EU Cyber Resilience Act

CRA compliance
for embedded teams

Scan your firmware, source code, and RTOS configuration — then map findings to all 21 CRA requirements with a prioritized remediation roadmap.

21
CRA requirements covered
10+
Embedded platforms
6
Build system extractors
3
CI/CD platforms
craguard — cortex-m4 scan
$ craguard scan --source ./stm32f407-gateway

Detecting platform... Cortex-M4 (STM32F407VG)
Analyzers: cortex-m, freertos, sbom, firmware, cve
──────────────────────────────────────────────────
Scanning linker script... MPU config... startup.s...
Scanning FreeRTOSConfig.h... 42 settings checked
SBOM: 18 components extracted (CMake + pip)
CVE scan: 18 components → NVD/OSV lookup

CRA Compliance — STM32F407 IoT Gateway v1.3
──────────────────────────────────────────────────
Overall Score: 68%
Status: Partially Compliant
Findings: 11 (1 critical, 3 high, 5 medium, 2 low)

Requirement Assessment (21 Annex I):
  [PASS] AI-PI-1a No Known Exploitable Vulnerabilities
  [PASS] AI-PI-1d Protection from Unauthorized Access
  [PASS] AI-PI-1e Confidentiality of Data
  [PART] AI-PI-1b Secure by Default — MPU disabled in 2 regions
  [PART] AI-PI-1j Attack Surface — SWD left enabled in release
  [FAIL] AI-PI-1k Exploitation Mitigation — no stack canary (-fstack-protector)
  [FAIL] AI-PI-1f Secure Update — OTA signature verification missing
  [ -- ] AI-PI-1g Data Minimization (not assessed)

Run `craguard report gap --format html` for the full remediation roadmap.

Everything you need for CRA compliance

From source code analysis to auditor-ready documentation — purpose-built for embedded systems, not adapted from web-app scanners.

🔍

Platform-Aware Scanning

Auto-detects your platform and runs targeted checks. Zephyr Kconfig, STM32 CubeMX .ioc, FreeRTOS config, Nordic nRF5, Mbed OS, RTX5 — plus generic Cortex-M hardening for any project.

📋

CRA Gap Analysis

Maps every finding to all 21 Annex I requirements. See exactly what's compliant, what's partial, and where the gaps are — with a prioritized remediation roadmap and effort estimates.

🔒

Firmware & Source Security

Binary hardening checks (NX, PIE, canaries), weak crypto detection, secrets scanning, unsafe C patterns, compiler flag validation, and linker script analysis.

📄

Compliance Documents

Generate EU Declaration of Conformity drafts and Technical Documentation skeletons per CRA Annex IV/V — pre-filled from your scan results, in HTML and PDF.

🔗

SBOM, CVE & VEX

Auto-generate CycloneDX SBOMs from CMake, npm, pip, Zephyr west, Yocto, and PlatformIO. Scan against NVD/OSV for CVEs. Manage VEX statements with OpenVEX and CSAF export.

🛡️

Audit Portal

Share hash-verified compliance snapshots with auditors and notified bodies via secure, expiring links with SHA-256 integrity verification.

VSCode Extension

Inline diagnostics, compliance status panel, CodeLens hints on Kconfig and .ioc files, and scan-on-save — all without leaving your editor.

🔄

CI/CD Integration

Auto-generate pipeline configs for GitHub Actions, GitLab CI, and Bitbucket. Set quality gates that fail builds on critical or high-severity findings.

🚀

Zero-Config Quickstart

Point CRAGuard at your project directory and run one command. It detects your platform, creates a config, runs a full scan, and generates your gap analysis report.

Built for your embedded stack

CRAGuard auto-detects your project type and runs the right analyzers automatically.

Zephyr RTOS
Kconfig, west.yml, DTS
STM32 CubeMX
RDP, JTAG, watchdog, RNG
FreeRTOS
Stack overflow, MPU, TrustZone
Nordic nRF5
APPROTECT, secure boot
Mbed OS
TLS config, bootloader
RTX5 / CMSIS
RTOS config, privilege levels
Bare-metal
Cortex-M generic checks
Yocto / OE
SBOM extraction
PlatformIO
SBOM extraction
Any C/C++
Unsafe patterns, compiler flags

Simple, transparent pricing

Start free, scale as you grow. All plans include all 21 CRA requirement checks.

Community

Free
  • 1 product
  • CLI scanner
  • HTML gap analysis report
  • Community support
Get started

Pro

€49/mo
  • Unlimited products
  • Web dashboard
  • PDF reports
  • Scan history
  • VEX workflow
  • Email support
Start free trial
Most Popular

Team

€149/mo
  • Everything in Pro
  • CI/CD integration
  • Audit portal
  • SARIF output
  • Findings management
  • Priority support
Start free trial

Enterprise

Custom
  • Everything in Team
  • On-premise deployment
  • Custom analyzers
  • SSO / SAML
  • SLA guarantee
  • Dedicated support
Contact sales

Ready to get CRA compliant?

Start scanning your embedded products today. No credit card required.

Start free trial