CRACI is an automated platform that integrates with existing CI/CD pipelines to generate software bill‑of‑materials (SBOMs), continuously monitor vulnerabilities, and produce audit‑ready reports for the EU Cyber Resilience Act. By supporting major CI/CD tools and exporting compliance documentation in multiple formats, it enables software manufacturers and development teams to maintain regulatory compliance without changing their workflow.
Funding
€1.4M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

FFFounders
Product
Problem
Software manufacturers and developers targeting the EU market must comply with the Cyber Resilience Act, which requires detailed software bill‑of‑materials (SBOM), continuous vulnerability monitoring, and audit‑ready documentation. Achieving this compliance manually is time‑consuming, error‑prone, and can delay release cycles.
Solution
CRACI provides an automated platform that embeds directly into existing CI/CD pipelines to generate SBOMs for every build, track real‑time vulnerabilities across all dependencies, and produce ready‑to‑submit CRA compliance reports. The service continuously monitors actively monitored SBOMs, alerts teams to newly discovered exploits, and formats evidence for regulatory audits. By supporting major CI/CD tools (GitHub Actions, GitLab CI, Jenkins, CircleCI) and exporting reports in multiple formats, CRACI enables developers to maintain compliance without altering their workflow. Pricing tiers scale from individual developers to enterprise organizations, offering flexible usage of SBOMs and build minutes.
Target Audience
Primary customers are software manufacturers, SaaS providers, and development teams that build digital products for the European market and need to meet Cyber Resilience Act requirements.
Features
- Automatic SBOM generation for each build in SPDX, CycloneDX, and other standard formats
- Continuous vulnerability tracking with instant alerts and severity‑based prioritization
- One‑click creation of audit‑ready CRA compliance reports in PDF, HTML, CSV, Excel, or JSON
- Seamless integration with GitHub Actions, GitLab CI, Jenkins, and CircleCI for automated security checks
- Monitoring of actively tracked SBOMs with reporting to ENISA on behalf of the user
- Scalable pricing based on number of users, monitored SBOMs, and build‑minute consumption