Frequently Asked Questions

Everything you need to know about our CRA due diligence assessments.

General Questions

Standard scanners are automated data collectors — they tell you what is known. Our reports are expert assertions — they tell you what the data means in a regulatory context.

The CRA requires "due diligence," which implies a level of professional review that raw tool output cannot provide. A scanner can tell you "CVE-2024-XXXX exists." Our report tells an auditor "we evaluated CVE-2024-XXXX in the context of standard deployment configurations and determined it is not reachable" — signed by a qualified expert.

While no one can guarantee a specific regulatory outcome, our reports are structured specifically to mirror the evidence requirements of the CRA. By providing a signed expert assertion backed by rigorous methodology, you are demonstrating a "high level of care," which is the primary defense against compliance-related liability.

Our reports map directly to CRA Article 10 and Annex I Essential Requirements — exactly what auditors will look for.

Simply use the Request an Assessment form. We typically deliver new assessments within 3–5 business days (Standard) or 5–10 business days (High-Criticality).

If you have a large list, upload your SBOM through our Assess My Stack page — we'll show you which components are already available and provide a timeline and quote for the rest.

Yes. We offer tailored pricing for teams assessing multiple components. Upload your SBOM through Assess My Stack or contact us and we'll send a custom proposal within 24 hours.

Reports are available as one-time purchases for specific component versions. No subscription required.

We also offer annual re-assessments to keep your reports current as components evolve. Contact us to learn more.

Every assertion includes:

  • The assessor's credentials and professional background
  • Specific methodology references (OpenSSF Scorecard, NVD, binary hardening analysis)
  • Direct mapping to CRA Annex I sections
  • A unique Report ID for traceability

Our methodology is transparent and reproducible. See a sample report to judge for yourself.

Technical Questions

Standard Tier ($499): Component identity, ecosystem health, CVE analysis with reachability & VEX, OpenSSF Scorecard evaluation, license risk analysis, static analysis (SAST), credential & secret scanning, SBOM (CycloneDX), safe usage recommendations, executive summary, and expert-signed CRA assertion.

High-Criticality Tier ($999): Everything in Standard, plus extended semantic SAST, binary hardening assessment, malware scanning, CI/CD workflow security analysis, cryptography analysis & CBOM, AI-augmented anomaly detection & threat model, dependency tree deep-dive, and detailed executive summary.

Machine-readable deliverables: Both tiers include a CycloneDX SBOM and OpenVEX document. High-Criticality also includes a CBOM (Cryptographic Bill of Materials).

Download a sample report to see exactly what you'll receive.

We accept SPDX (JSON and tag-value), CycloneDX (JSON and XML), plain text dependency lists, and package lock files (package-lock.json, yarn.lock, Pipfile.lock, etc.).

If you're not sure what format you have, just upload it — we'll figure it out.

For Standard reports, we assess the component itself (direct dependency). For High-Criticality reports, we include a review of the top 3 highest-risk transitive sub-dependencies.

For full dependency tree assessments, use Assess My Stack and we'll map your entire tree and prioritize components.

Business & Legal

Yes. Purchasers receive a license to use the report for internal compliance documentation and to share with auditors, regulators, and certification bodies. Reports may not be resold or publicly distributed.

Yes. We provide Stripe Invoices (Net 15/30) or manual invoices for larger engagements. Wire transfer is also accepted.

B2B (VAT-registered): Provide your VAT ID when we send the invoice for reverse charge (no VAT charged).

B2C (non-VAT-registered): VAT charged at your country's rate on the invoice.

All invoices are EU VAT-compliant and include VAT ID, rate, and amount.

No. Our reports are due diligence evidence, not a Declaration of Conformity (DoC) as defined in CRA Article 28 and Annex VII.

Under the CRA, only the manufacturer of a product with digital elements may issue a Declaration of Conformity. Our reports provide the expert-reviewed technical evidence and signed assertions that support a manufacturer's own conformity assessment process — they are an input to your DoC, not the DoC itself.

Think of our report the way you would think of an independent financial audit: the auditor provides evidence and professional opinion, but the company's board signs the annual report.

No. We are an independent assessment service. We do not develop, manufacture, distribute, or import any open source component. We are not an open source steward as defined in CRA Article 3(14).

We have no CRA obligations of our own with respect to the components we assess. Our role is analogous to a third-party testing laboratory or professional consultancy: we evaluate and report, but we do not place products on the market or assume any of the regulatory responsibilities assigned to manufacturers (Article 13), distributors (Article 22), or open source stewards (Article 24).

Our reports are delivered on a professional-services basis. As with any expert opinion, they reflect the state of the component at the time of assessment and are subject to our Terms of Service.

Still have questions?