99% more reported CVEs per day in 2026 than last year.
CRACI

About CRACI

Building the future of CRA compliance automation

Our Story

CRACI was founded in Helsinki in 2025, after the same conversation kept repeating itself with CISOs, CTOs and compliance leads. They knew the Cyber Resilience Act deadline. They had read the regulation. What they didn't have was tooling that could prove what was actually in the products they had already shipped.

Existing scanners stop at build time. But the vulnerabilities that matter surface later, in transitive dependencies that were clean when you shipped and aren't anymore โ€” and a build-time scan can't tell you which version of which component is running in which product today. So we built the SBOM generation into the CI runner itself, where the evidence is provable rather than inferred.

In 2026 we raised a โ‚ฌ1.4M pre-seed led by Lifeline Ventures, with First Fellow Partners and Wave Ventures, to bring continuous compliance to every team that has to meet the CRA.

Our Values

Evidence over assertion

A compliance claim is only worth the evidence behind it. We generate SBOMs inside the build runner so the artifact you ship is the artifact we describe โ€” not a scan that ran somewhere nearby.

Secure by default

The secure path has to be the default path. If staying compliant requires our customers to remember a step, we designed it wrong.

Open standards, no lock-in

We build on SPDX and CycloneDX and export in formats every auditor and tool already reads. Your compliance record belongs to you, including the day you leave.

Compliance without the tax

Regulation shouldn't cost teams their velocity. Everything we build has to survive contact with a CI pipeline that runs hundreds of times a day.

Our Mission

To empower teams to ship software with confidence by providing full transparency into their software supply chain.

Join Us on This Journey

Book a demo to get early access to CRACI

Book a demo