From 11 September 2026, EU law gives you 24 hours.
The Cyber Resilience Act requires software vendors to report actively exploited vulnerabilities to ENISA within 24 hours, even in products shipped years ago. CRAIR tells you what's in your product, what's exploited right now, and what you'd have to assess for the report.
Before the clock starts.
No credit card. Paste a repo or upload a lockfile, report ready in about a minute.
How it works
Point it at your product
A public GitHub URL, or upload your composer.lock / package-lock.json. Your source code is never read, only the dependency manifest.
We cross-reference three sources
Every dependency is checked against OSV.dev (known vulnerabilities), CISA KEV (actively exploited, the Art. 14 trigger) and FIRST EPSS (exploit probability).
Get your 2-page Snapshot
What you'd have to assess for ENISA reporting tomorrow, ranked findings with fixed-in versions, an SBOM summary, a shareable link and print-to-PDF.
Example scans of popular open-source projects
See what CRAIR produces before you sign up. These are public open-source projects, scanned automatically. Browse all.
The deadlines are not negotiable
| Date | Obligation |
|---|---|
| 11 Sep 2026 | CRA Art. 14 - 24-hour early warning to ENISA for actively exploited vulnerabilities, including products already on the market. 72-hour detailed notification, 14-day final report. |
| 11 Dec 2027 | Full CRA - SBOM, secure-by-design, CE marking, technical documentation for every product placed on the EU market. |
Penalties reach €15M or 2.5% of global turnover for the largest breaches. Micro and small enterprises can't be fined for missing the Article 14 reporting deadlines specifically, but the duty to report still applies, other breaches stay finable, and the full 2027 obligations carry their own penalties.
Pricing
Readiness Snapshot
- One-off scan per repo or lockfile
- Full 2-page report: KEV exposure, EPSS scores, SBOM summary
- Shareable link + PDF
Continuous monitoring
- Your products watched against fresh KEV data
- Alert the moment something you ship turns actively exploited
- ENISA report draft ready inside your 24-hour window
- All your products, one subscription
Questions we actually get
Do you access my source code?
No. We read the dependency manifest or lockfile (the list of packages and versions) nothing else. For private codebases, upload just the lockfile.
Does the CRA apply to my SaaS?
Honestly: it's contested. The CRA covers "products with digital elements"; pure cloud services mostly fall under NIS2 instead. If you ship anything installable (an agent, on-prem component, plugin, or device firmware) you're in scope.
I'm a small company, aren't we exempt from the fines?
Partly, and it's worth knowing exactly how. Micro and small enterprises (broadly, under 50 staff) can't be fined for missing the Article 14 reporting deadlines. But the obligation to report still applies; the exemption doesn't cover other CRA breaches or the full 2027 duties (SBOM, CE marking); market-surveillance authorities can still order corrective action; and it disappears the moment you grow past "small". Knowing what's actively exploited in your product matters whether or not a fine is attached to it.
What is the CISA KEV catalog, and why does it matter?
The Known Exploited Vulnerabilities catalog is a short list of vulnerabilities confirmed to be exploited in the wild. That's exactly the "actively exploited" trigger of CRA Art. 14 - which is why CRAIR leads with KEV matches instead of drowning you in hundreds of theoretical CVEs.
Which ecosystems are supported?
Composer (PHP) and npm (JavaScript/Node) today, lockfiles and manifests. More ecosystems are on the roadmap; tell us which one you need.
Is a Snapshot legal advice or a conformity assessment?
No. It's an automated readiness assessment built on public vulnerability data (OSV, CISA KEV, FIRST EPSS). It shows you where you stand; it doesn't certify you.
A 24-hour rule deserves a head start
Run the free Snapshot now. If the report comes back clean, you've earned your peace of mind. If it doesn't, better to know today than on day one of the clock.
Run a free Readiness Snapshot