CRA software for SMEs and the Mittelstand
Nuowei helps small and mid-sized software manufacturers and machine builders with firmware or software meet the Cyber Resilience Act without a dedicated security team. It connects to GitHub read-only and automates SBOMs, vulnerability monitoring and CRA evidence per repository.
Last updated:
The challenge
The CRA applies regardless of company size. Many manufacturers ship software, apps or firmware for their machines but have no security department. Since 11 September 2026 they must be able to report actively exploited vulnerabilities within 24 hours, and by 11 December 2027 they need full conformity.
What Nuowei automates
- Automatic SBOM per repository, continuously updated
- CVE and supply-chain monitoring of dependencies
- Secret scanning and static analysis
- Agentic pentesting (Defend plan)
- CRA risk assessment and evidence for technical documentation
- Vulnerability handling and CRA reporting workflows (Nuowei prepares, you submit)
Nuowei starts with standard-category products assessed through internal control (Module A). Support for important and critical products will follow later.
Pricing per repository
| Plan | Price |
|---|---|
| Observe | free, up to 4 repositories |
| Defend | EUR 99 / month for up to 8 repositories, EUR 5 per additional |
| Enterprise | Custom |
See pricing for details.
Status
Nuowei is in beta and launches in November 2026. It does not certify products; legal responsibility stays with you as the manufacturer. Read how we handle your code on the security page.