Regulation (EU) 2024/2847

Does the CRA apply to your product?

CRA compliance software for small manufacturers — wherever you’re based. If you sell connected products in the EU, the CRA applies to you. Start with a free 3-minute check.

See the software

Reporting obligation · in forceFull compliance · T−452 days

One tool for all four obligations

In scope? These are your four obligations

Every product with digital elements in the CRA’s default class owes the same four things.

What is the CRA?

SBOM per product

A machine-readable list of the third-party software inside your product.

Guide

Vulnerability monitoring

Track your components against known vulnerabilities, continuously.

Guide

24h incident reporting

A ready process to notify ENISA within 24 hours of an exploit.

Guide

CE marking + documentation

Technical file, Declaration of Conformity and the CE mark.

Guide

Nordchecks handles all four

One place for your SBOM, monitoring, reporting and documents.

app.nordchecks.com
Products4 tracked

39 findings · 1 at risk

ProductSBOMsFindingsStatus
Gateway firmware
IoT device · v2.4
3
35
Risk
Payments API
Software · v1.9
1
0
OK
Control panel
Machine · v3.1
2
4
OK
Sensor hub
Firmware · v0.9
0
Setup

Simple pricing

Starter

€99/mo

1 product

  • SBOM per product
  • Daily vulnerability monitoring
  • 24h incident reporting
  • Annex VII technical file + Declaration of Conformity
Start free while in beta

Pro

€249/mo

Unlimited products

  • SBOM per product
  • Daily vulnerability monitoring
  • 24h incident reporting
  • Annex VII technical file + Declaration of Conformity
Start free while in beta

Free during beta — pricing applies at launch.

Frequently asked questions

Does the CRA apply to SaaS?

Pure cloud services with no installable component generally fall outside the CRA — those are addressed by NIS2. But a SaaS with a mandatory local agent, app or firmware, or backend processing essential to a physical product, is in scope. The checker asks about exactly this.

Does the CRA apply to non-EU companies?

Yes. The CRA applies to every product with digital elements placed on the EU market, regardless of where the manufacturer is based. If you sell connected products into the EU from the US, UK, Asia or anywhere else, the same obligations apply — and you may also need an EU-based authorised representative or importer to place the product on the market.

What are the fines?

Non-compliance with the essential requirements can be penalised with fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher.

Is this legal advice?

No. This tool gives an indicative scope assessment based on the text of Regulation (EU) 2024/2847. It does not constitute legal advice — confirm your classification with qualified counsel before relying on it.

Who built this?

An independent tool for hardware and software makers preparing for the CRA. It is not affiliated with, nor endorsed by, the European Union, the European Commission or ENISA.