CRA compliance software
CRA compliance, without the spreadsheets.
For device makers, IoT startups and software vendors: everything the EU Cyber Resilience Act requires — SBOM, daily vulnerability monitoring, 24h reporting and your technical file — in one simple tool, no compliance department needed.
Everything the CRA requires, in one place
No spreadsheets, no consultants for the routine work. The four obligations, tracked per product and kept current.
- Software Bill of Materialslisted
- Vulnerability monitoringdaily
- 24-hour incident reportingready
- Technical documentationgenerated
- List what’s inside
- We watch for new vulnerabilities daily
- Your technical file, generated
Who it’s for
IoT & device makers
Connected hardware, firmware and the SBOM problem — handled without a DevOps team.
Read the guide →Machine builders
Add a cybersecurity chapter to the CE marking and technical file you already keep.
Read the guide →Software vendors (desktop, on-prem, apps)
The installable parts that fall in scope — desktop and mobile apps, on-prem, agents and SDKs.
Read the guide →How it works
Add your product
Name it and set its risk class — carried over from the free scope check.
Build your SBOM
Upload a lockfile, drop in a file, or list components by hand. We format it.
Turn on monitoring
We match your components against public vulnerability data every day.
Generate your documents
Technical file, EU Declaration of Conformity and your 24-hour reporting setup.
Questions
Is it free?
Free during early access — no card required. We’ll be clear about pricing well before that changes.
Do I need to know what an SBOM is?
No. Nordchecks builds it from your lockfile or a simple component list and explains each step in plain language.
Is this legal advice?
No. Nordchecks is a tool to help you do the compliance work. It is based on the text of Regulation (EU) 2024/2847 and is not legal advice.
Start with your product
Free during early access. Or run the 3-minute scope check first to see exactly what applies to you.