solidumsolidumCRAPro

Make your product CRA-ready and prove it on paper.

CRAPro takes your product and the standards the EU Cyber Resilience Act demands, and carries you the whole way — scope, scan, fix, prove — to auditor-ready CRA technical documentation where every claim walks back to the page it came from.

Prepares evidence and closes gaps. No credit card, no obligation — just early access.

Reporting obligations
11 September 2026

Actively-exploited vulnerabilities and severe incidents must be reported.

Full application
11 December 2027

Conformity assessment and CE marking obligations apply in full.

  1. Your product
  2. S1Scope
  3. S2Scan
  4. S3Fix
  5. S4Prove
  6. S5Document
  7. Sealed technical file

One line, from your product to a file that holds up.

Not a checklist to fill in by hand. CRAPro runs the whole assessment and keeps every step traceable to the standard's own text. It plays through below — jump in any time.

18%
Scope

Point CRAPro at your product. It decides which requirements apply — and which are excluded — each cited to the standard.

Applicability · EN 304 6364 of 5 in scope
  • FMT-1Default configuration is secure
    Ships with a network interface enabled by default.§5.1
  • FMT-4No universal default credentials
    Product exposes an administrative login.§5.2
  • ACM-2Vulnerabilities can be reported & handled
    Manufacturer maintains the software post-release.§6.3
  • CRY-7State-of-the-art cryptography
    Terminates TLS and stores key material.Annex K
  • PHY-3Tamper-evident physical enclosure
    Delivered as software only — no physical unit to tamper with.§8.4

Built for the person who has to defend it.

A PDF viewer shows you the standard. A GRC tool gives you a spreadsheet. CRAPro gives you a record an auditor can trust — because it was never allowed to say anything it could not cite.

Every standard the CRA needs
One data contract serves any standard the CRA points to. Adding a standard is a data act, not a rewrite.
Provenance is a type
Nothing asserts anything without a citation carrying the verbatim quote, its page, and a hash. Broken citations fail the build.
A tick that survives re-extraction
Each tick is stored against a hash of the exact requirement text — reword the source and it resurfaces as changed, never silently green.
Exclusions shown, never hidden
Auditors care about what you left out. Excluded requirements are drawn with the clause that excluded them.
Deterministic verdicts
The verdict arithmetic needs no LLM and is asserted by test. The same evidence always yields the same result.
A gate that refuses to send
Readiness is a number. The technical file will not leave while anything is inconclusive, unsigned, or stale — a named person presses send.

Built for every standard the CRA will demand.

The CRA leans on a whole family of harmonised standards — the ETSI EN 304 6xx product verticals and the EN 40000 horizontal series, ~41 in all under Standardisation Request M/606. Every one is a draft today; none is yet cited in the Official Journal. CRAPro is standard-agnostic by construction — EN 304 636 is simply the first it has taken all the way down.

1 · ETSI EN 304 6xxCompiled & fully cited
ETSI EN 304 636
Firewalls, intrusion detection & prevention
requirements
86
assessment criteria
86
verdict conditions
708
assessment activities
294
threats mapped
29
risk factors
16

First-party extraction of the 146-page ETSI draft.

Questions, answered straight.

The CRA (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements sold in the EU. Reporting obligations apply from 11 September 2026 and the full conformity and CE-marking obligations apply from 11 December 2027.

CRAPro carries a product through the whole lifecycle — scope the applicable requirements, scan the product against them, fix the gaps, prove each requirement with evidence, and generate the CRA technical documentation (Annex VII) — declaration of conformity, SBOM, risk assessment, user instructions — where every claim traces back to the standard's own text.

No. CRAPro prepares an evidence package and a provisional assessment to help you get ready. It does not confer conformity, and draft standards such as ETSI EN 304 636 are candidate standards not yet cited in the Official Journal.

Get ahead of the deadline.

Join the waitlist for early access. We'll reach out as CRAPro opens up — starting with teams whose products fall under the first CRA standards.

  • Early access before general availability
  • A say in which standards we compile next
  • No spam — a short note when it's your turn

We store your email only to contact you about CRAPro. Unsubscribe any time.