CRA-first · EU product law for software vendors

Know what applies. Do what's due.

Mudi is the regulatory radar for teams shipping software into the EU. Source-linked CRA applicability by how you deliver the product — then a living checklist before reporting clocks start.

Informational only — not legal advice. Verify against the official texts or qualified counsel.

Field log

We herd EU compliance.
We bark before deadlines bite.

In scope
Out of scope
Depends

Reporting obligations begin · 11 Sept 2026

CRA Art. 14 windows: 24h early warning · 72h notification · 14d final report

40 days left
Art. 14: early warning within 24 hours of awareness…

The blindside

CRA treats many vendors like manufacturers.

If you ship software into the EU, the Cyber Resilience Act may apply even if you are a five-person team in Austin or London. Most tools hand you a static quiz, a PDF that goes stale, or a twenty-thousand-dollar GRC suite built for SOC 2.

Mudi is narrower and sharper: supplier-side EU product law for software vendors, starting with CRA applicability by delivery model — then the operational path to September 2026 reporting readiness.

How it works

From delivery model to living obligations.

Start with a free CRA check. Keep the verdict current in the paid workspace when you need timers, templates, and a register.

  1. 01

    Map how you deliver

    Installable product, agent, device, pure SaaS, or hybrid. Delivery model is the first routing question — not a filter on who we serve.

  2. 02

    Get a source-linked verdict

    Likely in scope, likely out, or unclear — depends on X. Every material claim ties back to the regulation or guidance, not marketing vibes.

  3. 03

    Work the deadlines

    Living obligations checklist, vuln-process timers (24h / 72h / 14d / 1 month), saved products, and a register you can keep current as guidance moves.

Official timeline

Know what is due, and when.

Commission dates for CRA reporting and full application, with live day counts so the clock stays honest as guidance moves.

Reporting begins

11 Sept 2026

40 days remaining

Actively exploited vulnerabilities and severe incidents — 24h / 72h / 14d / 1 month windows.

Main obligations

11 Dec 2027

496 days remaining

Full product cybersecurity obligations across design, development, and maintenance.

Why Mudi

Not another stale CRA checker.

Software delivery-model routing

Owns the hard CRA/SaaS boundary cases: remote data processing, endpoint agents, offline-complete products with optional cloud, commercial open source.

Workspace after the quiz

Free checkers end at a blog post. Mudi continues into timers, templates, and a monitored update loop so the answer does not rot.

Built for technical buyers

Founders and eng leads at 1–20 person vendors — plain language, shareable verdicts, no enterprise GRC theater.

CRA

First

Applicability + reporting ops

NIS2

Next

Customer questionnaire pain

DORA / AI Act

Later

Thin applicability checks

Pricing

Priced for small product teams, not GRC seats.

Self-serve pricing for small product teams. Not seat-based GRC licensing.

Free

$0

CRA applicability wizard

  • No login required
  • Delivery-model routing
  • Shareable source-linked verdict
Start free check

Workspace

$49/mo

Or $490/yr

  • Obligations checklist + deadline timers
  • Vuln-process templates (24h / 72h / 14d / 1 month)
  • Saved products + documentation register
  • Monitored regulatory update loop
Open workspace

FAQ

Straight answers.

Is this legal advice?

No. Mudi is source-linked operational guidance for product teams. Use counsel or notified bodies for high-stakes classification and conformity assessment.

We’re pure SaaS — does CRA apply?

Often pure browser SaaS is out. Your agent, desktop build, or remote data processing component may be in. The wizard routes by delivery model so you get a clean out when you are out — and NIS2 customer demands still matter either way.

How is this different from Vanta or an SBOM tool?

Trust platforms cover org-level SOC 2 style programs. SBOM tools go deep on components. Mudi answers whether supplier-side EU product rules apply to what you ship, and what is due when — starting with CRA.

What does the free wizard include?

No-login CRA applicability path with a shareable, source-linked verdict. Paid workspace adds saved products, deadline timers, vulnerability-handling templates, and the regulatory update loop.

Find out if CRA applies to your product.

Minutes, not a sales call. Share the verdict with your co-founder or counsel, then keep the obligations current in the workspace.

Informational only — not legal advice. Verify against the official texts or qualified counsel.