Comparison
Nordchecks vs spreadsheets
The real competitor for most small manufacturers isn't another tool — it's a spreadsheet. A tab for components, a tab for vulnerabilities, a document template for the technical file. It's free, familiar, and it genuinely works at the start.
The problem is that the EU Cyber Resilience Act is continuous, not a one-time filing. This is an honest look at where a spreadsheet holds up, and where it quietly fails.
Side by side
| Nordchecks | Spreadsheets | |
|---|---|---|
| Cost | Free during early access, then €99–€249/month. | Free — you already have the spreadsheet. |
| SBOM | Generated from a lockfile and regenerated on every release, so it never goes stale. | A component list you maintain by hand; out of date the moment someone forgets to update it. |
| Vulnerability monitoring | Automatic daily matching against vulnerability databases; new findings are flagged. | Manual checking. New CVEs are published daily — a spreadsheet can't watch them, so you find out late or not at all. |
| 24-hour reporting | A ready ENISA reporting flow with a live 24h/72h/14-day clock and pre-filled notifications. | No clock, no templates. During an incident you assemble the process under time pressure. |
| Documentation | Technical file and Declaration of Conformity generated from current data. | Hand-edited documents that drift out of sync with the product each release. |
| Staying current | Stays true without maintenance — that's the whole point. | Depends on someone remembering to update it. That's where it fails. |
Which one fits you
Choose Nordchecks if
- You ship more than once and can't keep re-checking components by hand.
- You need continuous vulnerability monitoring, not a point-in-time snapshot.
- You want to be ready for the 24-hour reporting clock before an incident hits.
- You'd rather review compliance than rebuild it every release.
A spreadsheet is fine if
- You're doing a one-time scoping exercise to understand what the CRA asks.
- Your product never changes and you'll never add a component.
- You have the DevOps capacity to wire up your own SBOM and scanning tooling.
- You're still deciding whether the CRA applies at all (start with the free check).
Details about other products are based on their public positioning and can change — check their site for the latest.
Questions
Can I do CRA compliance in a spreadsheet?
You can start one in a spreadsheet, and for a one-time scoping exercise it's fine. It breaks down on the continuous parts: keeping the SBOM current every release, monitoring components against new vulnerabilities daily, and being ready to report an exploited vulnerability to ENISA within 24 hours. Those depend on someone remembering — which is exactly what fails under pressure.
What does a spreadsheet miss that software doesn't?
Three things above all: daily vulnerability monitoring (new CVEs appear every day and a spreadsheet can't watch them), the 24-hour reporting clock (no timer, no pre-filled ENISA templates), and documents that stay in sync with the current product. A spreadsheet is a snapshot; the CRA needs a live system.
Is switching from a spreadsheet a big project?
No. You upload a lockfile or component list, Nordchecks builds the SBOM, and monitoring starts. There's no implementation project — it's designed to replace the spreadsheet in minutes, not months.
Other comparisons
Not sure what you need yet?
Run the free 3-minute scope check — it tells you your risk class, the deadlines that apply, and exactly which obligations you have to meet.