaf": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/blog/csaf-2-advisories-explained", "note": "CSAF 2.0 csaf_vex profile generated from the remediation record" },
        "sbom-import": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/blog/sbom-minimum-elements-2026-what-changed", "note": "Imports SPDX 2.3 and CycloneDX 1.6, attaches to Annex I Part II(1)" },
        "risk-assessment": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/cra-self-assessment", "note": "STRIDE assessment per product mapped to Annex I applicability" },
        "eu-residency": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/trust", "note": "EU data residency on every tier, EU-resident analytics" },
        "pricing": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/pricing", "note": "Four published tiers, Free baseline at €0 per month" },
        "cross-framework": { "score": 2, "evidence": "verified", "source": "https://cvdportal.com/standards", "note": "NIS2, ISO 27001 and DORA evidence shared at the requirement level" },
        "audit-trail": { "score": 3, "evidence": "verified", "source": "https://cvdportal.com/trust", "note": "Hash-chained audit log and point-in-time snapshots per release" }
      }
    },
    {
      "slug": "venvera",
      "name": "Venvera",
      "hq": "Munich, Germany",
      "category": "CRA compliance governance",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "No public free Annex III classifier; the comparison page does not list one" },
        "article-14": { "score": 2, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "Article 14 clock described as first-class; submission package details not in public material" },
        "article-13": { "score": 1, "evidence": "vendor-stated", "source": "https://venvera.com/best/cra-compliance-software", "note": "Governance questionnaire covers part of Article 13 but no free whitelabel intake is advertised" },
        "annex-i-applicability": { "score": 2, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "24 controls mapped to essential requirements" },
        "annex-vii": { "score": 2, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "Technical file generation described; not Module A-specific self-assessment output" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "Not advertised as a built-in CSAF 2.0 capability" },
        "sbom-import": { "score": 1, "evidence": "vendor-stated", "source": "https://venvera.com/best/cra-compliance-software", "note": "Evidence collection from SBOMs implied; not the central feature" },
        "risk-assessment": { "score": 2, "evidence": "vendor-stated", "source": "https://venvera.com/best/cra-compliance-software", "note": "Risk register with residual-risk scoring described in product docs" },
        "eu-residency": { "score": 3, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "EU-hosted by default on every tier" },
        "pricing": { "score": 3, "evidence": "verified", "source": "https://venvera.com/pricing", "note": "Flat published pricing from €399 per month" },
        "cross-framework": { "score": 3, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "NIS2, ISO 27001 and DORA crosswalk is the central differentiator" },
        "audit-trail": { "score": 2, "evidence": "verified", "source": "https://venvera.com/best/cra-compliance-software", "note": "DOCX and PDF board packs, xBRL-CSV exports described" }
      }
    },
    {
      "slug": "cra-evidence-platform",
      "name": "CRA Evidence Platform",
      "hq": "European Union",
      "category": "CRA evidence management",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://craevidence.com", "note": "No public Annex III / Annex IV classifier on the public site" },
        "article-14": { "score": 1, "evidence": "vendor-stated", "source": "https://craevidence.com", "note": "Reporting workflows implied; submission package structure not in public docs" },
        "article-13": { "score": 0, "evidence": "verified", "source": "https://craevidence.com", "note": "No whitelabel intake or hosted security.txt advertised" },
        "annex-i-applicability": { "score": 2, "evidence": "vendor-stated", "source": "https://craevidence.com", "note": "Annex I mapping described in marketing material" },
        "annex-vii": { "score": 3, "evidence": "verified", "source": "https://craevidence.com", "note": "Standardized Annex VII generation is the headline feature" },
        "csaf": { "score": 3, "evidence": "verified", "source": "https://craevidence.com", "note": "CSAF 2.0 lifecycle management is a published capability" },
        "sbom-import": { "score": 3, "evidence": "verified", "source": "https://craevidence.com", "note": "CycloneDX and SPDX native" },
        "risk-assessment": { "score": 1, "evidence": "vendor-stated", "source": "https://craevidence.com", "note": "Risk management described; not detailed in public material" },
