This approach turns regulatory compliance from an after‑the‑fact documentation exercise into a continuous engineering workflow.
CRACI has raised €1.4 million in pre‑seed funding to develop its cybersecurity compliance platform.
Publicly available information confirms the funding amount but does not clearly identify the investors involved or detailed plans for how the funds will be allocated. Based on available reporting, those details have not been widely disclosed.
Modern software products rely heavily on open‑source libraries, third‑party components, and complex build pipelines. This creates a software supply chain where vulnerabilities can enter through dependencies, build tools, or integration systems.
Managing those risks is difficult because development teams must:
CRACI addresses this by connecting vulnerability discovery, tracking, and remediation directly into development pipelines, allowing teams to handle security issues as part of everyday development work rather than separate compliance processes.
The EU Cyber Resilience Act (CRA) is a sweeping cybersecurity regulation covering products with digital elements sold in the European Union. The law introduces mandatory security requirements for both hardware and software manufacturers.
Key goals of the regulation include:
The rules apply broadly to connected products, including software applications, operating systems, embedded systems, and devices connected to networks.
For many companies, compliance requires new processes for vulnerability management, documentation, and reporting across development teams.
The Cyber Resilience Act officially entered into force in December 2024, but companies are currently in a transition period.
Two upcoming milestones are particularly important for businesses:
Because of the long development cycles for many products, companies are already preparing their software pipelines to meet these requirements.
CRACI’s platform is built around the idea that compliance should happen inside developer workflows rather than in external audit processes.
By embedding security tooling into CI/CD pipelines, the system helps organizations:
These capabilities support the type of continuous security monitoring and lifecycle management expected under the Cyber Resilience Act.
The Cyber Resilience Act represents one of the first major regulatory frameworks focused specifically on software supply chain security at scale.
Because the regulation affects nearly every connected product sold in the EU, organizations across industries — from device manufacturers to software vendors — will need new tools and workflows to demonstrate compliance.
Platforms that automate vulnerability management, documentation, and remediation inside development pipelines are likely to become a key part of that transition.
CRACI is one of the early startups positioning itself in that emerging compliance and supply‑chain security market as European companies prepare for the 2026 and 2027 CRA deadlines.