CRACI

Securing your supply chain shouldn't cost more than a breach.

Choose the plan that's right for you

Pro

€330 /mo
€30 /mo Until end of 2026

For growing teams and businesses

  • 1–20 users
  • 1 actively monitored SBOM +€300/mo per additional SBOM
  • 10,000 build minutes +€0.004 per minute (2 vCPU)
  • Standard support
Talk to founders

Enterprise

Custom

For large organizations with specific needs

  • 20+ users
  • Annual contract
  • EU data residency
  • Custom data retention
  • SAML & SSO
  • ISO 27001 & SOC 2
  • Priority support
  • Influence the product roadmap
Talk to founders

Build your plan

Tell us about your usage and we'll estimate your monthly cost.

151050100250
10k20k50k100k500k1M

Frequently Asked Questions

Everything you need to know about our product and services

Who is CRACI built for?

Any company that builds or ships software — from startups and SaaS providers to enterprises, agencies, and hardware makers with embedded code.

If your team develops products with digital elements for the EU market, CRACI helps you stay compliant with the Cyber Resilience Act without slowing down development.

What is an SBOM?

An SBOM (Software Bill of Materials) is a complete inventory of every component your software is built from. CRACI generates a provably complete SBOM — including all transitive dependencies — directly from the CI runner, so you know the version you ship is the actual version described by the SBOM. CRACI supports SPDX, CycloneDX, and other industry-standard formats.

How are SBOMs per month calculated?

These are actively monitored SBOMs — CRACI continuously checks each one against the vulnerability database. You can archive SBOMs so they no longer count against your monthly quota.

CRACI also reports findings to ENISA on your behalf if you have enabled the compliance solution.

How does CRACI fit into my CI/CD?

CRACI provides its own build runner — SBOM generation has to happen inside CRACI's runner to be accurate and audit-ready, so we can't run on third-party runners. But CRACI integrates natively with your existing platforms: on GitHub, for example, CRACI acts as the runner while your runs still show up in the GitHub UI, and the same works with GitLab, Jenkins, and CircleCI.

What formats can compliance reports be exported in?

Compliance reports can be exported as PDF, HTML, CSV, Excel, or JSON.

How much do build minutes cost?

Build minutes are billed at €0.002 per vCPU-minute. A 2-vCPU Linux x86 runner costs €0.004 per minute — roughly half the industry standard. Major CI providers typically charge around €0.005–0.008 per minute for a comparable Linux x86 runner (GitHub Actions, for example, is $0.006 per minute for a standard 2-core Linux runner).

What does Enterprise pricing look like?

Enterprise plans are custom — reach out to talk to the founders directly.

Startup program

CRACI for Startups program is designed for VC-backed startups looking to secure their CI.

Apply by filling out the form, and we'll follow up if we need any additional details.

To be eligible, your startup must meet all of the following criteria:

  • Backed by a VC
  • Less than $5M in funding
  • Less than $5M in ARR
  • Less than 3 years old

If eligible, we will apply free credits to your CRACI account.

Apply today

By filling out the form you agree to our privacy policy.