101% more reported CVEs per day in 2026 than last year.

Features for CRA Compliance

Build-time SBOMs, vulnerability tracking and the evidence your Cyber Resilience Act process needs

SBOM Generation

CRACI records the SBOM during the build. A package-aware proxy observes what each job actually fetches, including packages restored from CI caches, and every SBOM carries a completeness state. Export it in CycloneDX or SPDX, with transitive dependencies and declared licenses, and know exactly what is in the software you ship.

Learn more โ†’
An SBOM recorded during the build Packages from npm, PyPI, Cargo, Go, OCI registries and the CI cache pass through a package-aware proxy on the CRACI runner. The job's SBOM lists what was fetched, states its completeness and exports as CycloneDX or SPDX. Package sources npm PyPI Cargo ยท Go OCI registries CI cache restore Package- aware proxy on the runner Job SBOM express 5.2.1 requests 2.32.3 serde 1.0.219 + transitive deps Declared license on every component Complete Completeness states per job and cache: Complete, Complete with connections, Incomplete, Unavailable, Not recorded CycloneDX ยท SPDX

Vulnerability Tracking

CRACI keeps re-evaluating monitored SBOMs as new vulnerabilities are published and aggregates findings across builds and repositories. Security teams triage what it finds and send it to the teams that own the fix, with VEX support. The SBOMs you collect from your own vendors are monitored alongside your builds.

Learn more โ†’
Vulnerability tracking after release After a release ships, its SBOM stays monitored. When a new vulnerability is published, CRACI re-evaluates the monitored SBOMs, finds the affected releases, and the security team triages the finding and routes it to the team that owns the fix. The inventory view shows which software versions are deployed to which products. Release shipped SBOM monitored Later New advisory published Re-evaluated automatically Finding: critical, in 2 releases 1. Triage 2. Route to owner 3. Team fixes Policy gates can block a build on findings ยท VEX supported Inventory: deployed versions Product Version Web app v4.12.0 Mobile API v2.3.1

CRA Evidence

Collect the evidence your CRA technical documentation needs: build-time SBOMs export as CycloneDX or SPDX, including the vulnerabilities found in their components, and the API returns SBOMs, network traces and provenance. CRACI automates a significant part of the supply chain visibility and evidence your CRA process needs.

Learn more โ†’
Evidence from the build record SBOMs export as CycloneDX or SPDX, including the vulnerabilities found in their components, and the public REST API returns SBOMs, network traces and provenance, for customers, auditors and frameworks such as the EU Cyber Resilience Act, NIS2, FDA SBOM requirements and ISO 27001 supply chain controls. The build record SBOMs Vulnerability records Provenance Network traces Export CycloneDX SPDX REST API Who asks for it Customers Auditors Security reviews Frameworks this evidence supports EU Cyber Resilience Act NIS2 supply chain security FDA SBOM for cyber devices ISO 27001 supply chain controls

CI/CD Integration

CRACI replaces the runner, not GitHub Actions. Change runs-on to craci and your runs still appear in GitHub. Every job records what it fetched and runs under an egress policy that is validated before the job starts and fails closed. GitHub Actions is supported today; other CI systems are on the roadmap.

Learn more โ†’
GitHub Actions jobs on CRACI runners A GitHub Actions workflow sets runs-on to craci. Each job runs in its own isolated virtual machine on a CRACI runner, on Linux x86-64 or ARM64, hosted in Europe, and the run still appears in GitHub. .github/workflows/release.yml jobs: build: runs-on: craci was: ubuntu-latest CRACI runners Hosted in Europe Job VM build Linux x86-64 Job VM test Linux ARM64 Job VM publish Linux x86-64 One isolated virtual machine per job, 1 to 32 vCPU Runs still appear in GitHub About 2x GitHub-hosted speed

Ready to get started?

Book a demo to get early access to CRACI

Book a demo