Nordchecks

CRA compliance, without the spreadsheets.

Everything the EU Cyber Resilience Act requires — SBOM, daily vulnerability monitoring, 24h reporting and your technical file — in one tool.

app.nordchecks.com
Products4 tracked

39 findings · 1 at risk

ProductSBOMsFindingsStatus
Gateway firmware
IoT device · v2.4
3
35
Risk
Payments API
Software · v1.9
1
0
OK
Control panel
Machine · v3.1
2
4
OK
Sensor hub
Firmware · v0.9
0
Setup

Report an incident before the clock runs out

Nordchecks tracks the 24-hour, 72-hour and 14-day ENISA deadlines and pre-fills each notification.

app.nordchecks.com/reporting
Incident · Gateway firmware v2.4reported 12h ago
Early warning24h
Submitted
11:48 after report
Notification72h
47:12:36
time remaining
Final report14d
13d 06h
scheduled

You don’t need to become an SBOM expert

Most people assume a CRA-compliant SBOM means learning tools and picking a format. It doesn’t — that’s exactly the part Nordchecks removes.

The hard way

  • Install Syft or cdxgen
  • Choose between CycloneDX, SPDX, SWID
  • Handle firmware, vendored libs, hashes
  • Set up CI/CD to regenerate on every release
  • Match components against CVE databases yourself

With Nordchecks

  1. Upload what you already have — a lockfile (package-lock.json, requirements.txt, go.mod) or list components by hand for firmware.
  2. We build your CycloneDX SBOM automatically.
  3. We monitor it against vulnerability databases every day and generate your technical documentation.

No tools to install. No formats to learn. No DevOps required. If you can find one file in your project, you’re done.

Try it free

Everything the CRA requires, in one place

No spreadsheets, no consultants for the routine work. The four obligations, tracked per product and kept current.

ComplianceNordchecks
  • Software Bill of Materialslisted
  • Vulnerability monitoringdaily
  • 24-hour incident reportingready
  • Technical documentationgenerated
  • List what’s inside
  • We watch for new vulnerabilities daily
  • Your technical file, generated

How it works

1

Add your product

Name it and set its risk class — carried over from the free scope check.

2

Build your SBOM

Upload a lockfile, drop in a file, or list components by hand. We format it.

3

Turn on monitoring

We match your components against public vulnerability data every day.

4

Generate your documents

Technical file, EU Declaration of Conformity and your 24-hour reporting setup.

Questions

What does it cost?

Free during early access — no card required. After that, plans are €99/month (Starter, a single product) and €249/month (Pro, a product range). We’ll be clear about pricing well before early access ends.

Do I need to know what an SBOM is?

No. Nordchecks builds it from your lockfile or a simple component list and explains each step in plain language.

Is this legal advice?

No. Nordchecks is a tool to help you do the compliance work. It is based on the text of Regulation (EU) 2024/2847 and is not legal advice.

Simple, transparent pricing

Free during early access — no card required. These are the plans once early access ends.

Starter

€99/month

For a single product: SBOM, daily vulnerability monitoring, incident reporting and technical documentation.

Free during early access

Pro

€249/month

For a product range: everything in Starter across multiple products, with priority support.

Free during early access

Start with your product

Free during early access. Or run the 3-minute scope check first to see exactly what applies to you.