Proofwright is the fleet-first EU Cyber Resilience Act (CRA) compliance and evidence platform for WordPress agencies — tamper-evident proof across every client site, so you can show the work was done.
— days until reporting obligations begin · —% of the runway since the CRA entered into force has passed.
No more "where do I even start?". Every step is flagged Must (legally required, with the regulation citation), Recommended or Optional, with live status — mirrored straight from the plugin dashboard.
Illustrative roadmap — your live status comes from your own site's scan. Proofwright is a workflow and evidence tool that supports a CRA due-diligence posture; it is not legal advice and not a guarantee of compliance. Citations per Regulation (EU) 2024/2847.
Swipe through the actual Proofwright admin — the dashboard, conformity tracker and CRA evidence your team works in, on every WordPress site you manage.
The headline additions across clarity, evidence, incident reporting and the supply chain.
A graphical step-by-step path to readiness with Must / Recommended / Optional flags and live status.
Removes the "where do I start?" anxiety.An onboarding checklist that tracks itself from your site's real state — entity, product class, first scan, security contact.
Set up in minutes, not days.Every CRA deadline — reporting windows, support-period end, the Dec 2027 date — in one dated view, with iCal export.
The deadlines come to you.Generates the required "Information & Instructions to the User" — secure setup, support end-date, how to report — in PDF / Word / HTML / MD.
One less document to write.The SBOM now inventories the npm/yarn dependencies bundled inside plugins and themes — JavaScript a PHP-only scan misses.
Nothing hides from the bill of materials.Mean / median time-to-fix, open findings and the oldest, and a score trend — evidence of continuous, not point-in-time, diligence.
Proves it over time.The 24h / 72h / final workflow now has structured fields, a completeness gate, and built-in transport for when ENISA's endpoint goes live.
File, don't scramble — for Sep 2026.Due diligence on the third-party components you bundle (Art. 13): SBOM? Declaration? security contact? support period? Per-maker status.
Your supply chain, documented.Patchstack feed (BYO key), Slack / Teams digests, a token-gated Fleet Connect API, and an ISO 27001 / SOC 2 / NIS2 control crosswalk.
Reuse one evidence base everywhere.Every artifact is dated, hash-chained and exportable. Hand them over, white-labelled, whenever a client or regulator asks.
Full + transitive component inventory, diffable over time, EOL flagged.
Tamper-evident chain: inventory → monitoring → remediation → reporting.
SRP-ready 24h / 72h / 14-day filings, pre-filled from your inventory.
Declaration of conformity, technical file outline and the five core docs.
Scored, time-stamped readiness snapshot with the gap list and trend.
Vulnerability Exploitability eXchange — say which CVEs actually affect you.
Proofwright is built directly on the EU Cyber Resilience Act — the dates, the obligations and the €15M fines come straight from the official text. Go to the source.
WordPress and Drupal have a native module — install once and stay current. On any other stack, bring an SBOM: the same readiness, sealed evidence and reporting, however it gets in.
Fastest path
One plugin per site. Inventory, evidence and CRA readiness stay current automatically — no exports, no scripts.
Install the pluginAny other stack
Drupal installs a native module, just like WordPress. On anything else, feed in a software bill of materials — same engine, any platform.
White-label Proofwright into your care plans and bill it to clients. Drag the levers to see what you can charge on top of every site — and what you keep after the Proofwright cost.
Illustrative. Agency lists at €999/yr metered by sites — founding €499 before 11 Sep 2026 (≈ €1.40 / site cost assumed here); you set your own client pricing. A workflow and evidence tool that supports a CRA posture — not legal advice.
You’ve sized the upside above. Here’s the cost — every plan keeps a tamper-evident evidence trail an auditor or enterprise client actually accepts.
The full get-it-done toolkit for one site — standalone, no account, no phone-home.
Everything in Free — plus prove and maintain it for one site.
Everything in Solo — for a few products, plus a build pipeline.
Everything in Pro — at fleet scale, branded, with a team.
↑ you sized this margin above
| Capability | Free | Solo | Pro | Agency |
|---|---|---|---|---|
| SBOM (SPDX + CycloneDX) · posture score · scope wizard | ✓ | ✓ | ✓ | ✓ |
| CRA documents incl. Annex II · roadmap · calendar · crosswalk | ✓ | ✓ | ✓ | ✓ |
| Public security.txt + VDP page | ✓ | ✓ | ✓ | ✓ |
| Immutable snapshots + diff · score drivers | — | ✓ | ✓ | ✓ |
| Vulnerability monitoring + remediation ledger + VEX | — | ✓ | ✓ | ✓ |
| Incident / SRP workflow (24h / 72h / final) | — | ✓ | ✓ | ✓ |
| Evidence packs + offline verifier + Audit Binder | — | ✓ | ✓ | ✓ |
| Supplier conformity register (Art. 13 due diligence) | — | ✓ | ✓ | ✓ |
| Scheduled scans + alerts (email / Slack / Teams) | — | ✓ | ✓ | ✓ |
| CI/CD gate + webhooks | — | — | ✓ | ✓ |
| Fleet console (cross-site rollup) | — | — | — | ✓ |
| PKI / x.509-signed, white-label evidence packs | — | — | — | ✓ |
| White-label resale · team seats / multi-tenant | — | — | — | ✓ |
| Fleet Connect API (hosted-console pull) | — | — | — | ✓ |
| Monitored sites | 1 | 1 | 10 | 500 |
Not legal advice — a workflow and evidence tool that supports a CRA due-diligence posture, with no guarantee of compliance. The free plugin is fully functional on its own; paid tiers are an optional licence that adds the rest, and a lapsed licence degrades gracefully to the free feature set — nothing breaks, no data is lost. CRA fine figures from Regulation (EU) 2024/2847, Art. 64.
Prices in EUR per year, excl. VAT · EU B2B reverse-charge where applicable · lock today's rate as a founding member.
Scope, deadlines, the 24 / 72 / 14 reporting, reselling, data residency — the real scenarios agencies ask about, answered straight (and we flag where the law is genuinely contested).
Have the proof ready across your fleet — and your margin running — before 11 September 2026.
Tell us how many client sites you manage and what you'd like to white-label. We'll map it to a plan and a rollout before the deadline.
Or email connect@proofwright.eu
By paying you agree to the Terms (incl. the refund policy). A workflow & evidence tool — not legal advice.