CRA compliance, without the spreadsheets.
Everything the EU Cyber Resilience Act requires — SBOM, daily vulnerability monitoring, 24h reporting and your technical file — in one tool.
39 findings · 1 at risk
Report an incident before the clock runs out
Nordchecks tracks the 24-hour, 72-hour and 14-day ENISA deadlines and pre-fills each notification.
You don’t need to become an SBOM expert
Most people assume a CRA-compliant SBOM means learning tools and picking a format. It doesn’t — that’s exactly the part Nordchecks removes.
The hard way
- Install Syft or cdxgen
- Choose between CycloneDX, SPDX, SWID
- Handle firmware, vendored libs, hashes
- Set up CI/CD to regenerate on every release
- Match components against CVE databases yourself
With Nordchecks
- Upload what you already have — a lockfile (package-lock.json, requirements.txt, go.mod) or list components by hand for firmware.
- We build your CycloneDX SBOM automatically.
- We monitor it against vulnerability databases every day and generate your technical documentation.
No tools to install. No formats to learn. No DevOps required. If you can find one file in your project, you’re done.
Try it freeEverything the CRA requires, in one place
No spreadsheets, no consultants for the routine work. The four obligations, tracked per product and kept current.
- Software Bill of Materialslisted
- Vulnerability monitoringdaily
- 24-hour incident reportingready
- Technical documentationgenerated
- List what’s inside
- We watch for new vulnerabilities daily
- Your technical file, generated
Who it’s for
IoT & device makers
Connected hardware, firmware and the SBOM problem — handled without a DevOps team.
Read the guide →Machine builders
Add a cybersecurity chapter to the CE marking and technical file you already keep.
Read the guide →Software vendors (desktop, on-prem, apps)
The installable parts that fall in scope — desktop and mobile apps, on-prem, agents and SDKs.
Read the guide →How it works
Add your product
Name it and set its risk class — carried over from the free scope check.
Build your SBOM
Upload a lockfile, drop in a file, or list components by hand. We format it.
Turn on monitoring
We match your components against public vulnerability data every day.
Generate your documents
Technical file, EU Declaration of Conformity and your 24-hour reporting setup.
Questions
What does it cost?
Free during early access — no card required. After that, plans are €99/month (Starter, a single product) and €249/month (Pro, a product range). We’ll be clear about pricing well before early access ends.
Do I need to know what an SBOM is?
No. Nordchecks builds it from your lockfile or a simple component list and explains each step in plain language.
Is this legal advice?
No. Nordchecks is a tool to help you do the compliance work. It is based on the text of Regulation (EU) 2024/2847 and is not legal advice.
See exactly what you’ll get
Two real example documents, generated for a fictional product (“Gateway firmware v2.4”) so you can see the output before you sign up. Each page is watermarked “Sample — not for submission”.
EU Declaration of Conformity
PDF · 2 pages
The signed statement that your product conforms to the CRA — standards applied, product class and conformity route all filled in.
Download PDFAnnex VII technical documentation
PDF · 5 pages
The full technical file: product description, risk assessment, essential requirements, test reports and a Software Bill of Materials.
Download PDFMore about the samples on the sample documents page, or read Annex VII explained section by section.
Simple, transparent pricing
Free during early access — no card required. These are the plans once early access ends.
Starter
€99/month
For a single product: SBOM, daily vulnerability monitoring, incident reporting and technical documentation.
Free during early accessPro
€249/month
For a product range: everything in Starter across multiple products, with priority support.
Free during early accessStart with your product
Free during early access. Or run the 3-minute scope check first to see exactly what applies to you.