CRA READY
No known release blockers.
- SBOM current.
- Security review complete.
- Pentest complete.
- Risk assessment current.
- Evidence complete.
CRA reporting obligations active since 11 Sep 2026Learn more
We're in beta. Launch Nov.
Our security agents continuously review your code and dependencies, maintain your CRA evidence and tell you when something needs your attention.
From code to CRA-ready. And ready afterwards.
main · Release v4.8.2
The Cyber Resilience Act turns cybersecurity into a continuous product responsibility.
You shouldn't need to become a CRA expert.
We automate the work.
Finding a CVE is easy.
The hard part is knowing whether it affects your product. Our agents connect code, dependencies and context to show what actually matters.
91%
95%
99%
90%
Every connected repository is continuously reviewed by specialized security agents. Your repository becomes the source of truth.
Automatic SBOM creation and continuous dependency tracking.
Continuous CVE monitoring across your software supply chain.
Static analysis, secrets detection and security-focused code review.
New dependencies, suspicious packages, unexpected changes and dependency risks are continuously monitored.
Our agents analyze how your application can actually be attacked.
Agentic security testing continuously challenges approved test environments and verifies potential weaknesses.
No annual snapshot. Continuous testing.
Every release gets a simple answer.
CRA READY
ACTION REQUIRED
Critical · Authentication bypass
Potentially exploitable in production.
High · Vulnerable dependency
Fix available.
No 80-page report.
Just what matters.
Security findings shouldn't disappear into tickets.
Every relevant scan, test, fix and decision becomes evidence.
Your CRA workspace stays continuously updated with:
11/11
When someone asks how you reached your conformity decision, the evidence is already there.
CRA reporting obligations are already active.
We escalate reportable vulnerabilities and severe incidents immediately.
Monitored for your product's entire lifecycle.
Example · Detected 09:42
Early-warning deadline
23h 51m
We prepare the information your team needs for the reporting process.
Your source code is your company.
We treat it that way.
We never need permission to modify your production repository.
Code is analyzed inside isolated environments and removed after processing.
We store findings and compliance evidence — not a permanent copy of your codebase.
Customer data is processed and stored in the EU.
Every customer environment is isolated.
No long-lived developer tokens sitting in our database.
Security-relevant actions are logged.
No seats. No developer licenses. No surprise scanning bills.
Freeup to 4 repositories
For teams that want continuous visibility.
Know what's happening.
€99/ month for up to 8 repositoriesEach additional repository €5 / month
For teams that want to become and stay CRA-ready.
From repo to CRA-ready.
Custom
For organizations with advanced security and deployment requirements.
Your infrastructure. Your policies. Our CRA engine.
For standard CRA products, manufacturers can generally use an internal conformity assessment. We automate and maintain the technical security checks, risk assessment, evidence and documentation needed to support that process. The manufacturer's formal legal responsibilities remain with the manufacturer.
No. CVE monitoring is one input. We combine repository analysis, software inventory, vulnerability intelligence, code security, supply-chain monitoring, security testing, product context and CRA requirements.
Our default architecture is designed to avoid permanently storing customer source code. Repositories are accessed with minimal permissions and analyzed in isolated environments.
Security agents continuously test approved environments and investigate potential attack paths. The goal is not just to detect theoretical issues, but to determine which weaknesses are actually relevant to your product.
Yes. Our goal isn't to replace every scanner you already use. Enterprise customers can feed existing security findings and evidence into the platform.
Not initially. We start with standard software products where internal CRA conformity assessment is possible. Important and critical CRA product categories require additional conformity procedures and are handled separately.
The CRA (Regulation (EU) 2024/2847) entered into force on 10 December 2024. The reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026. All other obligations apply from 11 December 2027.
Actively exploited vulnerabilities and severe incidents affecting the security of your product. An early warning is due within 24 hours of becoming aware, a notification within 72 hours. The final report follows no later than 14 days after a corrective or mitigating measure is available (vulnerabilities) or within one month of the notification (incidents). Reports go to the competent CSIRT via ENISA's Single Reporting Platform.
Generally not. Pure software-as-a-service is not a product with digital elements under the CRA; depending on your company, NIS2 may apply instead. The exception: remote data processing solutions of a product with digital elements – for example the cloud backend without which an app or device cannot perform one of its functions.
Yes. Manufacturers must create a software bill of materials in a machine-readable format covering at least the top-level dependencies. It does not have to be published, but it belongs in the technical documentation and must be provided to market surveillance authorities on request. Nuowei generates the SBOM automatically for every connected repository and keeps it up to date.
The reporting obligations do: they apply to all products with digital elements made available on the market, including those placed on the market before 11 December 2027. The other requirements apply to products placed on the market from 11 December 2027, and to earlier products if they are substantially modified afterwards.
Observe is free for up to 4 repositories. Defend costs EUR 99 per month for up to 8 repositories, plus EUR 5 per additional repository; Enterprise is custom. No seats, no developer licences. Enterprise is priced individually. Nuowei launches in November 2026; you can join the waitlist now.
Up to EUR 15 million or 2.5% of worldwide annual turnover for breaches of the essential requirements and the obligations in Articles 13 and 14. Up to EUR 10 million or 2% for other obligations, and up to EUR 5 million or 1% for incorrect or incomplete information. Micro and small enterprises are not fined for missing the 24-hour early-warning deadline.
Not three weeks before an audit. Not inside another spreadsheet. Not manually after every release.
Connect your repository once. We'll take it from there.
Join the waitlistNo spam. Only launch news.