        "eu-residency": { "score": 3, "evidence": "verified", "source": "https://craevidence.com", "note": "European operator, EU residency" },
        "pricing": { "score": 0, "evidence": "verified", "source": "https://craevidence.com", "note": "Pricing not published" },
        "cross-framework": { "score": 1, "evidence": "vendor-stated", "source": "https://craevidence.com", "note": "CRA-centric; cross-framework mapping not the focus" },
        "audit-trail": { "score": 2, "evidence": "vendor-stated", "source": "https://craevidence.com", "note": "Sigstore signing supports evidence integrity" }
      }
    },
    {
      "slug": "vanta",
      "name": "Vanta",
      "hq": "San Francisco, United States",
      "category": "Compliance automation (organisation level)",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://www.vanta.com", "note": "CRA not in the published framework library" },
        "article-14": { "score": 0, "evidence": "verified", "source": "https://www.vanta.com", "note": "No published Article 14 workflow to ENISA or national CSIRTs" },
        "article-13": { "score": 0, "evidence": "verified", "source": "https://www.vanta.com", "note": "No published whitelabel intake" },
        "annex-i-applicability": { "score": 0, "evidence": "verified", "source": "https://www.vanta.com", "note": "No published Annex I applicability table" },
        "annex-vii": { "score": 0, "evidence": "verified", "source": "https://www.vanta.com", "note": "No published Annex VII generator" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://www.vanta.com", "note": "No published CSAF 2.0 advisory generation" },
        "sbom-import": { "score": 1, "evidence": "vendor-stated", "source": "https://www.vanta.com", "note": "Evidence collection from cloud, identity and HR systems; not product-level SBOM" },
        "risk-assessment": { "score": 2, "evidence": "vendor-stated", "source": "https://www.vanta.com", "note": "Risk register described in the platform overview" },
        "eu-residency": { "score": 1, "evidence": "verified", "source": "https://www.vanta.com", "note": "US-headquartered; EU residency is an enterprise option" },
        "pricing": { "score": 0, "evidence": "verified", "source": "https://www.vanta.com", "note": "Pricing not published" },
        "cross-framework": { "score": 3, "evidence": "verified", "source": "https://www.vanta.com", "note": "Cross-framework control mapping is the central differentiator" },
        "audit-trail": { "score": 2, "evidence": "verified", "source": "https://www.vanta.com", "note": "Continuous control monitoring and audit pack generation" }
      }
    },
    {
      "slug": "drata",
      "name": "Drata",
      "hq": "San Diego, United States",
      "category": "Compliance automation (organisation level)",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://drata.com", "note": "CRA not in the published framework list" },
        "article-14": { "score": 0, "evidence": "verified", "source": "https://drata.com", "note": "No published Article 14 workflow to ENISA or national CSIRTs" },
        "article-13": { "score": 0, "evidence": "verified", "source": "https://drata.com", "note": "No whitelabel intake under the manufacturer's domain" },
        "annex-i-applicability": { "score": 1, "evidence": "vendor-stated", "source": "https://drata.com", "note": "Generic control library; Annex I applicability not a published feature" },
        "annex-vii": { "score": 0, "evidence": "verified", "source": "https://drata.com", "note": "No published Annex VII generator" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://drata.com", "note": "No published CSAF 2.0 advisory generation" },
        "sbom-import": { "score": 1, "evidence": "vendor-stated", "source": "https://drata.com", "note": "Endpoint posture monitoring; not a per-product SBOM store" },
        "risk-assessment": { "score": 2, "evidence": "vendor-stated", "source": "https://drata.com", "note": "Risk register described in the product summary" },
        "eu-residency": { "score": 1, "evidence": "verified", "source": "https://drata.com", "note": "US-headquartered; EU residency is an enterprise option" },
        "pricing": { "score": 0, "evidence": "verified", "source": "https://drata.com", "note": "Pricing not published" },
        "cross-framework": { "score": 3, "evidence": "verified", "source": "https://drata.com", "note": "Multi-framework mapping is the central differentiator" },
        "audit-trail": { "score": 2, "evidence": "verified", "source": "https://drata.com", "note": "Continuous evidence collection and audit workflow" }
      }
    },
    {
      "slug": "cycode",
      "name": "Cycode",
      "hq": "Tel Aviv, Israel",
      "category": "Application security posture management",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://cycode.com", "note": "No published Annex III / Annex IV classifier" },
