Your SBOM desk for the CRA
Cyber Resilience Act readiness for small software vendors
If a vulnerability in your dependencies turns out to be actively exploited, you have 24 hours to file an early warning with ENISA - for products you shipped years ago too. CRA Desk is your SBOM desk for the CRA.
AWS Ireland hosting, EU invoicing, DPA on request.
24 hours to report an actively exploited vulnerability - from 11 September 2026
24 hours
Early warning to the CSIRT coordinator and ENISA, from the moment you become aware.
72 hours
Vulnerability notification with what you know and what you are doing about it.
14 days
Final report, counted from a corrective or mitigating measure being available.
Start in CI, for free
Point the CRA Desk scan at the SBOM your build already produces - GitHub Action or GitLab CI/CD component. It reports what your inventory does and does not tell you and what the reporting obligation needs from you, right in your pipeline output, no account required.
- uses: actions/checkout@v4
- run: npx @cyclonedx/cdxgen -o sbom.json .
- uses: mmalinowski/cradesk-action@v1
with:
sbom-path: sbom.jsonOnly the first step changes with your stack - the CRA Desk step after it is identical everywhere.
Setup blocks, output paths and traps per ecosystemHow the product works
Watching for vulnerabilities is table stakes. Filing before the clock runs out, telling your users and keeping a record of both is the job.
- 1
Classify the product - scope, class and the conformity route that follows, with the article behind each answer.
- 2
Ingest the SBOM from CI, keep it per product version and diff it as it changes.
- 3
- Watch OSV advisories against your components - language packages and Alpine system packages alike.
- CISA KEV and EU KEV each supply the "actively exploited" flag, independently - a flag, not a guess.
- Dismissing a false match saves the reason in the standard VEX format, not just a checkbox.
- 4
- Deadline timers from the moment you became aware, with the evidence of when that was (alert delivered, match found, KEV listing per source) and a change history that is only ever added to.
- Drafts built from the fields of ENISA's Single Reporting Platform, counting what is still mandatory.
- For an incident, the Article 14(5) severity questions: asked, never answered for you.
- 5
- Affected product versions worked out from your own SBOM history: affected, not affected or not checked, never guessed.
- A user advisory for Article 14(8) in CSAF 2.0 plus a readable version, from the same input. Sending it stays yours.
- A monthly evidence report: what was watched, how well, and what was not measured.
Your SBOM stays in our environment - never shared, never sold.
Your CI/CD
- Your pipeline generates the SBOM
- Uploaded to CRA Desk
- Stays in our environment
CRA Desk's watch (background)
- OSV, CISA KEV, EU KEV and NVD
- Refreshed on a schedule
- Matched against your components
Plans
Free
0 EUR
- 1 product
- SBOM in the panel
- CVD policy and security.txt generators
- No monitoring
Starter
29 EUR/mo
- 2 products
Everything in Free, plus:
- OSV watch with CISA KEV and EU KEV alerts, Alpine images included
- Article 14 workflow: deadline timers, awareness evidence and SRP-field drafts
- Monthly evidence report by e-mail
Team
99 EUR/mo
- 5 products
- 5 users
Everything in Starter, plus:
- Annex VII technical-documentation skeleton
- SBOM diff
- Custom document templates
- Article 14(8) user notifications: CSAF 2.0 advisory and dispatch log
- AI-agent access over MCP: read-only or read/write tokens, every change approved by a person
Enterprise
Custom
Everything in Team, plus:
- More products and seats than Team
- Custom CI or reporting integrations
- Invoicing on contract terms
Prices are net, excluding VAT.
Hosted in AWS Ireland (eu-west-1). DPA on request and an EU invoice carrying your VAT ID on every paid plan.
What this does not do
Nothing is ever submitted to ENISA or a CSIRT on your behalf: the product computes deadlines, drafts reports and nags - a human reviews and files. Vulnerability coverage is declared, never claimed to be complete.
We tell you exactly what's covered and what isn't. Matching runs on OSV advisories for the language ecosystems and Alpine system packages listed on the coverage page - Debian and Ubuntu packages, images built on them and components with no purl aren't matched at all, and NVD only adds a CVSS score once a match already exists, never finds one. CISA KEV and ENISA's EU KEV each raise the actively-exploited flag, dated per source. If one of our sources goes quiet, the panel names it and says since when, so you don't mistake silence for "no vulnerabilities".
We hold ourselves to the same rule: our own security.txt and CVD policy are generated by this product.
Read themGet the full report by e-mail
One e-mail when the classifier and the reporting workflow open up. No newsletter.
Write to us