CRA Desk

Your SBOM desk for the CRA

Cyber Resilience Act readiness for small software vendors

If a vulnerability in your dependencies turns out to be actively exploited, you have 24 hours to file an early warning with ENISA - for products you shipped years ago too. CRA Desk is your SBOM desk for the CRA.

AWS Ireland hosting, EU invoicing, DPA on request.

24 hours to report an actively exploited vulnerability - from 11 September 2026

24 hours

Early warning to the CSIRT coordinator and ENISA, from the moment you become aware.

72 hours

Vulnerability notification with what you know and what you are doing about it.

14 days

Final report, counted from a corrective or mitigating measure being available.

Start in CI, for free

Point the CRA Desk scan at the SBOM your build already produces - GitHub Action or GitLab CI/CD component. It reports what your inventory does and does not tell you and what the reporting obligation needs from you, right in your pipeline output, no account required.

- uses: actions/checkout@v4
- run: npx @cyclonedx/cdxgen -o sbom.json .
- uses: mmalinowski/cradesk-action@v1
  with:
    sbom-path: sbom.json

Only the first step changes with your stack - the CRA Desk step after it is identical everywhere.

Setup blocks, output paths and traps per ecosystem

How the product works

Watching for vulnerabilities is table stakes. Filing before the clock runs out, telling your users and keeping a record of both is the job.

  1. 1

    Classify the product - scope, class and the conformity route that follows, with the article behind each answer.

  2. 2

    Ingest the SBOM from CI, keep it per product version and diff it as it changes.

  3. 3
    • Watch OSV advisories against your components - language packages and Alpine system packages alike.
    • CISA KEV and EU KEV each supply the "actively exploited" flag, independently - a flag, not a guess.
    • Dismissing a false match saves the reason in the standard VEX format, not just a checkbox.
  4. 4
    • Deadline timers from the moment you became aware, with the evidence of when that was (alert delivered, match found, KEV listing per source) and a change history that is only ever added to.
    • Drafts built from the fields of ENISA's Single Reporting Platform, counting what is still mandatory.
    • For an incident, the Article 14(5) severity questions: asked, never answered for you.
  5. 5
    • Affected product versions worked out from your own SBOM history: affected, not affected or not checked, never guessed.
    • A user advisory for Article 14(8) in CSAF 2.0 plus a readable version, from the same input. Sending it stays yours.
    • A monthly evidence report: what was watched, how well, and what was not measured.

Your SBOM stays in our environment - never shared, never sold.

Your CI/CD

  1. Your pipeline generates the SBOM
  2. Uploaded to CRA Desk
  3. Stays in our environment

CRA Desk's watch (background)

  1. OSV, CISA KEV, EU KEV and NVD
  2. Refreshed on a schedule
  3. Matched against your components
Alerts, the Article 14 case, user advisories and a monthly evidence report
See exactly which ecosystems are watched

Plans

Free

0 EUR

  • 1 product
  • SBOM in the panel
  • CVD policy and security.txt generators
  • No monitoring

Starter

29 EUR/mo

  • 2 products

Everything in Free, plus:

  • OSV watch with CISA KEV and EU KEV alerts, Alpine images included
  • Article 14 workflow: deadline timers, awareness evidence and SRP-field drafts
  • Monthly evidence report by e-mail

Team

99 EUR/mo

  • 5 products
  • 5 users

Everything in Starter, plus:

  • Annex VII technical-documentation skeleton
  • SBOM diff
  • Custom document templates
  • Article 14(8) user notifications: CSAF 2.0 advisory and dispatch log
  • AI-agent access over MCP: read-only or read/write tokens, every change approved by a person

Enterprise

Custom

Everything in Team, plus:

  • More products and seats than Team
  • Custom CI or reporting integrations
  • Invoicing on contract terms
Talk to us

Prices are net, excluding VAT.

Hosted in AWS Ireland (eu-west-1). DPA on request and an EU invoice carrying your VAT ID on every paid plan.

What this does not do

Nothing is ever submitted to ENISA or a CSIRT on your behalf: the product computes deadlines, drafts reports and nags - a human reviews and files. Vulnerability coverage is declared, never claimed to be complete.

We tell you exactly what's covered and what isn't. Matching runs on OSV advisories for the language ecosystems and Alpine system packages listed on the coverage page - Debian and Ubuntu packages, images built on them and components with no purl aren't matched at all, and NVD only adds a CVSS score once a match already exists, never finds one. CISA KEV and ENISA's EU KEV each raise the actively-exploited flag, dated per source. If one of our sources goes quiet, the panel names it and says since when, so you don't mistake silence for "no vulnerabilities".

We hold ourselves to the same rule: our own security.txt and CVD policy are generated by this product.

Read them

Get the full report by e-mail

One e-mail when the classifier and the reporting workflow open up. No newsletter.

Write to us