Know what applies. Do what's due.
Mudi is the regulatory radar for teams shipping software into the EU. Source-linked CRA applicability by how you deliver the product — then a living checklist before reporting clocks start.
Informational only — not legal advice. Verify against the official texts or qualified counsel.
Field log
We herd EU compliance.
We bark before deadlines bite.
Reporting obligations begin · 11 Sept 2026
CRA Art. 14 windows: 24h early warning · 72h notification · 14d final report
The blindside
CRA treats many vendors like manufacturers.
If you ship software into the EU, the Cyber Resilience Act may apply even if you are a five-person team in Austin or London. Most tools hand you a static quiz, a PDF that goes stale, or a twenty-thousand-dollar GRC suite built for SOC 2.
Mudi is narrower and sharper: supplier-side EU product law for software vendors, starting with CRA applicability by delivery model — then the operational path to September 2026 reporting readiness.
How it works
From delivery model to living obligations.
Start with a free CRA check. Keep the verdict current in the paid workspace when you need timers, templates, and a register.
- 01
Map how you deliver
Installable product, agent, device, pure SaaS, or hybrid. Delivery model is the first routing question — not a filter on who we serve.
- 02
Get a source-linked verdict
Likely in scope, likely out, or unclear — depends on X. Every material claim ties back to the regulation or guidance, not marketing vibes.
- 03
Work the deadlines
Living obligations checklist, vuln-process timers (24h / 72h / 14d / 1 month), saved products, and a register you can keep current as guidance moves.
Official timeline
Know what is due, and when.
Commission dates for CRA reporting and full application, with live day counts so the clock stays honest as guidance moves.
Reporting begins
11 Sept 2026
40 days remaining
Actively exploited vulnerabilities and severe incidents — 24h / 72h / 14d / 1 month windows.
Main obligations
11 Dec 2027
496 days remaining
Full product cybersecurity obligations across design, development, and maintenance.
Why Mudi
Not another stale CRA checker.
Software delivery-model routing
Owns the hard CRA/SaaS boundary cases: remote data processing, endpoint agents, offline-complete products with optional cloud, commercial open source.
Workspace after the quiz
Free checkers end at a blog post. Mudi continues into timers, templates, and a monitored update loop so the answer does not rot.
Built for technical buyers
Founders and eng leads at 1–20 person vendors — plain language, shareable verdicts, no enterprise GRC theater.
CRA
FirstApplicability + reporting ops
NIS2
NextCustomer questionnaire pain
DORA / AI Act
LaterThin applicability checks
Pricing
Priced for small product teams, not GRC seats.
Self-serve pricing for small product teams. Not seat-based GRC licensing.
Free
$0
CRA applicability wizard
- No login required
- Delivery-model routing
- Shareable source-linked verdict
Workspace
$49/mo
Or $490/yr
- Obligations checklist + deadline timers
- Vuln-process templates (24h / 72h / 14d / 1 month)
- Saved products + documentation register
- Monitored regulatory update loop
FAQ
Straight answers.
Is this legal advice?
No. Mudi is source-linked operational guidance for product teams. Use counsel or notified bodies for high-stakes classification and conformity assessment.
We’re pure SaaS — does CRA apply?
Often pure browser SaaS is out. Your agent, desktop build, or remote data processing component may be in. The wizard routes by delivery model so you get a clean out when you are out — and NIS2 customer demands still matter either way.
How is this different from Vanta or an SBOM tool?
Trust platforms cover org-level SOC 2 style programs. SBOM tools go deep on components. Mudi answers whether supplier-side EU product rules apply to what you ship, and what is due when — starting with CRA.
What does the free wizard include?
No-login CRA applicability path with a shareable, source-linked verdict. Paid workspace adds saved products, deadline timers, vulnerability-handling templates, and the regulatory update loop.
Find out if CRA applies to your product.
Minutes, not a sales call. Share the verdict with your co-founder or counsel, then keep the obligations current in the workspace.
Informational only — not legal advice. Verify against the official texts or qualified counsel.