CRACI is a Finnish cybersecurity startup that raised €1.4M in pre‑seed funding to build a platform that embeds vulnerability tracking and remediation into software development pipelines, helping companies comply with... The platform integrates with tools like GitHub, GitLab, and Jenkins to automate vulnerability tra...

Create a landscape editorial hero image for this Studio Global article: What is CRACI, how much funding has the Finnish cybersecurity startup raised, who invested, what problem does its software supply chain secu. Article summary: CRACI is a Finnish cybersecurity startup building a software supply chain security platform that helps companies embed security, vulnerability tracking, and remediation into development pipelines to meet requirements suc. Topic tags: general, government, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "CRACI helps you track vulnerabilities, manage compliance documentation, and stay ahead of EU regulations—all from your existing CI/CD pipeline. Key milestones you need to prepare f" source context "CRACI - Cyber Resilience Act Compliance Automation" Reference image 2: visual subject "Helsinki-based CR
European companies that build connected software or hardware are entering a new regulatory era. The EU Cyber Resilience Act (CRA) will soon require strict cybersecurity standards across the lifecycle of digital products. Startups are already emerging to help companies meet those obligations — including CRACI, a Finnish cybersecurity company focused on software supply‑chain security and compliance automation.
CRACI is a Finland‑based cybersecurity startup developing a platform designed to integrate security and compliance directly into software development workflows. The system connects security monitoring, vulnerability tracking, and remediation processes to developer pipelines so organizations can continuously manage software supply‑chain risks.
The platform integrates with widely used CI/CD tools such as GitHub, GitLab, and Jenkins, allowing security tasks to run alongside normal development activities. Instead of handling compliance through periodic audits or manual tracking, the platform automatically identifies vulnerabilities, assigns remediation tasks, and tracks fixes within the development pipeline.
This approach turns regulatory compliance from an after‑the‑fact documentation exercise into a continuous engineering workflow.
CRACI has raised €1.4 million in pre‑seed funding to develop its cybersecurity compliance platform.
Publicly available information confirms the funding amount but does not clearly identify the investors involved or detailed plans for how the funds will be allocated. Based on available reporting, those details have not been widely disclosed.
Modern software products rely heavily on open‑source libraries, third‑party components, and complex build pipelines. This creates a software supply chain where vulnerabilities can enter through dependencies, build tools, or integration systems.
Managing those risks is difficult because development teams must:
CRACI addresses this by connecting vulnerability discovery, tracking, and remediation directly into development pipelines, allowing teams to handle security issues as part of everyday development work rather than separate compliance processes.
The EU Cyber Resilience Act (CRA) is a sweeping cybersecurity regulation covering products with digital elements sold in the European Union. The law introduces mandatory security requirements for both hardware and software manufacturers.
Key goals of the regulation include:
The rules apply broadly to connected products, including software applications, operating systems, embedded systems, and devices connected to networks.
For many companies, compliance requires new processes for vulnerability management, documentation, and reporting across development teams.
The Cyber Resilience Act officially entered into force in December 2024, but companies are currently in a transition period.
Two upcoming milestones are particularly important for businesses:
Because of the long development cycles for many products, companies are already preparing their software pipelines to meet these requirements.
CRACI’s platform is built around the idea that compliance should happen inside developer workflows rather than in external audit processes.
By embedding security tooling into CI/CD pipelines, the system helps organizations:
These capabilities support the type of continuous security monitoring and lifecycle management expected under the Cyber Resilience Act.
The Cyber Resilience Act represents one of the first major regulatory frameworks focused specifically on software supply chain security at scale.
Because the regulation affects nearly every connected product sold in the EU, organizations across industries — from device manufacturers to software vendors — will need new tools and workflows to demonstrate compliance.
Platforms that automate vulnerability management, documentation, and remediation inside development pipelines are likely to become a key part of that transition.
CRACI is one of the early startups positioning itself in that emerging compliance and supply‑chain security market as European companies prepare for the 2026 and 2027 CRA deadlines.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
CRACI is a Finnish cybersecurity startup that raised €1.4M in pre‑seed funding to build a platform that embeds vulnerability tracking and remediation into software development pipelines, helping companies comply with...
CRACI is a Finnish cybersecurity startup that raised €1.4M in pre‑seed funding to build a platform that embeds vulnerability tracking and remediation into software development pipelines, helping companies comply with... The platform integrates with tools like GitHub, GitLab, and Jenkins to automate vulnerability tracking and remediation inside CI/CD pipelines, turning regulatory compliance into an ongoing developer workflow.[7]
The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for connected software and hardware sold in the EU, with major reporting obligations beginning in September 2026 and full compliance required...