Each role โ Manufacturer, Supplier, Auditor โ has a dedicated, isolated panel with purpose-built workflows for CRA compliance. No cross-role data access. Strict separation of duties. Exactly as CRA governance requires.
The Manufacturer is the administrator of the entire compliance ecosystem. You define what suppliers must prove, you review their submissions, and you decide whether they pass. The platform puts full control in your hands.
All 14 CRA requirements are pre-loaded. You add specific controls under each requirement that suppliers must satisfy. Your framework, your standards.
Create and manage Supplier and Auditor accounts. Plan-based supplier limits enforced automatically. Full lifecycle user management.
Three-level validation workflow. Review each supplier's compliance submissions, view uploaded evidence, and approve or reject with comments.
See every supplier's risk posture across all 14 CRA requirements. Filter by risk level, CRA class, and item type. Act on critical risks immediately.
Export full compliance reports to CSV or Excel. Share with regulators, customers, or internal stakeholders at any time.
Validate Compliance
Risk Status
Suppliers are the backbone of CRA compliance. The Supplier Panel gives them everything they need to register their products, assess risks, and submit compliance evidence โ in a guided, structured workflow.
Register all hardware, software, firmware, and IoT devices with full security property capture โ encryption, secure boot, update mechanisms, logging, and more.
Map all network connections between devices. Record encryption status, protocols, firewall rules, and data classification for every connection.
Register hundreds of devices or connections at once using our pre-formatted Excel manifest. Dropdown validation prevents errors on import.
Upload compliance evidence (PDFs, certificates, test reports) against each CRA control. Track submission status in real time. Resubmit rejected items easily.
Assess risk levels (Negligible to Critical) for each device and connection against each CRA requirement. Risk scores inform the manufacturer's review priority.


The Auditor Panel provides complete read-only visibility across the entire compliance ecosystem. Auditors can investigate, analyse, raise findings, and generate regulatory-grade reports without ever modifying data.
Read-only access to all BOM devices, connections, submissions, evidence files, and risk assessments across all suppliers. Complete transparency.
Automated gap analysis maps every device and connection against every applicable CRA requirement. Missing submissions shown instantly in a visual grid.
Automated scan flags six types of issues: inconsistent decisions, duplicate submissions, approvals without evidence, and stale pending submissions.
Raise Critical Non-Conformities, Minor Non-Conformities, Observations, and Recommendations with full lifecycle management from Open to Closed.
Generate Gap Analysis, Risk Summary, Security Posture, Submission History, and Executive Summary reports โ ready for regulators and management.


Built specifically for CRA compliance. No bloat. No generic GRC features. Every feature serves one purpose โ helping you achieve and prove CRA compliance.
Pre-embedded from day one. No configuration, no mapping, no interpretation required. The law is already built in.
Full Bill of Materials management for devices and network connections with all security properties captured and tracked.
Upload compliance evidence against each CRA control. Track submission status. Archive all evidence with full chain of custody.
Live risk dashboard showing Negligible to Critical risk scores for every device and connection across your supply chain.
Visual grid showing every missing compliance submission across every supplier, device, connection, and requirement.
Automated detection of inconsistencies, duplicates, approvals without evidence, and stale submissions.
Register hundreds of devices or connections at once using downloadable Excel manifests with built-in dropdown validation.
Five report types including Gap Analysis, Risk Summary, Security Posture, and Executive Summary โ ready for regulators.
Every action logged permanently. Timestamped, user-attributed, and non-repudiable. Admissible in regulatory proceedings.
Every client gets their own isolated subdomain โ ibm.cognisec-cra.com. Complete data separation from other clients.
Data never leaves European Union servers. Full GDPR compliance built in. Not a US platform with EU add-ons.
Suppliers receive instant notifications on submission approval or rejection. Manufacturers get alerts on new submissions.
No implementation project. No consulting fees. No 6-month onboarding. Start your 30-day trial and be live today.
Select a plan, enter details and credit card. 30-day trial begins immediately. No charges until trial ends.
Add your CRA requirements and controls. Invite your suppliers and auditors โ they receive login credentials instantly.
Suppliers register devices, map connections, assess risks, and upload compliance evidence for each requirement.
Review submissions, approve or reject, monitor risk dashboards. Your compliance posture is always current and visible.
We are actively seeking motivated sales partners across the United Kingdom and European Union to represent the Cognisec CRA Engine. If you work in cybersecurity, compliance consulting, or IT services โ let's talk.