We provide audit-ready security assessments for every open source component in your stack—signed by a 25-year industry veteran, mapped to CRA Annex I requirements.
Manufacturers must perform and document due diligence on every third-party component, including open source. Annex I and Recital 34 specify what that means.
open-source dependencies in the average commercial product
requires documented due diligence under the CRA
or 2.5% of global revenue — the penalty for non-compliance
Key enforcement dates are approaching. Where does your team stand?
Dec 2024
CRA entered
into force
Sep 2026
Reporting obligations
begin
Dec 2027
Full enforcement
& penalties
Penalties for non-compliance: up to €15M or 2.5% of global revenue.
Upload your SBOM or share your dependency list—we'll tell you exactly where you stand.
We deliver expert-assessed, audit-ready reports for every component in your stack.
Your compliance team has the documentation auditors require for CRA technical documentation (Annex VII).
Choose the assessment level that fits your component's risk profile.
Best for general-purpose utilities, UI frameworks, data libraries
Best for crypto, networking, privileged data handlers
Volume pricing available for 10+ components. See full pricing →
Auditors expect professional judgment, not raw tool output.
Ensure your product is compliant and your supply chain is secure. Tell us about your stack and we'll send a proposal within 24 hours.