Skip to content

FAQ

Questions worth asking before you buy compliance software

Including the ones where the honest answer is "no". CRA Sentinel supports regulatory work; it does not perform it for you, and the difference matters.

The basics

What is CRA Sentinel?

CRA Sentinel is business-to-business software that supports Cyber Resilience Act vulnerability monitoring, triage, reporting-case workflow and evidence keeping. It maintains an inventory of the products and versions you support and the components inside them, monitors those components for known vulnerabilities, records your team’s assessment of whether a product is affected, tracks the reporting deadlines that follow, and keeps an auditable history of the whole thing.

Who is it for?

Manufacturers of products with digital elements that are placed on the EU market, and the product security, compliance and engineering people inside them who carry the vulnerability-handling and reporting duties. It is sold to organisations, not to consumers.

What counts as a product?

One distinct thing you place on the market — a device, an application, a piece of firmware. That is also the unit your plan is priced by.

Versions, SBOMs, components, scans and evidence entries are not counted against anything on any plan. A manufacturer with one gateway and four supported versions of it is using one product, not four.

What is an SBOM, and which formats are supported?

A software bill of materials is a machine-readable list of the components inside a piece of software — the open-source libraries, their versions, and how they relate to each other. It is what makes the question “does this vulnerability affect the version we shipped?” answerable instead of a guess.

CRA Sentinel accepts CycloneDX and SPDX, as JSON documents. You upload one per supported product version.

What it will and will not decide

Does CRA Sentinel submit reports to ENISA or a CSIRT?

No. CRA Sentinel prepares notification content in ENISA’s field order and tracks what is due and when, but a named person on your team reviews and submits the report. There is no automated filing path.

Does CRA Sentinel decide whether a vulnerability is legally reportable?

No. That determination is human-controlled. The product surfaces the evidence — which of your supported versions a vulnerability reaches, and whether there is public evidence of active exploitation — and records what your team decides. It does not make the call for you.

Does CRA Sentinel make my organisation CRA compliant?

No. It supports the operational workflow — inventory, monitoring, triage, deadlines and evidence — but it does not determine legal compliance, and using it does not make an organisation compliant with the Cyber Resilience Act or any other law. Responsibility for regulatory obligations stays with you.

Does CRA Sentinel replace legal advice?

No. It is software. Nothing in the product or on this website is legal advice, and you should take your own advice on what the Cyber Resilience Act requires of your organisation and your products. CRA Sentinel supports the reporting workflow and the evidence trail; the legal and regulatory determinations remain with you and your advisers.

How monitoring works

What happens when a vulnerability is detected?

The component versions from your SBOM are range-checked against OSV continuously. A match means the version you actually ship falls inside an affected range, rather than merely sharing a package name with an advisory.

The match is cross-referenced against the CISA Known Exploited Vulnerabilities catalogue and the ENISA EU Vulnerability Database, and raised as an exposure against the specific product version it reaches. A named person on your team then records whether that product is affected, not affected, mitigated, or needs more information, with the reasoning. Where the decision leads to a duty, a reporting case opens and the 24-hour, 72-hour and final-report stages begin from the awareness time your team recorded. Every step is written to the evidence history.

Nothing moves past triage on its own. The software does not decide that an exposure is reportable, and it does not open a case behind your back.

How does it handle actively exploited vulnerabilities?

Matches are cross-referenced against the CISA Known Exploited Vulnerabilities catalogue and the ENISA EU Vulnerability Database. Where those sources report evidence of active exploitation, the finding is surfaced accordingly — which matters because the CRA reporting duty is keyed to actively exploited vulnerabilities, not to every published CVE.

This reflects what those sources report. A vulnerability being exploited without any source having published that fact is not something this or any tool can surface.

Can my team change a triage decision?

Yes. Assessments change as understanding improves, and the product expects that. Changing a decision does not overwrite the previous one: each is kept as a revision, so the history shows where the assessment moved, when, and who moved it. A regulator asking what you believed in the first 24 hours gets that answer, not the one you reached later.

What reporting deadlines does it track?

An early warning stage at 24 hours and a detailed notification stage at 72 hours, both measured from the moment awareness is recorded rather than from when someone opens the application.

The final report stage is not a third countdown from awareness. For an actively exploited vulnerability it is keyed to when a corrective or mitigating measure became available; for a severe incident it runs from the submission of the 72-hour notification. The product tracks whichever applies rather than collapsing both into one figure.

Your data

Where is my data stored?

The application database and the private object storage that holds uploaded SBOMs are hosted in Ireland, within the European Economic Area. The Privacy Policy names every sub-processor and what each one does.

Is my SBOM public?

No. Uploaded SBOM originals are held in private object storage. The bucket is not public, no public ACL is set on upload, and the documents are not served from a publicly addressable URL. Other customers cannot reach them either — every record belongs to exactly one organisation and every request is authorised against it.

What happens to our data if we cancel?

Nothing is deleted. Your organisation becomes read-only: you can still sign in, read every product, version, component, finding, triage decision, reporting case and evidence entry, export the full history as CSV or JSON, and continue working on compliance cases that are already open.

What stops is new paid capacity — adding new monitored products or versions, uploading new SBOMs for monitoring, and triggering new scans — which also means new vulnerabilities stop being surfaced while the subscription is inactive. Deleting data is a separate, explicit request. See the Refund & Cancellation Policy.

Plans and billing

How much does CRA Sentinel cost?

A subscription is priced per organisation and covers a number of products. Starter is €79 per month or €790 per year and covers up to 5 products. Growth is €199 per month or €1,990 per year and covers up to 25 products. Beyond that, Enterprise pricing is agreed with you rather than published. Annual billing saves about 16.7% on either plan. Taxes may apply depending on billing details and applicable law.

Every capability is included on every plan. These prices are provisional and subject to final launch approval. See Pricing.

What happens if I reach my product limit?

Adding a further product waits until there is room. Nothing you already have is removed, hidden or paused: your existing products, their versions, SBOM ingestion, scanning, triage and CRA reporting all carry on exactly as before, and the evidence history is untouched.

The product tells you which plan you are on and how many products it covers before it refuses, so the next step is a decision rather than a puzzle. Moving up a plan is done from the billing portal.

Can I change plans?

Yes, from the billing portal. Moving up takes effect so you can add the next product. Moving down to a plan smaller than the number of products you already have removes nothing — everything existing keeps working, and only adding a further product waits until you are back within the plan.

Switching between monthly and annual is handled in the billing portal where the payment provider supports it. Otherwise the supported route is to cancel, let the paid period run out, and subscribe again on the other interval, using the same organisation with your history intact.

Can I use it today?

CRA Sentinel is open for early access. You can create an account and use the production application today. Paid subscriptions open at launch.

Early access is the full production application, not a sandbox or a trial copy: add a product, add a supported version, upload its SBOM, and see exactly what CRA Sentinel can and cannot check against your own inventory. What you record now is your data, in the system you will keep using.

If you want to talk about a plan, timing or Enterprise terms before subscriptions open, get in touch.

Not answered here?

Ask. Questions about what the product does and does not do are the ones most worth getting right before anyone buys anything.