CRA reporting obligations begin in days · the maximum fine is €15,000,000 Calculate your fleet →
Secure access
EU Cyber Resilience Act · enforcement countdown

The CRA’s maximum fine is €15 million. Make sure it’s never your number.

Proofwright is the fleet-first EU Cyber Resilience Act (CRA) compliance and evidence platform for WordPress agencies — tamper-evident proof across every client site, so you can show the work was done.

Not on WordPress? Proofwright now does CRA compliance for any software via SBOM — see all platforms →

00days
00hrs
00min
00sec
The compliance clock

The fines aren’t hypothetical. Neither is the deadline.

days until reporting obligations begin · % of the runway since the CRA entered into force has passed.

11 Dec 2024in force 11 Sep 2026reporting begins 11 Dec 2027full requirements
The CRA Roadmap

One ordered path to readiness — and exactly what's mandatory.

No more "where do I even start?". Every step is flagged Must (legally required, with the regulation citation), Recommended or Optional, with live status — mirrored straight from the plugin dashboard.

Required steps complete · 2 of 5 Must
Confirm scope & reporting entityScope wizard → manufacturer / open-source steward / distributorMust · Art. 3Done
Build the SBOM — incl. npm/yarn front-end depsSPDX 2.3 + CycloneDX 1.5, hash-chained snapshotsMust · Annex IDone
4Generate the CRA documentsDeclaration of Conformity (Annex V), Technical Doc (Annex VII), Risk Assessment, Annex II user docMustTo-do
5Declare the support periodHow long you'll ship security updates — Art. 13(8)MustTo-do
6Turn on continuous monitoring + the incident workflow24h / 72h / final · ENISA submission-readyRecommendedTo-do
7Seal & export an evidence packOffline, dependency-free verifier · optional PKI signatureRecommendedTo-do
8Reuse the evidence for ISO 27001 / SOC 2 / NIS2Cross-framework control crosswalkOptionalTo-do
Inside the platform

Every feature, demonstrated.

Swipe through the actual Proofwright admin — the dashboard, conformity tracker and CRA evidence your team works in, on every WordPress site you manage.

SBOM spine

Bills of materials, dated & diffable

SPDX + CycloneDX snapshots of every WordPress plugin, theme and the transitive dependencies inside them — EOL components flagged.

sbom · acme-dental.comSPDX 2.3 · CycloneDX 1.6
woocommerce@8.6.1
├─ jetpack-autoloader@3.0
├─ composer/installers@2.2 sha256:7b1c…
├─ league/container@4.2 ⚑ EOL
└─ @wordpress/blocks@12.26
Vulnerability monitoring

Every CVE: open → mitigated → fixed

Continuous monitoring with who/when/how recorded as evidence — this is the data behind Annex I, Part II.

vulnerabilities · live3 open · 41 resolved
CVE-2026-1187
contact-form-7 · RCE
critical
CVE-2026-0934
woocommerce · XSS
mitigated
CVE-2026-0421
jetpack · SSRF
fixed ✓
Readiness dashboard

Two scores, and the path between them

Posture grades the evidence you’ve produced; readiness counts CRA requirements met. The console hands you the single highest-impact next action.

proofwright · acme-dental.comupdated live
90
Posture score90 / 100
32%
CRA readiness6 of 19 met
Readiness ≠ legal compliance
Run scan / refresh SBOMDownload SBOM
0Confirm scope & reporting entity0/1
Stand up your reporting front door2/2
2Attest product security properties0/10
3Documents & disclosure0/3
Keep it continuous4/4
Next best action: Disclose fixed-vulnerability info once updates ship · II(4) · +5.3%Open
Annex I conformity

Every requirement, mapped to evidence

Part II (vulnerability handling) is evidenced automatically from your scans. Part I you attest, each with a named control.

conformity · Reg (EU) 2024/2847Annex I · Part II
Part
II(1)
Components & vulnerabilities, incl. SBOMMet — auto
Part
II(2)
Remediate vulnerabilities without delayMet — auto
Part
II(4)
Disclose fixed-vulnerability informationPending
Part
II(5)
Coordinated disclosure policyMet — auto
Part
II(7)
Securely distribute updatesPending
Not legal advice · 19 requirements across Part I & II
Incident workflow

