Comparison
CRACI vs Medcrypt
Medcrypt helps medical device makers get their cybersecurity submission through FDA review and keep it current. CRACI runs the build, records the SBOM from it, and keeps watching that SBOM for new vulnerabilities after the device ships.
Updated
The short answer
Medcrypt is a medical device cybersecurity company. Its platform, Medcrypt Security Intelligence (MSI), combines software with a team of former FDA reviewers to prepare, audit and maintain a device's cybersecurity submission. Its homepage promise is "Get your cybersecurity submission approved. The first time." Helm, its SBOM and vulnerability management product, is part of MSI and is also sold on its own.
CRACI is a GitHub Actions runner that records the dependencies each job actually fetched and produces the SBOM from that record, with a completeness state. It then re-evaluates monitored SBOMs as advisories appear, and security teams triage findings and route them to the team that owns the fix. CRACI does not prepare or review FDA submissions. For the SBOM and the postmarket vulnerability tracking of software you build, CRACI replaces Helm, starting from the build itself.
At a glance
| Capability | CRACI | Medcrypt |
|---|---|---|
| Produces the SBOM | Recorded during each GitHub Actions job | Ingests SBOMs; a generation tool on request |
| Runs your CI builds | Jobs run on CRACI runners | Its GitHub Action uploads an SBOM file |
| Signal on SBOM completeness | Completeness state per job and cache | Not stated |
| Import of supplier SBOMs | Vendor SBOMs can be added | Upload or create CycloneDX or SPDX |
| Monitoring after release | Monitored SBOMs re-evaluated continuously | Continuous monitoring, email on new vulnerabilities |
| Vulnerability triage and VEX | Triage, team routing and VEX | Rescoring, remediation, CycloneDX VEX export |
| Which releases a vulnerability affects | Every past build and its SBOM, within retention | Checks whether a vulnerability impacts your products |
| Egress policy while the build runs | Validated before the job, fails closed | Does not run your build |
| FDA submission support | Former FDA reviewers, threat modeling, submission audits | |
| Reports for regulators | SBOMs export as CycloneDX or SPDX; no report export | Medcrypt FDA SBOM, VEX and VDR reports |
| CI systems | GitHub Actions today; GitLab CI and Jenkins on the roadmap | SBOM upload by API, GitHub Action or Azure DevOps extension |
| Pricing | Pay per build minute: $0.004 per 2 vCPU minute, metered per second. No monthly fee and no per-SBOM charge. | MSI $35,000 per product line per year, with 15 advisory hours; Helm alone on request (as of October 2026). |
- Included
- Partly
- Not included
What Medcrypt does well
- FDA expertise on staff. MSI's checks, audits and templates are built by a team that, in Medcrypt's words, includes "former FDA reviewers and authors of the guidance itself." The MSI plan includes 15 advisory hours a year with them, and the platform scans submission packages for what a reviewer would flag. For a first 510(k) or PMA submission, that is help CRACI does not offer.
- The whole submission, not just the SBOM. MSI covers threat modeling, cybersecurity risk assessment, document generation (marked beta), responses to deficiency letters, and penetration testing as an add-on through vetted partners.
- Postmarket work after clearance. MSI includes continuous vulnerability monitoring and MedISAO membership, which Medcrypt says brings device-specific vulnerability alerts, a coordinated vulnerability disclosure program and guidance updates. Its platform page puts it plainly: "Section 524B made post-market cybersecurity a legal duty."
- Helm is built for device makers. Helm ranks findings with EPSS, CISA KEV, ExploitDB and Metasploit data, rescores vulnerabilities in bulk to match each device's context, carries remediations across product versions, and uses alias rules to match components to NVD entries. It exports CycloneDX and SPDX SBOMs, VEX and VDR reports, and a Medcrypt FDA SBOM format.
- An established vendor in its niche. Medcrypt was founded in 2016, went through Y Combinator, and reports $36.4M in funding with investors including Johnson & Johnson Innovation, Intuitive Ventures and Dexcom Ventures. It says 140+ medical device manufacturers trust it, including 13 of the top 50.
- Published pricing. MSI costs $35,000 per product line per year with unlimited users, invoiced annually.
Where CRACI is different
It produces the SBOM, from the build
Helm works with SBOMs you give it. You upload or create CycloneDX or SPDX files, or a Helm GitHub Action uploads an SBOM file from your workflow (the docs say it supports CycloneDX JSON today). For teams without an SBOM, the Helm docs point to open-source generators, manual creation, expert services, or a Medcrypt generation tool available on request. So the component list Helm monitors still comes from a scanner or a hand-built file.
