The moment a CVE affecting a dependency you ship goes onto CISA's Known Exploited Vulnerabilities list, you get an email with the EU CRA Article 14 24-hour clock already started and the ENISA report fields pre-filled.
Paste your key dependencies, comma-separated. Checks them right now against the live CISA KEV catalog — no account, no card.
Already know you have one to report? Generate your ENISA report fields free — no signup.
$19/mo · cancel anytime · no contract, no sales call, no login required to sign up
Start daily monitoring →Article 14 is brand new — it took effect yesterday for anyone reading this on launch day — and it applies to a huge base of small SaaS and software vendors who have no compliance team and no existing process for watching a government vulnerability feed. CRA Kit and similar tools sell one-time document generators (policies, ENISA templates); real continuous SBOM-vs-vulnerability monitoring exists but is enterprise DevSecOps tooling built and priced for engineering teams running CI/CD pipelines, not a solo founder. Nobody sells "tell me the moment one of my listed dependencies is being actively exploited" cheaply and instantly, self-serve. Read the full plain-language Article 14 explainer if you're still figuring out whether this applies to you.
Solo founders and small software vendors with EU customers who now have a real, unfamiliar legal obligation and no compliance team to hand it to.
Other tools from the same builder: KDPCheck (KDP AI-disclosure checker) · Edge Thirteen (value-investing newsletter) · StripeCheckup (Stripe integration audit) · TriageShield (AI-slop vuln-report checker) · BrewClear (TTB label clearance) · MarkRadar (trademark + domain-squat alerts) · FilingCheck (SEC-grounded stock reports) · AuditFlag (SEC going-concern alerts) · RenewalMatrix (click-to-cancel compliance) · SlopCheck (YouTube demonetization-risk checker) · VercelPyCheck (Vercel Python deploy bug scanner)