Compliance made easy
crality turns the requirements of the Cyber Resilience Act from an administrative uphill battle into a simple, transparent and secure process.
- Software Bill of Materials (SBOM)
- Vulnerability management
- Reporting obligations
Made in Germany. Built for EU regulations.
Ready for the CRA
Every tool in one place — so compliance is finally within reach.
The CRA roadmap
The Cyber Resilience Act takes effect in stages. These three dates are especially relevant for manufacturers and distributors of products with digital elements.
11 Dec 2024
The Cyber Resilience Act becomes law
The official entry into force kicks off a three-year transition period — your window to bring your processes up to speed, step by step.
11 Sep 2026
Reporting obligations for companies
From this date, the extensive reporting obligations for critical security incidents and actively exploited vulnerabilities kick in.
11 Dec 2027
All requirements must be met
Once the transition period ends, products made available in the EU must fully meet all requirements and obligations.
11 Dec 2024
The Cyber Resilience Act becomes law
The official entry into force kicks off a three-year transition period — your window to bring your processes up to speed, step by step.
11 Sep 2026
Reporting obligations for companies
From this date, the extensive reporting obligations for critical security incidents and actively exploited vulnerabilities kick in.
11 Dec 2027
All requirements must be met
Once the transition period ends, products made available in the EU must fully meet all requirements and obligations.
Compliance starts now
Start with the Free plan and prepare your company step by step for the requirements of the Cyber Resilience Act.
With zero risks or commitments.
Common questions
The Cyber Resilience Act raises a lot of questions — here you'll find the most important answers.
-
The Cyber Resilience Act applies across all industries and regardless of company size to everyone who develops, imports or distributes products with digital elements in the EU. This covers nearly all hardware devices and software solutions that can connect to a network or other systems — think apps, smart home devices, routers or connected industrial machinery.
Pure SaaS offerings are generally exempt from the Cyber Resilience Act, as long as they don't serve as remote data processing for a device's function. Also exempt are areas already covered by their own, stricter rules, such as medical devices or motor vehicles.
So if your company makes connected software or hardware available on the EU market, it's very likely subject to the obligations of the Cyber Resilience Act. But even if you're not formally covered, implementing the requirements can still pay off. Adopt the rules voluntarily and you'll turn plain compliance into a real competitive edge, earn deep trust from your customers and future-proof your information security almost as a happy side effect. -
From 11 September 2026, the first phase of the Cyber Resilience Act that's genuinely relevant in practice kicks in, with strict, time-critical reporting obligations. From that date, you'll have to report actively exploited vulnerabilities and serious security incidents that put the security of products with digital elements at risk.
The reporting process follows three stages: an initial early warning is due within 24 hours of you becoming aware, followed by a detailed update after 72 hours and a final report once the vulnerability or incident has been resolved. -
The Cyber Resilience Act brings a lot of regulatory complexity with it. The extensive requirements and strict provisions of the Cyber Resilience Act can pose challenges that shouldn't be underestimated — even for companies that already have a strong security posture.
This is exactly where crality comes in: instead of fighting your way through dense legal texts, you're guided step by step through the compliance process by smart workflows — from the Software Bill of Materials through vulnerability analysis all the way to the reporting obligations.
So with crality, you master the complex requirements of the CRA with ease, minimize the administrative effort involved and turn your products' conformity into an efficient routine. -
crality's clear goal is to support you fully across every aspect of the Cyber Resilience Act. Since the Act takes effect in stages and the EU is still fine-tuning details, guidance and technical standards in parallel — like the Single Reporting Platform — we keep developing crality in an agile, forward-looking way.
For you, that means you always have exactly the features you need, right when they matter. crality will let you meet the reporting obligations that apply from 11 September 2026 precisely on time, for example. And up until the law fully enters into force on 11 December 2027, we'll keep adding features as the details are settled.
So if you get started with crality now, your compliance grows organically along with the requirements — and you can look ahead to the full entry into force of the Cyber Resilience Act with complete peace of mind. -
Yes, absolutely. The crality Free plan gives you a free, no-strings way to get started — and "free" definitely doesn't mean "feature-poor" here. The Free plan is fully multi-tenant, for instance, and lets you add as many products as you like. With it you can easily create Software Bills of Materials (SBOMs) for all your products, run vulnerability analyses and even comprehensively meet the reporting obligations that apply from 11 Sep 2026.
In the interest of transparency, though, we should mention that a Pro plan with a significantly expanded feature set is on the way. Since new features land there first, companies after a comprehensive way to address everything the Cyber Resilience Act requires will be happier with Pro in the long run. Even so, the Free plan stays a genuinely useful, permanent solution — with no hidden costs and no expiry date.
Start simple. Scale flexibly.
Choose the plan that fits you — from a free starting point to individual support.
Coming soon
Extended feature set
Pro
- Everything in the Free plan
- VEX support
- Permissions
- Change history
- Automations
No cost
No commitment
Free
- Multi-tenancy
- Unlimited products
- Software Bill of Materials (SBOM)
- Vulnerability management
- Reporting obligations
On request
Extensive support
Enterprise
- Everything in the Free plan
- Everything in the Pro plan
- Custom terms
- Service Level Agreements
- Dedicated support