From CVE to ENISA in minutes

A guided 24h / 72h / 14-day flow that pre-fills from your inventory and produces an SRP-ready package.

incident · INC-2048Single Reporting Platform
24hEarly warning submitted
72hFull notification to CSIRT + ENISA
14dFinal report — corrective measure
SRP-ready package generated
Evidence packs

Tamper-evident, verifiable offline

Hash-chained, dated from day one. Export a per-client pack anyone can verify — independently, white-labelled.

evidence pack · northwind-law.euQ3 2026
SBOM snapshot
SPDX + CycloneDX · sealed
#a1f0
Remediation log
who · when · how
#3c7b
Verified offline ✓
sha256:9f2a7c1e…b40d
Fleet console

Your whole fleet, one screen

Every WordPress site rolled up: CRA compliance posture, SBOMs, vulnerabilities and incidents — metered by site.

fleet · 247 sitesavg posture 92
acme-dental.com94
northwind-law.eu88
harbor-clinic.org97
New in v0.22

What we shipped since the last refresh.

The headline additions across clarity, evidence, incident reporting and the supply chain.

CRA Roadmap

A graphical step-by-step path to readiness with Must / Recommended / Optional flags and live status.

Removes the "where do I start?" anxiety.

Guided first-run setup

An onboarding checklist that tracks itself from your site's real state — entity, product class, first scan, security contact.

Set up in minutes, not days.

Compliance calendar

Every CRA deadline — reporting windows, support-period end, the Dec 2027 date — in one dated view, with iCal export.

The deadlines come to you.

Annex II user document

Generates the required "Information & Instructions to the User" — secure setup, support end-date, how to report — in PDF / Word / HTML / MD.

One less document to write.

Front-end / npm scanning

The SBOM now inventories the npm/yarn dependencies bundled inside plugins and themes — JavaScript a PHP-only scan misses.

Nothing hides from the bill of materials.

Posture analytics

Mean / median time-to-fix, open findings and the oldest, and a score trend — evidence of continuous, not point-in-time, diligence.

Proves it over time.

ENISA — submission-ready

The 24h / 72h / final workflow now has structured fields, a completeness gate, and built-in transport for when ENISA's endpoint goes live.

File, don't scramble — for Sep 2026.

Supplier conformity register

Due diligence on the third-party components you bundle (Art. 13): SBOM? Declaration? security contact? support period? Per-maker status.

Your supply chain, documented.

Integrations & scale

Patchstack feed (BYO key), Slack / Teams digests, a token-gated Fleet Connect API, and an ISO 27001 / SOC 2 / NIS2 control crosswalk.

Reuse one evidence base everywhere.
What you can download

Reports an auditor — or an enterprise client — will actually accept.

Every artifact is dated, hash-chained and exportable. Hand them over, white-labelled, whenever a client or regulator asks.

Software Bill of Materials

Full + transitive component inventory, diffable over time, EOL flagged.

SPDX 2.3CycloneDX 1.6JSON
Download sample

Per-client evidence pack

Tamper-evident chain: inventory → monitoring → remediation → reporting.

PDFJSONoffline verifier
Download sample

ENISA report package

SRP-ready 24h / 72h / 14-day filings, pre-filled from your inventory.

PDFJSONSRP schema
See an example

CRA conformity documents

Declaration of conformity, technical file outline and the five core docs.

PDFDOCX
Download sample

Posture & readiness report

Scored, time-stamped readiness snapshot with the gap list and trend.

PDF
Download sample

VEX statements

Vulnerability Exploitability eXchange — say which CVEs actually affect you.

CycloneDX VEXJSON
Download sample
Don’t take our word for it

Read the mandate yourself.

Proofwright is built directly on the EU Cyber Resilience Act — the dates, the obligations and the €15M fines come straight from the official text. Go to the source.

One engine · every platform

Choose how you connect.

WordPress and Drupal have a native module — install once and stay current. On any other stack, bring an SBOM: the same readiness, sealed evidence and reporting, however it gets in.

Fastest path

On WordPress

Live

One plugin per site. Inventory, evidence and CRA readiness stay current automatically — no exports, no scripts.

