Skip to content

CRA reporting obligations active since 11 Sep 2026Learn more

We're in beta. Launch Nov.

Your repo.CRA-ready. – CRA compliance software for software manufacturers

Our security agents continuously review your code and dependencies, maintain your CRA evidence and tell you when something needs your attention.

From code to CRA-ready. And ready afterwards.

  • GitHub connected in minutes.
  • Read-only access.
  • No source code stored permanently.

Compliance shouldn't be another full-time job.

The Cyber Resilience Act turns cybersecurity into a continuous product responsibility.

You shouldn't need to become a CRA expert.

We automate the work.

  • You need to know what's inside your software.
  • You need to know what's vulnerable.
  • You need to test it.
  • You need to document it.
  • And when something happens, you need to react fast.

More than another vulnerability scanner.

Finding a CVE is easy.

The hard part is knowing whether it affects your product. Our agents connect code, dependencies and context to show what actually matters.

Manual work vs Nuowei

  • Time to alert

    91%faster

    Manual
    48 h
    Nuowei
    4.3 h
  • Average time to triage a finding

    95%faster

    Manual
    45 min
    Nuowei
    2 min
  • Triage cost per finding

    99%less

    Manual
    €120
    Nuowei
    €1.20
  • Evidence preparation per release

    90%less

    Manual
    15 days
    Nuowei
    1.5 days

Your software, understood by agents.

Every connected repository is continuously reviewed by specialized security agents. Your repository becomes the source of truth.

  • Software inventory

    Automatic SBOM creation and continuous dependency tracking.

  • Vulnerabilities

    Continuous CVE monitoring across your software supply chain.

  • Code security

    Static analysis, secrets detection and security-focused code review.

  • Supply chain

    New dependencies, suspicious packages, unexpected changes and dependency risks are continuously monitored.

  • Attack surface

    Our agents analyze how your application can actually be attacked.

  • Pentesting

    Agentic security testing continuously challenges approved test environments and verifies potential weaknesses.

    No annual snapshot. Continuous testing.

Know if you can ship.

Every release gets a simple answer.

Release v4.8.2

CRA READY

No known release blockers.

  • SBOM current.
  • Security review complete.
  • Pentest complete.
  • Risk assessment current.
  • Evidence complete.
Release v4.9.0

ACTION REQUIRED

2 issues need attention before release.

  • Critical · Authentication bypass

    Potentially exploitable in production.

  • High · Vulnerable dependency

    Fix available.

No 80-page report.
Just what matters.

We build the CRA file while you build the product.

Security findings shouldn't disappear into tickets.

Every relevant scan, test, fix and decision becomes evidence.

CRA file

Example
11/11

Your CRA workspace stays continuously updated with:

  • SBOM

  • Cybersecurity risk assessment

  • Security findings

  • Remediation evidence

  • Vulnerability handling evidence

  • Security test results

  • Third-party component evidence

  • Release history

  • Support-period information

  • Technical documentation

  • Conformity documentation

  • 11/11

    Evidence complete.

When someone asks how you reached your conformity decision, the evidence is already there.

When 24 hours matter, you shouldn't start with a spreadsheet.

CRA reporting obligations are already active.

We escalate reportable vulnerabilities and severe incidents immediately.

  • New vulnerability? We check if you're affected.
  • Compromised dependency? We find every affected release.
  • Security incident? We start the CRA response.

Monitored for your product's entire lifecycle.

Potential CRA reportable event

Example · Detected 09:42

Incident
  • Affected product identified
  • Affected versions identified
  • Initial impact assessed
  • Evidence collected
  • Responsible team alerted

CRA response workflow started

Early-warning deadline

23h 51m

We prepare the information your team needs for the reporting process.

Security starts with how we access your code.

  • Your source code is your company.
    We treat it that way.

  • Read-only by default

    We never need permission to modify your production repository.

  • Ephemeral analysis

    Code is analyzed inside isolated environments and removed after processing.

  • No permanent source storage

    We store findings and compliance evidence — not a permanent copy of your codebase.

  • European infrastructure

    Customer data is processed and stored in the EU.

  • Tenant isolation

    Every customer environment is isolated.

  • Short-lived credentials

    No long-lived developer tokens sitting in our database.

  • Fully auditable

    Security-relevant actions are logged.

Simple pricing.

No seats. No developer licenses. No surprise scanning bills.

  • Observe

    Freeup to 4 repositories

    For teams that want continuous visibility.

    Know what's happening.

    • Automatic SBOM
    • Continuous CVE monitoring
    • Dependency monitoring
    • Supply-chain monitoring
    • Secret scanning
    • Static security analysis
    • Agentic repository review
    • Instant security alerts
    • Security dashboard
  • Defend

    Most popular

    €99/ month for up to 8 repositoriesEach additional repository €5 / month

    For teams that want to become and stay CRA-ready.