        "article-14": { "score": 0, "evidence": "verified", "source": "https://cycode.com", "note": "No published Article 14 reporting workflow to ENISA or national CSIRTs" },
        "article-13": { "score": 0, "evidence": "verified", "source": "https://cycode.com", "note": "No published whitelabel intake portal" },
        "annex-i-applicability": { "score": 1, "evidence": "vendor-stated", "source": "https://cycode.com", "note": "CRA mapped onto existing AppSec data; Annex I Part I applicability not a published feature" },
        "annex-vii": { "score": 0, "evidence": "verified", "source": "https://cycode.com", "note": "No published Annex VII generator" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://cycode.com", "note": "No published CSAF 2.0 advisory generation" },
        "sbom-import": { "score": 3, "evidence": "verified", "source": "https://cycode.com", "note": "Automated SBOM generation is the headline capability" },
        "risk-assessment": { "score": 2, "evidence": "vendor-stated", "source": "https://cycode.com", "note": "Code-to-runtime risk posture described" },
        "eu-residency": { "score": 1, "evidence": "verified", "source": "https://cycode.com", "note": "Israel-headquartered; EU residency is an enterprise option" },
        "pricing": { "score": 0, "evidence": "verified", "source": "https://cycode.com", "note": "Pricing not published" },
        "cross-framework": { "score": 2, "evidence": "vendor-stated", "source": "https://cycode.com", "note": "Multiple frameworks mapped onto the AppSec data" },
        "audit-trail": { "score": 2, "evidence": "vendor-stated", "source": "https://cycode.com", "note": "Audit-ready evidence collection described" }
      }
    },
    {
      "slug": "armorcode",
      "name": "ArmorCode",
      "hq": "Palo Alto, United States",
      "category": "Application security posture management",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://www.armorcode.com", "note": "No published Annex III / Annex IV classifier" },
        "article-14": { "score": 2, "evidence": "vendor-stated", "source": "https://www.armorcode.com", "note": "CRA material describes tracking the 24h / 72h / 14-day clocks as data" },
        "article-13": { "score": 0, "evidence": "verified", "source": "https://www.armorcode.com", "note": "No published whitelabel intake portal" },
        "annex-i-applicability": { "score": 1, "evidence": "vendor-stated", "source": "https://www.armorcode.com", "note": "CRA mapped onto AppSec data; Part I applicability not a published feature" },
        "annex-vii": { "score": 0, "evidence": "verified", "source": "https://www.armorcode.com", "note": "No published Annex VII generator" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://www.armorcode.com", "note": "VEX described in published material; CSAF 2.0 not a separate headline" },
        "sbom-import": { "score": 3, "evidence": "verified", "source": "https://www.armorcode.com", "note": "Tamper-resistant SBOM and VEX" },
        "risk-assessment": { "score": 2, "evidence": "vendor-stated", "source": "https://www.armorcode.com", "note": "Exploit-aware prioritisation described" },
        "eu-residency": { "score": 1, "evidence": "verified", "source": "https://www.armorcode.com", "note": "US-headquartered; EU residency is an enterprise option" },
        "pricing": { "score": 0, "evidence": "verified", "source": "https://www.armorcode.com", "note": "Pricing not published" },
        "cross-framework": { "score": 2, "evidence": "vendor-stated", "source": "https://www.armorcode.com", "note": "Multiple frameworks mapped onto the AppSec data" },
        "audit-trail": { "score": 2, "evidence": "vendor-stated", "source": "https://www.armorcode.com", "note": "Tamper-resistant disclosures support audit evidence" }
      }
    },
    {
      "slug": "anchore",
      "name": "Anchore",
      "hq": "Santa Barbara, United States",
      "category": "SBOM and software supply chain security",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://anchore.com", "note": "No published Annex III / Annex IV classifier" },
        "article-14": { "score": 0, "evidence": "verified", "source": "https://anchore.com", "note": "No published Article 14 reporting workflow to ENISA or national CSIRTs" },
        "article-13": { "score": 0, "evidence": "verified", "source": "https://anchore.com", "note": "No published whitelabel intake portal" },
        "annex-i-applicability": { "score": 1, "evidence": "vendor-stated", "source": "https://anchore.com", "note": "Policy engine maps to controls; Annex I Part I applicability not a published feature" },
        "annex-vii": { "score": 0, "evidence": "verified", "source": "https://anchore.com", "note": "No published Annex VII generator" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://anchore.com", "note": "No published CSAF 2.0 advisory generation" },
