For makers of connected products under the EU CRA

Know within hours when a component in your product is exploited.

Daily checks against the EU and US exploited-vulnerability lists. Your 24-hour CRA notification, drafted.

Get a free exploit check

Send a component list. One-page result within 48 hours. See an example ↓

Illustration: fictional components

Example report

Example: fictional product and placeholder data

ExploitBench · Exploit check

Smart thermostat (fictional)

Checked
2026-10-11 09:12 CET
Components
6
Lists
EU + US exploited

1 component needs triage.5 have no known exploited vulnerability.

Component Version Identifier Status Verdict
Linux kernel 5.15.148 cpe:2.3:o:linux:linux_kernel:5.15.148 No known exploited vulnerability No action needed
BusyBox 1.36.1 cpe:2.3:a:busybox:busybox:1.36.1 No known exploited vulnerability No action needed
OpenSSL 3.0.13 cpe:2.3:a:openssl:openssl:3.0.13 No known exploited vulnerability No action needed
lighttpd 1.4.73 cpe:2.3:a:lighttpd:lighttpd:1.4.73 Actively exploited: CVE-20XX-XXXXX Needs triage: check whether the affected module is enabled
Mbed TLS 3.5.2 cpe:2.3:a:arm:mbed_tls:3.5.2 No known exploited vulnerability No action needed
zlib 1.3.1 cpe:2.3:a:zlib:zlib:1.3.1 No known exploited vulnerability No action needed

Reporting readiness

  • Who submits notifications?
  • EU Login account with MFA?
  • Your national CSIRT: NCSC for the Netherlands, CCB for Belgium

What the CRA now requires

  1. 24 hours

    Early warning after you become aware of an actively exploited vulnerability in your product.

  2. 72 hours

    Full notification, including what users can do to protect themselves.

  3. 14 days

    Final report after a fix is available.

This applies to products already on the market, not just new ones. The fine exemption for micro and small companies covers only the 24-hour early warning.

How it works

  1. Send us your components

    A spreadsheet, an SBOM, or a plain list.

  2. We match and check them

    Each component is matched to a standard identifier and checked against the exploited-vulnerability lists.

  3. You get a one-page result

    What's affected, what isn't, and what to do next.

Ongoing monitoring

€49/ month per product line
excl. VAT

Founding customers: €29/month, fixed for 12 months.

Includes
  • Daily checks
  • An alert within hours when something is exploited
  • A triage note for each alert
  • Draft text for the 24-hour, 72-hour and final reports
  • A monthly monitoring report you can share with your own customers

You stay in control: you decide whether to report, and you submit it yourself through the EU reporting platform. We prepare the text.

Your data

We only need component names and versions: no source code, no firmware.

Your data is stored in the EU, never shared, and deleted within [X] days if you don't become a customer.

Send a component list. Get one page back within 48 hours.

Get a free exploit check

check@[DOMAIN] · No call needed.

Questions

Do I need to send firmware or source code?

No. Component names and versions are enough.

Do you submit the notification for me?

No, you submit it through the EU reporting platform. We prepare the text so it takes minutes, not hours.

What counts as "actively exploited"?

Reliable evidence that attackers have used the vulnerability in real systems. Whether your product is affected depends on whether the vulnerable code is present and reachable; that's what our triage note covers.

Is this legal advice?

No. We give you the information and drafts; the decisions are yours.