CRA compliance software

CRA compliance, without the spreadsheets.

For device makers, IoT startups and software vendors: everything the EU Cyber Resilience Act requires — SBOM, daily vulnerability monitoring, 24h reporting and your technical file — in one simple tool, no compliance department needed.

Everything the CRA requires, in one place

No spreadsheets, no consultants for the routine work. The four obligations, tracked per product and kept current.

ComplianceNordchecks
  • Software Bill of Materialslisted
  • Vulnerability monitoringdaily
  • 24-hour incident reportingready
  • Technical documentationgenerated
  • List what’s inside
  • We watch for new vulnerabilities daily
  • Your technical file, generated

How it works

1

Add your product

Name it and set its risk class — carried over from the free scope check.

2

Build your SBOM

Upload a lockfile, drop in a file, or list components by hand. We format it.

3

Turn on monitoring

We match your components against public vulnerability data every day.

4

Generate your documents

Technical file, EU Declaration of Conformity and your 24-hour reporting setup.

Questions

Is it free?

Free during early access — no card required. We’ll be clear about pricing well before that changes.

Do I need to know what an SBOM is?

No. Nordchecks builds it from your lockfile or a simple component list and explains each step in plain language.

Is this legal advice?

No. Nordchecks is a tool to help you do the compliance work. It is based on the text of Regulation (EU) 2024/2847 and is not legal advice.

Start with your product

Free during early access. Or run the 3-minute scope check first to see exactly what applies to you.