Your workspace for Cyber Resilience Act compliance.
Classify each product, record the assessment, and file an Article 14 report inside the deadline, in one place. Your compliance stays documented, audit-ready, and defensible.
- ISO/IEC 29147
- EN 40000-1-3
- CSA STAR Level 1
- GCVE GNA 126
- CSAF 2.0 export
- EU hosted
- GDPR processor terms
- Pentested quarterly

One journey, from first disclosure to CE marking.
Receive disclosures
A branded portal on your own subdomain, with a published policy and 48-hour acknowledgment tracking. Free.
Create a free portal →File on the clock
An actively exploited vulnerability starts the 24-hour, 72-hour, and 14-day Article 14 timers. The filing package is prepared for you.
How Article 14 filing works →Classify and assess
Classify under Annex III and IV, pick the Article 32 conformity route, and run the risk assessment.
Classify your product →Declare conformity
Close the Annex I gaps, assemble the technical file, and draw up the EU Declaration of Conformity.
See how self-assessment works →Where a notified body is still requiredRead the condition →
Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
Industry Context
“Organisations increasingly recognise that software development nowadays requires an active, positive response to vulnerability reports, which strengthens security and is becoming a strong selling point when handled properly.”
EU buyers and market surveillance authorities increasingly expect manufacturers to show a documented CRA position. CVD Portal gives you a structured assessment, the technical file to back it, and a published disclosure process.
Simple, transparent pricing
See full pricing →Receive, track, and acknowledge disclosures
Article 14 authority filing support + full CRA-compliant vulnerability disclosure workflow
CRA self-assessment through to the EU Declaration of Conformity
Every module at scale, lifecycle support for 25 products, integrations, EUDI identity
Prefer to work offline? 37 fillable CRA templates in DOCX, PDF, and Markdown, which import into the workspace later. Browse template packages →
Does your company meet the CRA disclosure baseline?
Enter your domain. The scan checks the two Article 13(2) contact requirements, an RFC 9116 security.txt and a discoverable disclosure policy. No signup.
Probes /.well-known/security.txt and five CVD policy paths. No data is shared with third parties. Up to five scans per hour.
Achieve complete CRA compliance before the deadlines arrive
Open a free disclosure portal today, or start the 14-day Compliance trial for classification, risk assessment, and the EU Declaration of Conformity.
