Pricing
The comparison that matters is not against another tool. It is against a consultant’s invoice, or against the €18,400 per product the European Commission modelled for self-assessment.
Starter
One product, done properly
or €990 a year — two months free
One-person companies and small teams with a single paid app, plugin or SDK.
- One product
- Annex I Part I and Part II requirement tracking with evidence
- Cybersecurity risk assessment (Article 13(2))
- CycloneDX SBOM generation, continuous OSV monitoring
- Coordinated vulnerability disclosure policy and hosted security.txt
- Annex VII technical file and EU declaration of conformity as PDF
- Article 14 incident reporting workflow with 24/72-hour clocks
- Tamper-evident audit trail
- 2 users
Growth
Most vendorsA product line
or €2,490 a year — two months free
Small IoT, electronics and machinery brands, and SaaS firms shipping agents or mobile apps alongside the platform.
- Up to 10 products
- Everything in Starter, per product
- Risk library to start each assessment from
- Versioned declarations with revision history
- Audit trail export with chain verification
- Up to 10 user seats
Scale
A portfolio, or a representative
or €4,990 a year — two months free
Vendors with a real catalogue, importers and authorised representatives holding files on behalf of non-EU manufacturers.
- Up to 100 products
- Everything in Growth
- Priority support, 1 business day
- Up to 50 user seats
Would rather not do it yourself?
We build the technical file for you from €2,900, or tell you where you stand for €600.
The trial runs 4 days and takes a card up front; cancel before it ends and you are not charged. During it you can produce every artefact; documents carry a draft watermark until you pick a plan. Cancel any time — your documents and audit trail remain downloadable, because Article 31(3) obliges you to retain them.
What is in each plan
| Feature | Starter €99 | Growth €249 | Scale €499 |
|---|---|---|---|
Products | 1 | 10 | 100 |
User seats | 2 | 10 | 50 |
Annex I requirement tracking Annex I | included | included | included |
Cybersecurity risk assessment Article 13(2) | included | included | included |
CycloneDX and SPDX SBOM Annex I, Part II, point 1 | included | included | included |
Continuous vulnerability monitoring Annex I, Part I, point 2(a) | included | included | included |
CVD policy and hosted security.txt Annex I, Part II, points 5–6 | included | included | included |
Annex VII technical file Annex VII | included | included | included |
EU declaration of conformity Article 28, Annex V | included | included | included |
Article 14 reporting workflow Article 14 | included | included | included |
Tamper-evident audit trail Article 31(3) | included | included | included |
Audit trail export with verification | — | included | included |
Shared risk library across products | — | included | included |
Scans per month | 50 | 500 | 5,000 |
What you would otherwise pay
| Option | Cost | What you get |
|---|---|---|
| Do nothing | Up to €15m or 2.5% of worldwide turnover | Administrative fines for breaching the essential requirements or the manufacturer obligations (Article 64). |
| Compliance consultant | €8,000 – €30,000 per product | Day rates, and the deliverable is a document set that goes stale the moment you ship a new dependency. |
| Enterprise compliance platform | From €10,000 / year | Built for a security team you do not have, sold through a demo funnel and an annual contract. |
| Commission’s own estimate, per product | €18,400 self-assessed / €25,000 third-party | From the impact assessment behind the Regulation. This is the number your board should be comparing against. |
| CRA Bureau | From €99 / month | Self-serve, live from the day you sign up, and the artefacts stay current because the scanning is continuous. |
Questions people actually ask
Does this make me compliant?
No tool can. It produces the artefacts the Regulation requires and tells you honestly where they are incomplete — but the statements in them have to be true, and only you can make them true. The declaration of conformity is deliberately blocked while a blocking requirement is unmet, because signing one means assuming legal responsibility under Article 28(1).
What if my product needs a notified body?
The workspace records the body’s details and puts them on the declaration where Annex V requires. It does not replace the assessment — Annex III Class II and Annex IV products cannot be self-assessed. What it does is prepare the documentation the body will ask for first, which is most of the engagement cost.
Can I export everything and leave?
Yes, and you should be able to: Article 31(3) requires you to retain the technical documentation for ten years or the support period. Every PDF, the CycloneDX and SPDX SBOMs, and the audit trail with its raw JSON chain are downloadable at any time.
Do you see my source code?
No. The scanner reads dependency manifests and lockfiles only — never source. For a public repository it fetches just those files over the API; for an upload they are parsed in memory.
Where does the vulnerability data come from?
OSV.dev, which aggregates GHSA, PyPA, RustSec, the Go vulnerability database and the distro databases. It is free and needs no key, which is why this can cost €99 a month rather than carrying a per-seat feed licence.
What happens after December 2027?
The work does not stop. The incident reporting duty and the support period obligations run for years afterwards, and the SBOM and vulnerability position need maintaining for as long as the product is supported. The deadline is the start of the obligation, not the end.
Try it on one product
Watermarked drafts, no card. Add a product, generate the technical file, and see exactly how far from ready you are. That answer is worth having even if you never pay.