EU Cyber Resilience Act
Sell in the EU. Stay compliant. Automatically.
Cemply takes your connected product from zero to full CRA compliance (SBOM, vulnerability monitoring, ENISA reporting, CE technical file) and keeps it there for the life of the product. For the price of one consultant-day per month.
Free CRA-ready SBOM and vulnerability report for your product, in minutes.
…
days until ENISA reporting
becomes mandatory (Sept 11, 2026)
…
days until full CRA compliance
is required (Dec 11, 2027)
Four modules. Four legal obligations. Zero panic.
■ Inventory
Know what's inside every product.
Connect your repos or upload manifests. Cemply generates versioned CycloneDX/SPDX SBOMs for every product and every scan, the foundation the CRA requires.
■ Watch
Never miss a vulnerability that matters.
Every night, Cemply re-checks your latest SBOM against public vulnerability databases and records every new match in your audit trail, proof of continuous monitoring.
■ Report
24h / 72h ENISA deadlines, handled.
Guided incident qualification, generated notifications, tamper-proof timestamps and multi-channel escalation. Sleep through the night; keep the audit trail.
■ File
Your CE technical file, generated.
Annex VII documentation assembled from your real product data, versioned, and regenerated in one click whenever your product changes. You complete what only the manufacturer can know.
Get your SBOM and vulnerability report, for free.
Upload a dependency manifest and get a free CRA-ready SBOM plus a first look at the known vulnerabilities inside your product.
Generate your free SBOM →Paid plans open in September 2026.
Leave your email and we'll send you one message when they do.
No spam, no follow-ups.