Make your product CRA-ready and prove it on paper.
CRAPro takes your product and the standards the EU Cyber Resilience Act demands, and carries you the whole way — scope, scan, fix, prove — to auditor-ready CRA technical documentation where every claim walks back to the page it came from.
Prepares evidence and closes gaps. No credit card, no obligation — just early access.
Reporting obligations
11 September 2026
––days––hours––minutes––seconds
Actively-exploited vulnerabilities and severe incidents must be reported.
Full application
11 December 2027
––days––hours––minutes––seconds
Conformity assessment and CE marking obligations apply in full.
Your product
S1Scope
S2Scan
S3Fix
S4Prove
S5Document
Sealed technical file
One line, from your product to a file that holds up.
Not a checklist to fill in by hand. CRAPro runs the whole assessment and keeps every step traceable to the standard's own text. It plays through below — jump in any time.
18%
Scope
Point CRAPro at your product. It decides which requirements apply — and which are excluded — each cited to the standard.
Applicability · EN 304 6364 of 5 in scope
FMT-1Default configuration is secure
Ships with a network interface enabled by default.§5.1
FMT-4No universal default credentials
Product exposes an administrative login.§5.2
ACM-2Vulnerabilities can be reported & handled
Manufacturer maintains the software post-release.§6.3
CRY-7State-of-the-art cryptography
Terminates TLS and stores key material.Annex K
PHY-3Tamper-evident physical enclosure
Delivered as software only — no physical unit to tamper with.§8.4
Built for the person who has to defend it.
A PDF viewer shows you the standard. A GRC tool gives you a spreadsheet. CRAPro gives you a record an auditor can trust — because it was never allowed to say anything it could not cite.
Every standard the CRA needs
One data contract serves any standard the CRA points to. Adding a standard is a data act, not a rewrite.
Provenance is a type
Nothing asserts anything without a citation carrying the verbatim quote, its page, and a hash. Broken citations fail the build.
A tick that survives re-extraction
Each tick is stored against a hash of the exact requirement text — reword the source and it resurfaces as changed, never silently green.
Exclusions shown, never hidden
Auditors care about what you left out. Excluded requirements are drawn with the clause that excluded them.
Deterministic verdicts
The verdict arithmetic needs no LLM and is asserted by test. The same evidence always yields the same result.
A gate that refuses to send
Readiness is a number. The technical file will not leave while anything is inconclusive, unsigned, or stale — a named person presses send.
Built for every standard the CRA will demand.
The CRA leans on a whole family of harmonised standards — the ETSI EN 304 6xx product verticals and the EN 40000 horizontal series, ~41 in all under Standardisation Request M/606. Every one is a draft today; none is yet cited in the Official Journal. CRAPro is standard-agnostic by construction — EN 304 636 is simply the first it has taken all the way down.
1 · ETSI EN 304 6xxCompiled & fully cited
ETSI EN 304 636
Firewalls, intrusion detection & prevention
requirements
86
assessment criteria
86
verdict conditions
708
assessment activities
294
threats mapped
29
risk factors
16
First-party extraction of the 146-page ETSI draft.
2 · ETSI EN 304 6xxDraft · public
ETSI EN 304 617
Standalone & embedded browsers
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
84 requirements · 59 assessment criteria in the working draft
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
3 · ETSI EN 304 6xxDraft · public
ETSI EN 304 623
Boot managers
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
≈98 requirements in the working draft
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
4 · ETSI EN 304 6xxDraft · public
ETSI EN 304 620
Virtual Private Networks (VPNs)
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
15 threats · 14 risk factors modelled in the working draft
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
5 · ETSI EN 304 6xxDraft · public
ETSI EN 304 622
SIEM systems
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
≈26 requirements in the working draft
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
6 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 626
Operating systems
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
7 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 627
Routers, modems & switches
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
8 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 619
Antivirus & anti-malware
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
9 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 635
Hypervisors & container runtimes
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
10 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 618
Password managers
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
11 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 624
PKI & certificate issuance
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
12 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 632
Smart-home security products
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
13 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 633
Internet-connected toys
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
14 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 634
Personal wearables
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
15 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 642
Telecom network functions
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
16 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 631
Smart-home virtual assistants
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
17 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 621
Network management systems
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
18 · ETSI EN 304 6xxDraft · M/606
ETSI EN 304 625
Physical & virtual network interfaces
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
19 · EN 40000 · horizontalDraft · M/606
prEN 40000-1-2
Principles for cyber resilience
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
20 · EN 40000 · horizontalDraft · M/606
prEN 40000-1-3
Vulnerability handling requirements
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
21 · EN 40000 · horizontalDraft · M/606
prEN 40000-1-4
Generic security requirements
essential requirements
21
product requirements
13
vuln-handling requirements
8
conformity modules
4
CRA annexes
8
incident reporting
24·72h
The fixed CRA target every product meets — Reg. (EU) 2024/2847, Annex I.
Questions, answered straight.
The CRA (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements sold in the EU. Reporting obligations apply from 11 September 2026 and the full conformity and CE-marking obligations apply from 11 December 2027.
CRAPro carries a product through the whole lifecycle — scope the applicable requirements, scan the product against them, fix the gaps, prove each requirement with evidence, and generate the CRA technical documentation (Annex VII) — declaration of conformity, SBOM, risk assessment, user instructions — where every claim traces back to the standard's own text.
No. CRAPro prepares an evidence package and a provisional assessment to help you get ready. It does not confer conformity, and draft standards such as ETSI EN 304 636 are candidate standards not yet cited in the Official Journal.
Get ahead of the deadline.
Join the waitlist for early access. We'll reach out as CRAPro opens up — starting with teams whose products fall under the first CRA standards.