Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

CRACI

SBOM generation and Cyber Resilience Act reporting built into the CI build

ToolSBOM AnalysisCloud

Pricing: Pro at 330 euro per month, listed at 30 euro per month until the end of 2026, covering 1 to 20 users, one actively monitored SBOM (further SBOMs at 300 euro per month each) and 10,000 build minutes, then 0.004 euro per minute. Enterprise is annual and priced on request.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed September 2026 · How we review listings

What is CRACI?

CRACI is a software supply chain compliance platform from CRACI Corporation Oy, a Finnish company founded in 2025. It runs as a GitHub Actions runner, so builds stay in GitHub, and generates a software bill of materials from the build itself in CycloneDX or SPDX. Alongside the SBOM it tracks vulnerabilities across dependencies, lets teams assign and follow remediation, and produces the reporting the EU Cyber Resilience Act calls for, including vulnerability disclosure to ENISA. The workspace is organised around builds, security, inventory and compliance, and the vendor says other CI systems are on its roadmap. CRACI is delivered as a service and states ISO/IEC 27001 certification, with EU data residency, SAML and single sign-on on enterprise plans. The company raised 1.4 million euro in pre-seed funding in May 2026 in a round led by Lifeline Ventures, with First Fellow Partners and Wave Ventures.

Best for: Product teams selling into the EU that want Cyber Resilience Act evidence produced by the build, with the SBOM and vulnerability tracking inside the CI pipeline rather than a separate scan

Key Features

SBOM generation from the build, in CycloneDX or SPDX
Runs as a GitHub Actions runner, with builds staying in GitHub
Continuous vulnerability tracking across dependencies
Assignment and remediation tracking for vulnerabilities
Cyber Resilience Act reporting, including vulnerability disclosure for ENISA
Workspace split into builds, security, inventory and compliance
EU data residency, SAML and single sign-on on enterprise plans

Do you work at CRACI? to confirm the details or send us a correction.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent CRACI? Request a correction.

Key facts

Pricing
Pro at 330 euro per month, listed at 30 euro per month until the end of 2026, covering 1 to 20 users, one actively monitored SBOM (further SBOMs at 300 euro per month each) and 10,000 build minutes, then 0.004 euro per minute. Enterprise is annual and priced on request.
Model
Subscription by user band and monitored SBOM, plus metered build minutes
Founded
2025
Cloud
Yes
Self-hosted
No

Where CRACI appears

Guides

Certifications

ISO/IEC 27001 (vendor-stated)