EU Regulation 2024/2847

Comply with the
Cyber Resilience Act
without the complexity.

CRA Shield guides iOS and Android developers through classification, assessment, SBOM generation, and compliance documentation.

One-time payment No subscription

Why this matters

Non-compliance isn't an option.

Your app has digital elements

If your iOS or Android app connects to a network, processes data, or uses third-party libraries — the CRA applies to you.

No SBOM, no docs, no process

Without a Software Bill of Materials, vulnerability handling, and conformity documentation — you're non-compliant by default.

Fines up to €15 million

Market surveillance authorities can fine developers €15M or 2.5% of global turnover — whichever is higher. Per violation.

Lost revenue & trust

Apps pulled from the EU market. User trust shattered. Partners walk away. Recovery takes years — if it happens at all.

The CRA enforcement deadline is 11 December 2027. Don't wait.

Get compliant for €99 →
Classify
3-step wizard
Assess
21 requirements
Scan
SBOM + OSV.dev
Document
ENISA-ready PDFs
01

Know your classification

Answer three sets of questions. The wizard checks your app against Annex III and Annex IV triggers and tells you whether you're Default, Class I, or Class II. The trigger definitions update automatically when delegated acts change.

  • Scope check with 3 criteria
  • Annex IV Class II triggers
  • Annex III Class I triggers
  • Results saved for document pre-fill
1
2
3

Step 2: Class II Triggers (Annex IV)

Does your app fall into any of these categories?

SBOM Vulnerability Report

5 issues
CVE-2026-1234
CRITICAL
CVE-2026-5678
CRITICAL
GHSA-abcd-1234
HIGH
+ 2 medium severity
94 components scanned via OSV.dev
02

Scan every dependency

Upload your lock files — package.json, Podfile.lock, Package.resolved, build.gradle. CRA Shield parses every component, queries OSV.dev for known vulnerabilities, and generates a CycloneDX 1.5 SBOM.

  • npm, CocoaPods, SPM, Gradle
  • Severity-ranked vulnerability list
  • Fix version recommendations
03

Generate every document

Four pre-built templates cover all required CRA documentation. Each template is pre-filled from your classification and assessment data. Fill in the remaining fields, generate a PDF, and export your full compliance package as a ZIP.

Declaration of Conformity
Article 18, Annex II
Vuln Disclosure Policy
Article 13(6)
User Information Sheet
Annex II, Part II
Technical Doc Summary
Article 31
compliance_package.zip
4 documents + SBOM + vulnerability report
Pricing

Simple, one-time pricing

No subscriptions. No per-seat fees. Pay once, own it forever.

Developer
€99

One-time payment. Up to 2 apps.

Get Developer
  • Classification wizard
  • Self-assessment checklist
  • SBOM + vulnerability scan
  • All document templates
  • Compliance ZIP export
BEST VALUE
Professional
€197

One-time payment. Up to 10 apps.

Get Professional
  • Everything in Developer
  • Up to 10 apps
  • Priority support
  • €19.70/app vs €49.50/app
Add-on
€7 /month

Continuous monitoring. Cancel anytime.

24×7 Scanning
New CVEs checked every 6 hours
Email Alerts
Instant notification for new vulns
Incident Reporter
Pre-filled ENISA forms (Art. 14)
Available as upsell during checkout
FAQ

Questions & answers

Does my mobile app need CRA compliance?

If your app is a commercial product with digital elements placed on the EU market, it likely falls under the CRA. Our three-step classification wizard determines this by checking scope criteria and Annex III/IV triggers specific to your app.

What's the difference between one-time and subscription?

Developer (€99) and Professional (€197) are one-time payments with lifetime access. The Vulnerability Monitoring add-on (€7/month) is the only recurring charge, and it's entirely optional.

Which package managers are supported for SBOM?

npm (package.json, package-lock.json, yarn.lock), CocoaPods (Podfile.lock), Swift Package Manager (Package.resolved), and Gradle (build.gradle). Output is CycloneDX 1.5 JSON format.

Is CRA Shield legal advice?

No. CRA Shield is a compliance toolkit that helps you organise your CRA effort. All generated documents carry disclaimers. Consult with legal counsel for your specific situation.

Start your CRA compliance today

One-time payment. No subscriptions. Full compliance toolkit.

Get Started — from €99