Skip to main content
Techlogia — AI and Web Development Berlin

Product · in development · self-hosted

CRA-Akte: Cyber Resilience Act evidence on your own network

CRA-Akte keeps the records the Cyber Resilience Act requires from a manufacturer — scope, product file, vulnerability handling, notifications. And it keeps them where they belong: on a machine on your own network, with no cloud and no connection to the outside.

  • Runs without internet access — three containers, one command
  • Released records are sealed at database level
  • No telemetry, no hosted edition, no self-updating

Honest about the status: in development

The foundation and the large majority of modules are running and in use at Techlogia itself. What stands and what is missing is listed openly below — deliberately: a compliance tool that promises more than it delivers does more harm than none at all.

Why this is pressing now

The Cyber Resilience Act — Regulation (EU) 2024/2847 — applies in stages. The middle one is the first that genuinely affects every manufacturer:

  • 11 June 2026Chapter IV: rules on conformity assessment bodies (Art. 35–51)
  • 11 September 2026Article 14: reporting obligations for actively exploited vulnerabilities and severe security incidents
  • 11 December 2027The remainder of the regulation — conformity assessment, technical documentation, CE marking

The reporting duty from September 2026 also covers products already shipped. And its deadlines are short: 24 hours to the early warning, 72 hours to the supplementary notification. Anyone who only starts looking in an emergency — which product is affected, since when it has been on the market, who owns it — burns the deadline on the search.

What CRA-Akte does today

Built and in use, as of 11 August 2026.

  • Legal context

    The relevant articles and deadlines as a look-up reference, in two languages. If the legal position changes, the reference is replaced — not the code.

  • Scope assessment

    Guided questionnaire under Art. 2 and 3. Result: in scope, out of scope or unclear — stating which criterion decided it.

  • Products and versions

    Product lines with classification, support period and version history including the date of placing on the market.

  • Risk assessment

    Foreseeable misuse and risks with likelihood, impact, measure, reference to Annex I and stated residual risk.

  • Bills of materials (SBOM)

    Import in CycloneDX format, checked against stored quality rules — missing licences, hashes or document metadata are named rather than silently accepted.

  • Vulnerabilities and triage

    Assess and decide on incoming reports, with a VEX statement per affected component. The reasoning remains evidenced later.

  • Article 14 notifications

    Cases with the three stages and their deadlines — early warning, supplementary notification, final report.

  • Corrective actions

    What follows from a finding, who owns it and when it was completed.

  • Evidence package

    The status of the Annex I requirements per version, released and retrievable as a package. Basis for the declaration of conformity under Annex V.

  • Accounts and roles

    Five roles, assignment and withdrawal logged. The list explicitly flags when fewer than two accounts hold approval authority.

  • Immutability

    Released records are sealed and cannot be altered afterwards at database level. Every change before that is in the audit log.

  • Archive

    Technical documentation must be kept for ten years under Annex VII. Superseded versions remain retrievable instead of being overwritten.

What is not there yet

A combined overview of upcoming due dates across all product lines is not built yet. Deadlines currently sit on the individual case, not on a shared dashboard.

What it takes to run

  • A machine on your own network

    A small server or a VM is enough.

  • Docker with Compose

    Nothing else — no Python, no Node, no database on the host. Three containers, all images pinned to their digest.

  • A name on the network

    `cra.company.internal` in DNS or a `.local` name. TLS sets itself up.

  • No internet access

    Explicitly not required. Installation is a single command; a setup dialogue then asks for master data and the first administrative account.

What it deliberately does not do

  • Phone home

    No telemetry, no usage figures, no error reports. Outbound connections exist only to sources the operator enables — a vulnerability feed, for instance.

  • Update itself

    The operator installs a new release when they have time. A compliance system that changes unnoticed is a contradiction in terms.

  • Go to the cloud

    A manufacturer's records belong to the manufacturer. There is no hosted edition.

We are the first user

The product file for the Techlogia App lives in CRA-Akte — scope, versions, risk assessment, bill of materials and the released evidence package. It was entered and approved by two different people; four-eyes is therefore not described, it is in use. What of that belongs in public is on our CRA readiness page.

See our own CRA disclosures

And until then?

The Article 14 reporting assistant is finished, free and usable without sign-up — it covers exactly the deadline that starts on 11 September 2026. If you want to know whether CRA-Akte fits your case, write to us. We will tell you openly what holds today and what does not.

Not legal advice

CRA-Akte classifies what follows from the entries and the stored criteria, and makes the reasoning traceable. Legal assessment and responsibility for accuracy, completeness and meeting deadlines remain with the manufacturer.

Frequently asked

Questions we get asked a lot

Is CRA-Akte finished and available to buy?

The product is in development. The foundation and the large majority of modules are running and in use at Techlogia itself; a combined overview of due dates across all product lines is still missing. Whether it holds for your case we will tell you openly on request — there is currently no published price.

Does CRA-Akte run in the cloud?

No, and no hosted edition is planned. The application runs as three containers via Docker Compose on a machine on your own network. A manufacturer's records belong to the manufacturer.

Does the installation need internet access?

No. Internet access is not required for operation. Outbound connections exist only to sources the operator enables — a vulnerability feed, for instance. Telemetry, usage figures and error reports are not transmitted.

Can I change entries afterwards?

Until release yes, and every change is in the audit log. Released records are sealed and cannot be altered afterwards at database level. Evidence that can be adjusted retrospectively is worth little in an audit — which is why the lock does not sit in the application but one layer below.

How is the four-eyes principle implemented?

Through five roles whose assignment and withdrawal are logged. The account list explicitly flags when fewer than two accounts hold approval authority. At Techlogia itself, entry and approval are split between two different people.

Does CRA-Akte cover the reporting duty from 11 September 2026?

Article 14 notification cases with their three stages and deadlines are built into the application. Separately, techlogia.de offers a free reporting assistant that works without sign-up and produces a submission-ready notification text plus a log. In both cases the manufacturer makes the submission.

Is this legal advice?

No. CRA-Akte classifies what follows from the entries and the stored criteria, and makes the reasoning traceable. Legal assessment and responsibility for accuracy, completeness and meeting deadlines remain with the manufacturer.

How do you like this page?