Free CRA Readiness Check

Where does your product stand with the CRA? Know in 24 hours.

You get a clear report: a traffic-light status on CRA readiness, the complete list of your software components and known vulnerabilities with severity, plus a licence review. Free, once per company (repeat report after remediation: €99). Ready to report today, ready to prove by December 2027 — from the same data.

You already have a bill of materials?

Whether you produced it yourself with Syft, cdxgen or Trivy, export it from your build or received it from a supplier — as CycloneDX or SPDX: send the file to [email protected]. No tool, no installation, no access to your source code.

You get the free CRA report — plus your file back, with supplier and licence filled in from a database of around 51,000 components.

An example you can recheck. Syft's bill of materials for the caddy web server holds 265 entries: 10 file entries, 34 CI tools and 221 Go modules. The 221 are the point. Not one of them carried a supplier. After the match against our database, all 221 do. Names and versions came from Syft's file — what we added are the fields an auditor asks for.

What we could not fill in, the report names. Whether a component is missing altogether it cannot see — for that the tool has to read your build itself.

We evaluate your file, send the enriched version back to you and delete our copy afterwards. Details in the privacy notice.

Your project exists as source code?

The generator is free. Open source under GPL, so it is free and stays free. No code, no account, nothing in return.

pipx install jochwacht-sbom
jochwacht-sbom .

The tool reads your build and writes your SBOM, the software bill of materials, to a file in your project folder. It is yours. You can leave it at that.

If you want the free CRA report as well, send the file with --send --email <your address> — or as an attachment to [email protected]. It arrives within 24 hours.

Sending is voluntary, and it is what we get out of this. It is how we get into conversation with you. Before sending, the tool shows you the complete list and asks.

Earlier package names keep working and install the current version. No pipx yet? sudo apt install pipx. pip works too, but inside a virtual environment — since Ubuntu 24.04 and Debian 12 the system Python refuses a direct install.

This is the section that sits before the findings in your report. It answers the question the 24-hour deadline hangs on.

Active exploitation

Checked: 47 components, 25 findings
Source 1: CISA KEV, retrieved when the report was generated
Source 2: EUVD (European list), retrieved when the report was generated

Result: None of the 25 findings appears on either list.

"Findings" are CVE entries for the components in your SBOM.
A listed finding means active exploitation is documented for it. The reporting
duty under CRA Art. 14 also requires the vulnerability to be present in your
product — that is your assessment. It therefore goes first, regardless of its
CVSS rating.

Most of the time the answer is no. Then that is what it says, with both sources and the time of the query. A report without this section is not evidence.

  • Since 11 September: what must be reported is what is actively exploited — not what is severe. Your report checks that against the two lists above and adds the EPSS probability.
  • What sits inside the FPGA, too. Vivado, Libero SoC and Quartus Prime are read; third-party IP cores appear in the report with name and version.
  • Licensing, too. Copyleft obligations are evaluated along the entire dependency chain, not just for directly included packages.
  • No false alarms. We check the version that is actually in your build. If your build configuration resolves to OpenSSL 3.0.13, we check 3.0.13 — not every flaw ever reported for some 3.0 release.

Optional: your personal code

You do not need a code to send, your e-mail address is enough. If you have one, you save yourself the typing: the report then goes automatically to the address registered here. The code arrives by e-mail and is valid for one check.

We use your details to deliver the code and the report and to contact you about our offer. Details: privacy notes for the check.

Frequently asked questions

What exactly leaves our building?

Of the components we discover, only names, versions and package ecosystems — no source code, no file paths, no configuration. Plus whatever you declared yourself in your Ihrer Deklarationsdatei (supplier, licence, identifiers) — that is your own record, and it makes the report considerably more complete; switch it off with --no-declared-metadata. You do not have to take our word for it: the SBOM sits as a file in your project folder before you decide about sending. On request, --anonymize even hashes the project name. And because trust should be verifiable, the generator is open source under GPL: github.com/Innomatica-GmbH/jochwacht-sbom.

What does the check cost?

The first check is free — once per company. A proof after remediation costs €99 net against invoice. For continuous monitoring, Jochwacht Monitor is in preparation. Every price is on the pricing page.

Which projects are supported?

Anything with package-manager or build files: Conan, vcpkg, CMake, Cargo, npm/yarn/pnpm, Python, Go, Maven/Gradle, Yocto/Buildroot environments and more. Plus FPGA projects from Vivado, Libero SoC and Quartus Prime. Plain Make projects without such files can declare components manually — the report states that clearly.

Who produces the report?

The analysis runs on our own servers in Germany; every report is personally reviewed by our team before it goes out. No call centre, no data resale — we are a German embedded-software company.