CVD Portal

CRA compliance platform with a free whitelabel vulnerability disclosure portal for EU manufacturers

CompanyCyber Resilience Act ComplianceCloud

Pricing: Free at 0 euros per month with no card required. Reporting at 99 euros per month billed annually. Compliance at 299 euros per month billed annually. Enterprise at 1,499 euros per month billed annually. Paid tiers below Enterprise offer a 14-day trial with no card.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings

What is CVD Portal?

CVD Portal is a compliance platform for manufacturers placing products with digital elements on the EU market under the Cyber Resilience Act, Regulation (EU) 2024/2847. It covers product classification under Annexes III and IV, Annex I essential requirements, Annex VII technical documentation, the EU declaration of conformity, vulnerability handling and Article 14 authority reporting. The free tier provides a branded HTTPS intake portal for the Article 13 single point of contact, with submission tracking, 48-hour acknowledgement tracking, automatic disclosure policy publication and PGP-encrypted researcher communication. Paid tiers add the Article 14 notification workflow on the 24-hour, 72-hour and 14-day deadlines, CSAF 2.0 advisory export, SBOM and hardware component registries, and CRA self-assessment tooling including STRIDE threat modelling. It is operated by Porta Regulus B.V. in the Netherlands, runs on Hetzner infrastructure in Germany with no transfers outside the EU or EEA, and is listed in the CIRCL-operated GCVE registry as numbering authority 126.

Best for: EU manufacturers, importers and distributors that need an Article 13 disclosure contact and Article 14 reporting workflow in place before the 11 September 2026 deadline.
Pros
  • The free tier is genuinely free: the pricing page states 0 euros with no credit card, covering the public submission portal, disclosure policy publication and acknowledgement tracking
  • Independently recognised in the CIRCL-operated GCVE registry, which lists numbering authority 126 as cvdportal pointing at the vendor site
  • Evidence of a shipping product rather than a landing page: the published OpenAPI specification documents five endpoints, and a live call to the products endpoint returns a proper authentication error
  • EU data residency is specific and checkable, naming Hetzner Nuremberg for compute and database, Falkenstein for object storage, and listing every subprocessor
  • The CRA references are accurate, including the Article 13 single point of contact, the Article 14 deadlines, the 11 September 2026 reporting date and the use of Annexes I, III, IV and VII
  • Publishes original research with a disclosed methodology, scanning 342 EU manufacturers and reporting an undetermined bucket rather than counting blocked responses as absences
  • Practises what it sells: the vendor publishes a valid RFC 9116 security.txt with an unexpired expiry date
Things to check
  • Article 14 output is described as filing packages prepared for manual submission, so filing to ENISA and national CSIRTs is not fully automated
  • API access, custom domain portal and SSO or SAML sit behind the Enterprise tier at 1,499 euros per month
  • The operator states it is not a notified body and cannot perform third-party conformity assessment, so products needing a notified body route are only partly served
  • The only security credential claimed is CSA STAR Level 1, a self-assessment that could not be located in the CSA registry; SOC 2 Type 1 is recorded as in progress and there is no ISO 27001
  • Very new: the domain was created in March 2026, and no customer references or independent product reviews could be found
  • The imprint gives an Amsterdam address while the business register and EU VAT records show Hoofddorp

Reported in public reviews and vendor documentation. See sources below.

Key Features

Whitelabel HTTPS vulnerability intake portal for the Article 13 single point of contact
48-hour acknowledgement tracking and submission tracking with IDs
Automatic coordinated vulnerability disclosure policy publication
PGP-encrypted researcher submissions with a compliance audit trail
Article 14 notification workflow on the 24-hour, 72-hour and 14-day deadlines
Filing packages prepared for submission to ENISA and national CSIRTs
CSAF 2.0 advisory export
CVSS severity scoring and ENISA-aligned triage
SBOM registry and hardware component registry
CRA product classifier for Annex III and Annex IV classification
Annex I risk assessment with STRIDE threat modelling and a 21-requirement self-assessment checklist
Annex VII technical documentation templates and EU declaration of conformity draft
Conformity route selection and CE marking guidance
REST API with Bearer key authentication, webhooks, SSO and SAML, and a custom domain portal on the Enterprise tier
EU data residency on Hetzner with a published subprocessor list

Do you work at CVD Portal? to confirm the details or send us a correction.

Quick Info
PricingFree at 0 euros per month with no card required. Reporting at 99 euros per month billed annually. Compliance at 299 euros per month billed annually. Enterprise at 1,499 euros per month billed annually. Paid tiers below Enterprise offer a 14-day trial with no card.
ModelFreemium subscription with a permanent free tier and three paid tiers
Founded2026
CloudYes
Self-HostedNo

Last updated: Aug 24, 2026