EU Cyber Resilience Act — mandatory reporting starts September 2026

CRA compliance
shouldn't be complicated.

Verimu scans your dependencies, generates CRA-compliant SBOMs, and alerts you instantly when a vulnerability is discovered. One install. Zero training.

Mandatory vulnerability reporting begins in

00days
:
00hours
:
00min
:
00sec

September 11, 2026 — Penalties up to €15M or 2.5% of global turnover

24h
CVE reporting window under CRA
€15M
Maximum penalty for non-compliance
<5 min
Time to install and configure Verimu
€49/mo
Starting price — not thousands
Built by compliance engineers

Made by medtech engineers who've been through CRA compliance.

We built Verimu because we needed it ourselves. Our team has hands-on experience implementing CRA and IEC 62443 requirements in regulated European industries. We know the pain of generating SBOMs, tracking vulnerabilities, and producing audit-ready documentation — so we automated it.

CycloneDX SBOMsNVD + EUVD + CISA KEVCRA Article 11 ReadyEU-Hosted
verimu scan output
✓ Scanned 847 dependencies
✓ SBOM generated (CycloneDX 1.7)
✓ Cross-referenced NVD, EUVD, CISA KEV

⚠ 2 vulnerabilities found:
  CVE-2026-1234  lodash@4.17.20  HIGH
  CVE-2026-5678  express@4.18.1  MEDIUM

→ Alert sent to: cto@acme.eu, security@acme.eu
→ CRA report: verimu.com/reports/acme-2026-02
→ Next review deadline: 72h (Feb 10, 2026)
Why switch?

Enterprise tools charge thousands per month.
They still don't solve CRA compliance.

Most SCA tools were built for American security teams, not European compliance officers. Verimu was built specifically for the EU Cyber Resilience Act.

FeatureVerimu
from €49/mo
Enterprise SCA
€2,000–5,000+/mo
CRA-specific compliance reports
SBOM generation (CycloneDX)
CVE alerting
24h→72h→14d CRA notification workflow
EUVD (EU Vulnerability Database)
CRA conformity score per project
Setup in under 5 minutes
No security training required
EU-hosted infrastructure
Price includes all features
Free tool — no signup required

Need an SBOM right now?

Paste your package.json and generate a CRA-compliant CycloneDX 1.7 SBOM instantly in your browser. No install needed.

Generate SBOM Now
How It Works

Three steps. Zero confusion.

No training required. Your engineering team adds one line — Verimu handles the rest.

Our project uses
with

Step 1Add the GitLab CI Job

Add the Verimu stage to your .gitlab-ci.yml. Connects to your project with read-only access.

Step 2Set Alert Contacts

Define who gets notified when a CVE affects your dependencies. Assign by project, severity, or team.

Step 3You're CRA Compliant

SBOMs generate automatically every commit. CVE alerts fire in real-time. Download compliance reports anytime.

your-project/.gitlab-ci.yml
verimu-compliance:
  image: node:20
  stage: test
  variables:
    VERIMU_API_KEY: $VERIMU_API_KEY
  script:
    - npx verimu scan --fail-on HIGH
  artifacts:
    paths:
      - sbom.cdx.json

# That's it. SBOM generated. CVEs checked. Alerts sent.

Want to see the SBOM output before you install anything?

Try It Now — Generate an SBOM in Your Browser

No install, no signup. Runs entirely in your browser.

Verimu supports NuGet (C#/.NET), Maven (Java), Cargo (Rust), go.mod (Go), npm (Node.js), pip (Python), Composer (PHP), and Bundler (Ruby) — across GitHub, GitLab, and Bitbucket. Need another package manager? Let us know.

Pricing

Compliance shouldn't break the bank.

Start free. Upgrade when you're ready. No lock-in, no surprises.

Free

Try Verimu on a single repo. No credit card required.

€0forever
  • 1 repository
  • Basic CVE scanning
  • SBOM export (CycloneDX)
  • Weekly email digest
  • Community support
Start Free

Starter

For small teams getting CRA-ready.

€49/month
  • Up to 5 repositories
  • Real-time CVE alerts
  • SBOM per commit (CycloneDX & SPDX)
  • Up to 5 alert contacts
  • CRA compliance dashboard
  • Slack & Teams integration
  • Email support (48h)
Start 14-Day Trial
Most Popular

Professional

Full CRA compliance for growing companies.

€149/month
  • Up to 25 repositories
  • Real-time CVE alerts + CISA KEV
  • SBOM per commit (all formats)
  • Unlimited alert contacts
  • CRA conformity reports (PDF)
  • 24h → 72h → 14d notification workflow
  • EUVD integration
  • Priority support (24h)
  • Audit log
Start 14-Day Trial

Start your CRA compliance today.

Get early access to Verimu. We'll have you compliant in under 5 minutes.

No credit card required. Free tier available forever.