CRA Gate — 2027 compliance, verified in your pipeline
A check that plugs into your CI/CD and verifies, on every release, your compliance with the Cyber Resilience Act. You save on audit firms and gain time, because everything is automated.
- SBOM generated and signed
- Known vulnerabilities (CVE) analysed
- Disclosure policy present
- Audit evidence archived
Three steps, then nothing left to do
Once set up, CRA Gate works on every release without any action from you.
1. Add the step
One line in your GitLab, GitHub or other pipeline. No rewriting, no migration. CRA Gate runs after your tests.
2. Automatic analysis
On every release, CRA Gate inspects your application, your dependencies and your documentation against the CRA requirements.
3. Audit-ready evidence
A time-stamped, signed report is archived automatically. On audit day, everything is already there, organised and traceable.
Everything the CRA requires, checked automatically
Automatic SBOM
Generates and signs the software bill of materials (SBOM) required by the CRA, up to date on every build.
Vulnerability scanning
Cross-references your dependencies with known CVEs and flags what must be fixed before going to production.
Documentation check
Verifies the presence of a disclosure policy, security instructions and mandatory information.
Non-compliance alerts
The pipeline fails or warns as soon as a gap appears. You fix it early, when it costs the least.
Continuous audit file
Every release feeds a dated evidence file, exportable in one click for your auditors or customers.
Tracking over time
Visualise how your compliance evolves, version after version, to demonstrate continuous diligence.
A cost that pays for itself in hours saved
Less external audit
Save on the firms
Evidence is produced automatically and continuously. Your auditors spend fewer hours collecting and verifying — the bill goes down.
Zero manual work
Gain time
Verification is built into an already automated process. No new meeting, no checklist to fill in by hand.
2027 deadline
Compliant before the date
The Cyber Resilience Act obligations become binding in 2027. Get compliant gradually, without last-minute rush.
Hosted in Switzerland, or on your premises
The same product, the option that matches your constraints. Pricing on request, no surprises.
Cloud (hosted in Switzerland)
We run CRA Gate for you on Swiss infrastructure. The simplest way to get started.
- Up and running in under an hour
- Updates and monitoring included
- Compliance dashboard
- Hosting and data in Switzerland
Self-hosted
Install CRA Gate on your own infrastructure. Your data and your evidence never leave your walls.
- Runs entirely on your premises
- Full data sovereignty
- Integrates with your existing CI/CD
- Annual licence, support included
What decision-makers ask us
What is the Cyber Resilience Act?+
It's a European regulation that imposes cybersecurity requirements on products with digital elements. Its main obligations apply from 2027. Swiss companies that sell or export digital products to the EU are concerned.
Is my Swiss company concerned?+
If your software or connected products are placed on the European market, yes. CRA Gate helps you determine this and build the necessary evidence, whether you are a vendor, manufacturer or integrator.
Do we have to change the way we work?+
No. CRA Gate adds to your existing pipeline as an extra step. Your teams keep working exactly as before; compliance is verified in the background.
Does CRA Gate replace an auditor?+
No, but it sharply reduces their work. CRA Gate prepares and organises the evidence continuously, which makes the audit faster, more predictable and less costly.
Put your CRA compliance on autopilot
Book a 30-minute demo. We look at your pipeline together and estimate what CRA Gate will save you.