    From repo to CRA-ready.

    Everything in Observe, plus

    • Agentic exploitability analysis
    • Continuous agentic pentesting
    • CRA product assessment
    • CRA risk assessment
    • CRA control mapping
    • Release readiness checks
    • Compliance evidence
    • Technical documentation
    • Vulnerability handling workflow
    • CRA incident workflow
    • Conformity documentation
  • Enterprise

    Custom

    For organizations with advanced security and deployment requirements.

    Your infrastructure. Your policies. Our CRA engine.

    Everything in Defend, plus

    • Unlimited products and repository bundles
    • Private runners
    • VPC or on-premise deployment options
    • SSO & advanced RBAC
    • Custom retention policies
    • Enterprise audit logs
    • Custom integrations
    • Human security review
    • Dedicated compliance support
    • Custom SLA
    • Contractual compliance warranty options

In short

  • Nuowei is CRA compliance software by hafencity.dev GmbH (Hamburg, Germany) for manufacturers of software and other products with digital elements.
  • Nuowei connects GitHub repositories with read-only access, generates an SBOM automatically, monitors vulnerabilities and the software supply chain, and maintains the evidence for a CRA conformity assessment.
  • CRA reporting obligations have applied since 11 September 2026; the Cyber Resilience Act applies in full from 11 December 2027.
  • Pricing: Observe is free for up to 4 repositories, Defend EUR 99 per month for up to 8 repositories (EUR 5 per additional repository), Enterprise custom. Currently in beta with a waitlist; launch in November 2026.
  • Pure SaaS is generally outside the CRA's scope – unless it is the remote data processing solution of a product with digital elements.

Frequently asked questions

For standard CRA products, manufacturers can generally use an internal conformity assessment. We automate and maintain the technical security checks, risk assessment, evidence and documentation needed to support that process. The manufacturer's formal legal responsibilities remain with the manufacturer.

No. CVE monitoring is one input. We combine repository analysis, software inventory, vulnerability intelligence, code security, supply-chain monitoring, security testing, product context and CRA requirements.

Our default architecture is designed to avoid permanently storing customer source code. Repositories are accessed with minimal permissions and analyzed in isolated environments.

Security agents continuously test approved environments and investigate potential attack paths. The goal is not just to detect theoretical issues, but to determine which weaknesses are actually relevant to your product.

Yes. Our goal isn't to replace every scanner you already use. Enterprise customers can feed existing security findings and evidence into the platform.

Not initially. We start with standard software products where internal CRA conformity assessment is possible. Important and critical CRA product categories require additional conformity procedures and are handled separately.

The CRA (Regulation (EU) 2024/2847) entered into force on 10 December 2024. The reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026. All other obligations apply from 11 December 2027.

Actively exploited vulnerabilities and severe incidents affecting the security of your product. An early warning is due within 24 hours of becoming aware, a notification within 72 hours. The final report follows no later than 14 days after a corrective or mitigating measure is available (vulnerabilities) or within one month of the notification (incidents). Reports go to the competent CSIRT via ENISA's Single Reporting Platform.

Generally not. Pure software-as-a-service is not a product with digital elements under the CRA; depending on your company, NIS2 may apply instead. The exception: remote data processing solutions of a product with digital elements – for example the cloud backend without which an app or device cannot perform one of its functions.

Yes. Manufacturers must create a software bill of materials in a machine-readable format covering at least the top-level dependencies. It does not have to be published, but it belongs in the technical documentation and must be provided to market surveillance authorities on request. Nuowei generates the SBOM automatically for every connected repository and keeps it up to date.

The reporting obligations do: they apply to all products with digital elements made available on the market, including those placed on the market before 11 December 2027. The other requirements apply to products placed on the market from 11 December 2027, and to earlier products if they are substantially modified afterwards.

Observe is free for up to 4 repositories. Defend costs EUR 99 per month for up to 8 repositories, plus EUR 5 per additional repository; Enterprise is custom. No seats, no developer licences. Enterprise is priced individually. Nuowei launches in November 2026; you can join the waitlist now.

Up to EUR 15 million or 2.5% of worldwide annual turnover for breaches of the essential requirements and the obligations in Articles 13 and 14. Up to EUR 10 million or 2% for other obligations, and up to EUR 5 million or 1% for incorrect or incomplete information. Micro and small enterprises are not fined for missing the 24-hour early-warning deadline.

The CRA work should happen automatically.

Not three weeks before an audit. Not inside another spreadsheet. Not manually after every release.

Connect your repository once. We'll take it from there.

Join the waitlist

No spam. Only launch news.

Join the waitlist

We launch in November. Be the first to get access.