Install the plugin
  • Live software inventory, auto-updated on every change
  • Hash-sealed, tamper-evident evidence log
  • CRA readiness score with guided fixes for every gap
  • One-click, audit-ready compliance report
Minutes to set up Any WordPress host VAT invoice included

Any other stack

Drupal & any stack

Drupal installs a native module, just like WordPress. On anything else, feed in a software bill of materials — same engine, any platform.

Install on Drupal Live Get started
Upload an SBOM Live Get started
Connect a repo Live Get started
Add to CI/CD Live Get started
Scan a container Live Get started
However you connect, every path lands the same place — CRA readiness, sealed evidence and audit-ready reporting.
Agency / Fleet · the resale lever

First, see what your fleet is worth. Then pick a plan.

White-label Proofwright into your care plans and bill it to clients. Drag the levers to see what you can charge on top of every site — and what you keep after the Proofwright cost.

Test an example fleet:
Your margin, after the Proofwright cost
€7,296
per year · recurring, across your fleet
You bill clients
€8,640 /yr
Proofwright costs you
€1,344 /yr
Your markup
6.4×
Clients covered
80
See what the platform costs ↓
Pricing

Cover your fleet for less than one hour of breach response.

You’ve sized the upside above. Here’s the cost — every plan keeps a tamper-evident evidence trail an auditor or enterprise client actually accepts.

Founding offer — lock today's rate before the 11 Sep 2026 reporting deadline ( days left). Your founding price holds for the life of your subscription.

Free

The full get-it-done toolkit for one site — standalone, no account, no phone-home.

€0
  • SBOM — SPDX 2.3 + CycloneDX 1.5
  • CRA posture score
  • All CRA documents (incl. Annex II)
  • Roadmap, calendar, control crosswalk
  • Public security.txt + VDP page
  • 1 site · scope wizard
Start free

Solo

Everything in Free — plus prove and maintain it for one site.

€49€29 / yr
Founding rate · before 11 Sep 2026
  • Vulnerability monitoring + VEX
  • Snapshots + diff · incident + ENISA filing
  • Supplier register (Art. 13 due diligence)
  • Evidence pack + audit binder + offline verifier
  • 1 site

Pro

Everything in Solo — for a few products, plus a build pipeline.

€149€99 / yr
Founding rate · before 11 Sep 2026
  • Everything in Solo
  • CI/CD gate — shift CRA checks left in your build
  • Webhooks + REST posture API
  • Up to 10 sites / products
Built for your book of clients

Agency / Fleet

Everything in Pro — at fleet scale, branded, with a team.

€999from €499 / yr · metered by sites
Founding rate · before 11 Sep 2026
  • Central fleet console + Connect API
  • White-label · PKI-signed evidence packs
  • Team seats · reviewer sign-off (SoD)
  • Fleet re-attestation · priority support
  • Up to 500 sites

↑ you sized this margin above

CapabilityFreeSoloProAgency
SBOM (SPDX + CycloneDX) · posture score · scope wizard
CRA documents incl. Annex II · roadmap · calendar · crosswalk
Public security.txt + VDP page
Immutable snapshots + diff · score drivers
Vulnerability monitoring + remediation ledger + VEX
Incident / SRP workflow (24h / 72h / final)
Evidence packs + offline verifier + Audit Binder
Supplier conformity register (Art. 13 due diligence)
Scheduled scans + alerts (email / Slack / Teams)
CI/CD gate + webhooks
Fleet console (cross-site rollup)
PKI / x.509-signed, white-label evidence packs
White-label resale · team seats / multi-tenant
Fleet Connect API (hosted-console pull)
Monitored sites1110500

Prices in EUR per year, excl. VAT · EU B2B reverse-charge where applicable · lock today's rate as a founding member.

Questions, answered

“But does this even apply to my agency?”

Scope, deadlines, the 24 / 72 / 14 reporting, reselling, data residency — the real scenarios agencies ask about, answered straight (and we flag where the law is genuinely contested).

Browse all 40 answers →

Don’t be the test case.

Have the proof ready across your fleet — and your margin running — before 11 September 2026.

00days
00hrs
00min
00sec

Talk to us

Have a fleet to onboard?

Tell us how many client sites you manage and what you'd like to white-label. We'll map it to a plan and a rollout before the deadline.

Or email connect@proofwright.eu