CRACI runs the job. You change runs-on to craci, and a package-aware proxy records
traffic to package sources during the build: npm, PyPI, RubyGems, Cargo, Go, Nix, OCI, apt, apk and Git sources,
plus download presets. Dependency evidence travels with CI caches, so a package restored from a cache is still in
the record. Each SBOM states how complete it is, per job and per cache: Complete, Complete with connections,
Incomplete, Unavailable or Not recorded.
Embedded Linux builds
If your device runs a Yocto image, the comparison is direct. The Helm docs show how to turn on Yocto's own SPDX output and upload it.
CRACI runs BitBake on runners of up to 32 vCPUs and 96 GB of RAM. In a
side-by-side build of core-image-sato, CRACI's SBOM had every
component in Yocto's own SPDX output, 88 more such as host packages and GitHub Actions, and a package URL for each
of the 653 Rust crate versions Yocto lists without one.
Postmarket answers from build history
When a new vulnerability lands, the postmarket question is which shipped versions contain it and for how long. CRACI keeps every past build and its SBOM, within retention, and shows which builds contained the vulnerable dependency, direct or transitive, so you know the period you were affected. Its inventory view shows which software versions are deployed to which products. Policy gates can stop a later build that still contains a specific CVE.
Control over what the build can reach
Because CRACI is the runner, it enforces a network egress policy: default deny or default allow, with 24 built-in software-source presets and typed custom sources, validated before the job starts and failing closed. It alerts on policy violations. Medcrypt does not run your build, so this is outside its scope.
Under FDA section 524B
Under section 524B, a cyber device submission must include an SBOM "including commercial, open-source, and off-the-shelf software components" and a plan to monitor and address postmarket vulnerabilities. Both products touch these requirements in different ways.
Medcrypt works on the submission itself: the threat model, the risk assessment, the documents, the audit against what FDA reviewers flag, and the response if FDA sends a deficiency letter. Its pricing page notes, "FDA is what the platform covers today."
CRACI supplies evidence that comes out of the build: an SBOM of what the build actually used, exported as CycloneDX or SPDX, and continuous monitoring of that SBOM after release, with triage and routing to the team that owns the fix. CRACI does not write, review or submit FDA documentation, and it does not make a device compliant. The plan and the submission remain the manufacturer's work. For how this fits a product security team, see what a PSIRT does and CRACI for PSIRT teams.
When to choose which
- You are preparing a first submission, or answering a deficiency letter. Medcrypt. Former FDA reviewers, submission audits and threat modeling are what it is built for, and CRACI does none of them.
- You need SBOM and vulnerability management for software you build in GitHub Actions. CRACI. It produces the SBOM in each build and monitors it, so there is no separate generator to run and no upload step to maintain.
- You need encryption, key management or device identity in the field. Medcrypt's Guardian covers device-side security. CRACI works on the build, not on the device.
- Your builds run in GitLab CI or Jenkins. Helm offers an API, a GitHub Action and an Azure DevOps extension for uploading SBOMs. CRACI supports GitHub Actions today, with GitLab CI and Jenkins on the roadmap.
Replacing Helm with CRACI
For device software built in GitHub Actions, CRACI covers what Helm is there to do: it produces the SBOM in each build, re-evaluates monitored SBOMs as new vulnerabilities are published, aggregates findings across builds and repositories, supports VEX, and lets security teams triage findings and route each one to the team that owns the fix. You can add vendor SBOMs too, so bought-in components are monitored alongside your own builds.
Be clear about what you give up. Helm ranks findings with exploit intelligence such as EPSS and CISA KEV, offers AI guidance on mitigations, matches components with alias rules, tracks end of support data, and exports VDR reports and the Medcrypt FDA SBOM format. And none of MSI's submission work, advisory hours or MedISAO membership has a CRACI equivalent. If your main need is getting a submission through FDA review, Medcrypt is built for that.
Comparing more tools for product security teams? See the PSIRT tools comparison.
CRACI supports GitHub Actions today. GitLab CI, Jenkins and other CI systems are on the roadmap. Read more about build-time SBOM generation and CRACI for PSIRT teams.
Bring a device build to the demo
Book a demo and we will run one of your GitHub Actions builds on CRACI and walk through the SBOM it records.
Book a demo