# CRA Evidence

> EU Cyber Resilience Act (CRA) Compliance Platform

- Canonical listing: https://agencysource.com/agencies/cra-evidence
- Location: Oviedo, Spain
- Categories: [Custom Software Development](https://agencysource.com/categories/custom-software-development), [Cybersecurity](https://agencysource.com/categories/cybersecurity), [IT Consulting & Managed IT](https://agencysource.com/categories/it-services), [Legal Services](https://agencysource.com/categories/legal-services)
- Services: Cybersecurity, IT Managed Services, IT Strategy Consulting
- Team size: 2 - 9
- Hourly rate: Undisclosed
- Minimum project: Undisclosed
- Founded: 2026
- Website: https://craevidence.com
- Listing: Not yet claimed
- Agency Source rating: no Agency Source reviews yet

## About

CRA Evidence is the EU Cyber Resilience Act compliance platform for manufacturers, importers, and distributors.

The CRA enters full application in December 2027. Products with digital elements placed on the EU market will require a technical file under Annex VII, an EU Declaration of Conformity, ten years of documentation under Article 13, and incident reporting to ENISA under Article 14. Non-compliance carries fines of up to €15M or 2.5% of global turnover.

SBOM Management. Ingest CycloneDX 1.4+ and SPDX 2.3+, scored against BSI TR-03183, with HBOM support for embedded systems.

Vulnerability Knowledge Base. Own VKB synced every 15 minutes from NVD, OSV.dev, GitHub Advisories, and CISA KEV, with an independent scanner as a second detection layer.

Exploit-Driven Prioritization. Findings enriched with EPSS from FIRST.org and CISA KEV, so remediation follows real-world exploitation likelihood, not raw CVSS.

VEX Automation. VEX statements generated per finding, so non-exploitable CVEs are documented and shared with downstream consumers in machine-readable form.

Technical File Generation. Annex VII packages, EU Declaration of Conformity, Annex II Security Data Sheets, and CE marking records produced as signed PDFs.

ENISA Reporting Workflow. Structured 24h/72h/14d notification timelines with deadline tracking and submission receipts.

Supplier & Importer Portal. Collect SBOMs and conformity declarations from upstream suppliers, so importers and distributors verify compliance before placing products on the EU market.

CI/CD Integration. Open-source CLI publishes SBOMs and release metadata directly from your build pipeline.

Digital Product Passports. QR-linked passports for physical product labelling.

Trusted by manufacturers, importers, and distributors to meet CRA obligations and stay aligned with NIS2, RED, and the Machinery Regulation.

---

Source: Agency Source, https://agencysource.com/agencies/cra-evidence. Ratings and reviews come only from reviews submitted and moderated on Agency Source; agencies cannot pay for rank.
