Nordchecks

Comparison

Nordchecks vs spreadsheets

The real competitor for most small manufacturers isn't another tool — it's a spreadsheet. A tab for components, a tab for vulnerabilities, a document template for the technical file. It's free, familiar, and it genuinely works at the start.

The problem is that the EU Cyber Resilience Act is continuous, not a one-time filing. This is an honest look at where a spreadsheet holds up, and where it quietly fails.

Side by side

 NordchecksSpreadsheets
CostFree during early access, then €99–€249/month.Free — you already have the spreadsheet.
SBOMGenerated from a lockfile and regenerated on every release, so it never goes stale.A component list you maintain by hand; out of date the moment someone forgets to update it.
Vulnerability monitoringAutomatic daily matching against vulnerability databases; new findings are flagged.Manual checking. New CVEs are published daily — a spreadsheet can't watch them, so you find out late or not at all.
24-hour reportingA ready ENISA reporting flow with a live 24h/72h/14-day clock and pre-filled notifications.No clock, no templates. During an incident you assemble the process under time pressure.
DocumentationTechnical file and Declaration of Conformity generated from current data.Hand-edited documents that drift out of sync with the product each release.
Staying currentStays true without maintenance — that's the whole point.Depends on someone remembering to update it. That's where it fails.

Which one fits you

Choose Nordchecks if

  • You ship more than once and can't keep re-checking components by hand.
  • You need continuous vulnerability monitoring, not a point-in-time snapshot.
  • You want to be ready for the 24-hour reporting clock before an incident hits.
  • You'd rather review compliance than rebuild it every release.

A spreadsheet is fine if

  • You're doing a one-time scoping exercise to understand what the CRA asks.
  • Your product never changes and you'll never add a component.
  • You have the DevOps capacity to wire up your own SBOM and scanning tooling.
  • You're still deciding whether the CRA applies at all (start with the free check).

Details about other products are based on their public positioning and can change — check their site for the latest.

Questions

Can I do CRA compliance in a spreadsheet?

You can start one in a spreadsheet, and for a one-time scoping exercise it's fine. It breaks down on the continuous parts: keeping the SBOM current every release, monitoring components against new vulnerabilities daily, and being ready to report an exploited vulnerability to ENISA within 24 hours. Those depend on someone remembering — which is exactly what fails under pressure.

What does a spreadsheet miss that software doesn't?

Three things above all: daily vulnerability monitoring (new CVEs appear every day and a spreadsheet can't watch them), the 24-hour reporting clock (no timer, no pre-filled ENISA templates), and documents that stay in sync with the current product. A spreadsheet is a snapshot; the CRA needs a live system.

Is switching from a spreadsheet a big project?

No. You upload a lockfile or component list, Nordchecks builds the SBOM, and monitoring starts. There's no implementation project — it's designed to replace the spreadsheet in minutes, not months.

Not sure what you need yet?

Run the free 3-minute scope check — it tells you your risk class, the deadlines that apply, and exactly which obligations you have to meet.