CRA Desk

Frequently asked questions

Short, direct answers. For the long version of the September deadline, see the article; for a scope verdict on your own product, run the classifier - it cites the article of the regulation behind every answer.

What does CRA Desk actually do?

It watches your components against vulnerability advisories, flags which ones are CRA-reportable, and drafts the Article 14 report against a deadline timer computed from the regulation itself. It also generates the artefacts Annex I asks for: an SBOM per product version, a CVD policy and security.txt and an Annex VII technical-documentation skeleton.

Is CRA Desk a vulnerability scanner?

It runs SCA-style matching underneath - OSV advisories, CISA KEV - but that matching is an input, not the product. A generic scanner stops at a CVE list. CRA Desk's job starts there: the 24h/72h/ 14-day timers Article 14 sets, a draft report per stage and a human who files it.

Does the CRA apply to me if I only ship a hosted service?

Generally no. Article 3(2) scopes the regulation to a product's own "remote data processing solutions" - software that runs on someone else's device is in, a browser-only web app usually isn't. This is a per-product question, not a company-wide one, so run the classifier against your actual product rather than relying on a rule of thumb.

What's matched against vulnerabilities and what isn't?

Matching runs on OSV advisories across nine package ecosystems, with CISA KEV supplying the "actively exploited" flag. NVD only adds a CVSS score to a match that already exists - it never finds one on its own. System packages (Debian, Ubuntu, Alpine), container images and components with no package URL aren't matched at all. The full boundary is on the coverage page.

What is VEX and why does it matter?

Dismissing a false match records the reason in the OpenVEX format, not just a status flip. If an auditor or a customer later asks why a match doesn't count, you have a standard, portable artifact instead of a memory.

How much does it cost?

Free covers one product, an in-panel SBOM and the CVD policy/security.txt generators, with no monitoring. Starter and Team are self-serve at fixed EUR prices; Enterprise is invoiced on contract terms. No paid tier is gated behind a sales call.

Where is data hosted?

AWS Ireland, with a DPA available on request and EU invoicing.

Do you hold yourself to the same rules you sell?

Yes. Our own security.txt and CVD policy are generated by this product - see the live page.

Does CRA Desk replace a notified body or a lawyer?

No. Class II and Annex IV products still need a notified body for the 2027 conformity assessment, and nothing here is legal advice. CRA Desk covers the Article 14 reporting workflow and the technical-documentation skeleton the regulation asks for - not certification.

Can I trust the classifier's verdict?

It runs a versioned, rule-based ruleset in your browser - not a model guessing - and every verdict cites the article of the regulation it came from. Nothing you enter leaves the page.


This is a compliance aid, not legal advice. The obligations rest with the manufacturer.