        "sbom-import": { "score": 3, "evidence": "verified", "source": "https://anchore.com", "note": "SBOM generation and policy enforcement are the headline capabilities" },
        "risk-assessment": { "score": 2, "evidence": "vendor-stated", "source": "https://anchore.com", "note": "Continuous vulnerability scanning described" },
        "eu-residency": { "score": 1, "evidence": "verified", "source": "https://anchore.com", "note": "US-headquartered; EU residency is an enterprise option" },
        "pricing": { "score": 2, "evidence": "verified", "source": "https://anchore.com", "note": "Syft and Grype free; commercial tiers on request" },
        "cross-framework": { "score": 2, "evidence": "vendor-stated", "source": "https://anchore.com", "note": "Policy engine supports multiple frameworks" },
        "audit-trail": { "score": 2, "evidence": "vendor-stated", "source": "https://anchore.com", "note": "Policy enforcement produces an evidence trail" }
      }
    },
    {
      "slug": "onekey",
      "name": "ONEKEY",
      "hq": "Düsseldorf, Germany",
      "category": "Industrial OT and IoT firmware security",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://onekey.com", "note": "No public free Annex III / Annex IV classifier" },
        "article-14": { "score": 0, "evidence": "verified", "source": "https://onekey.com", "note": "No public Article 14 workflow to ENISA or national CSIRTs" },
        "article-13": { "score": 0, "evidence": "verified", "source": "https://onekey.com", "note": "Not advertised as a public whitelabel intake portal" },
        "annex-i-applicability": { "score": 1, "evidence": "vendor-stated", "source": "https://onekey.com", "note": "Automated compliance reporting maps to Annex I" },
        "annex-vii": { "score": 2, "evidence": "vendor-stated", "source": "https://onekey.com", "note": "Technical file evidence exports described" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://onekey.com", "note": "Not a published headline" },
        "sbom-import": { "score": 3, "evidence": "verified", "source": "https://onekey.com", "note": "Binary decomposition is the headline capability" },
        "risk-assessment": { "score": 2, "evidence": "vendor-stated", "source": "https://onekey.com", "note": "Firmware vulnerability analysis" },
        "eu-residency": { "score": 3, "evidence": "verified", "source": "https://onekey.com", "note": "Germany-headquartered, native EU residency" },
        "pricing": { "score": 0, "evidence": "verified", "source": "https://onekey.com", "note": "Pricing not published" },
        "cross-framework": { "score": 2, "evidence": "vendor-stated", "source": "https://onekey.com", "note": "IEC 62443 and ETSI EN 303 645 alignment" },
        "audit-trail": { "score": 2, "evidence": "vendor-stated", "source": "https://onekey.com", "note": "Automated technical file evidence exports" }
      }
    },
    {
      "slug": "hackerone",
      "name": "HackerOne",
      "hq": "San Francisco, United States",
      "category": "Bug bounty and VDP platform",
      "isWinner": false,
      "cells": {
        "classification": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "Not in the scope of the product" },
        "article-14": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "No published Article 14 workflow to ENISA or national CSIRTs" },
        "article-13": { "score": 1, "evidence": "vendor-stated", "source": "https://www.hackerone.com", "note": "VDP covers intake, but a published CRA-framed CVD policy is not advertised" },
        "annex-i-applicability": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "No published Annex I applicability table" },
        "annex-vii": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "No published Annex VII generator" },
        "csaf": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "Not advertised" },
        "sbom-import": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "Not in the scope of the product" },
        "risk-assessment": { "score": 1, "evidence": "vendor-stated", "source": "https://www.hackerone.com", "note": "Severity scoring is part of triage" },
        "eu-residency": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "US-headquartered; EU residency is an enterprise option" },
        "pricing": { "score": 1, "evidence": "verified", "source": "https://www.hackerone.com", "note": "Free VDP tier; paid tiers not published" },
        "cross-framework": { "score": 0, "evidence": "verified", "source": "https://www.hackerone.com", "note": "Not framed as a multi-framework compliance platform" },
        "audit-trail": { "score": 2, "evidence": "vendor-stated", "source": "https://www.hackerone.com", "note": "Programmatic workflow with audit trail" }
      }
    }
  ]
}
