From Zero to #Compliant
You’re building the future of connected products. We make sure the EU Cyber Resilience Act doesn’t slow you down.
The same obligations as for large enterprises, on the same timeline: reporting obligations from 11 September 2026, full application from 11 December 2027. All deadlines at a glance
Your Stack Already Carries the Raw Material
Repos, dependency manifests, releases, architecture docs: what your development produces anyway is exactly what the EU CRA wants to see. Kunnus gives you the tooling to turn it into audit-ready evidence and to close the gaps that remain. How you work stays the same.
The EU CRA Plans for Small Companies
The regulation includes dedicated relief for micro and small enterprises. We know every one of them and build them into your path from day one. Core obligations like the SBOM, vulnerability handling and the Declaration of Conformity still apply, and with Kunnus you meet them as lean as the EU CRA intends for you.
Simplified technical documentation
A dedicated, simplified form for the technical documentation required by Annex VII.
Art. 33 · EU CRAFine exemption for early warnings
Late early-warning notifications do not lead to fines for micro and small enterprises.
Art. 64 · EU CRADedicated points of contact
Dedicated helpdesks and advisory support aimed at small manufacturers.
Art. 33 · EU CRAPriority access to regulatory sandboxes
Preferential access to test conformity early, with guidance along the way.
Art. 33 · EU CRA
Our Startup Program
Qualifying startups get the full Kunnus platform at significantly reduced rates, so you can focus on your product while staying EU CRA-ready.
Full platform access, cloud-deployed.
You get the same tools that enterprises use, from SBOM management and vulnerability monitoring to conformity documentation and regulatory tracking. Fully cloud-hosted in the EU, nothing to install, up and running in minutes.
Pricing that respects your stage.
We work with each startup individually on a licensing model that fits your current situation. Cost should never be the reason you postpone compliance.
A team that knows startups.
Our team knows the challenges startups face with EU-CRA compliance and helps you set up efficiently and avoid expensive mistakes early. You have one named contact, from the first call onwards.
The startup program is available to companies that meet specific eligibility criteria. Contact our team to learn more about qualification and terms.
Is Your Startup Eligible?
Our program is designed for early-stage companies building products that fall under the EU Cyber Resilience Act. Typical participants include:
- Companies with fewer than 50 employees
- Building connected products, IoT devices, or software with digital elements
- Planning to enter or already active in the EU market
- At an early growth stage
Not sure if you qualify? Reach out. A quick conversation will settle it.

Getting Started Is Simple
Get in touch
Platform demo, Q&A, no commitment. Tell us about your product and we’ll show you exactly how Kunnus can help.
Onboard
Platform setup, team training (~2 hours), and initial SBOM import. You’ll be operational by end of day.
Comply
Capture and classify your products, then build risk analysis and evidence right in the platform, up to the EU Declaration of Conformity.
Monitor
Continuous matching against NVD and OSV, ENISA reporting ready, and technical documentation that stays current.

Meet Us at Bits & Pretzels
Three days of Munich, founding teams, investors, and us right in the middle. Talk to us about what the EU Cyber Resilience Act means for your product.
View detailsReady to Make Compliance Your Competitive Advantage?
Reporting obligations apply from 11 September 2026. The earlier you start, the smoother the path. Let’s talk about how Kunnus can support your startup.
No commitment. Just a conversation about your compliance needs.