What’s new
Notable changes to CRAnotify, release after release. For the live state of the service, see the status page.
One price, based on the products you manage
Pricing now follows a single number: the Managed Products in your workspace. Every CRA capability is included at every size — there are no tiers to buy and nothing held behind one. SKUs, GTIN/EAN identifiers, variants, hardware revisions and firmware releases live inside a Managed Product and are not billed separately; neither seats, cases, SBOMs nor vulnerabilities found affect the fee. The price list is a continuous curve, so 27 products cost the price of 27 — not the price of 50. Annual billing is ten monthly instalments: two months free.
The pricing page is now a counter you can drive, and the account area shows what happens to the fee before you confirm a change of perimeter, in both directions. Archiving a Managed Product removes it from the active count without deleting its history, evidence or audit trail. If you already have a subscription, it keeps the price list it was signed under: a new price list does not, by itself, change an existing subscription.
Site search, 24 EU languages & a real cookie panel
Search the whole site from the header, or with “/” and cmd/ctrl+K: “Art. 14”, “art 14” and “articolo 14” all find the same page. The language menu now declares all 24 official languages of the Union — the ones we do not serve yet are shown as in translation rather than as links that lead nowhere. The cookie notice gained a real preferences panel with a switch per category and the actual list of cookies the product sets, and the choice stays revocable from a permanent recall.
Security hardening & the public API
Two-factor secrets encrypted at rest, stricter role-based access on billing and filing, protection against request forgery and open redirects, and a documented v1 read API with an OpenAPI specification and a self-hosted reference explorer.
Monitoring, live status & a hardened pipeline
Infrastructure and cost alerting, a real public status page, and a continuous-integration gate that blocks any release failing build, vet or race tests from reaching production.
Trust Center, CRA guide & documentation
A Trust Center describing how we protect your data and our sub-processors, a dedicated explainer of the Cyber Resilience Act and its obligations, and expanded product documentation.
Roles, SSO, notifications & client reporting
Role-based access control, single sign-on (OIDC), an in-app notification centre, a reliable deadline scheduler, guided onboarding and compliance reporting.
SBOM integrations & product registry
Connect the SBOM tools you already run, receive bills of materials from your pipeline, and keep a product registry with CSV import/export to scope vulnerabilities fast.
The core flow: triage, deadlines, filing & dossier
Guided Art. 14 triage, the deadline clock (24h/72h/final report), a pre-filled notification, the ENISA filing with receipt, an escalation chain and a tamper-evident registry with a defensive dossier.
Want to be notified of new releases? Write to info@cranotify.eu.