Since 11 September 2026, makers of apps sold in the EU must report actively exploited vulnerabilities to ENISA within 72 hours. Full requirements, including technical documentation and CE marking, follow in December 2027. Check in two minutes whether your app is in scope.
Swift Package Manager and CocoaPods dependencies turned into a CycloneDX SBOM on every build, from Xcode Cloud, GitHub Actions or your Mac.
Daily checks against OSV, CISA's exploited list, ENISA's EU vulnerability database and EPSS. You hear about actively exploited issues, not every CVE.
Records when you became aware, runs the 24h, 72h and 14-day clocks, and pre-fills the text for ENISA's Single Reporting Platform.
Hosted security.txt, disclosure policy and report inbox. Technical-file skeleton, EU declaration of conformity and support-period statement.
The scanner is open source. Try it on your project today:
pipx install cra-scan cra-scan scan path/to/YourApp # writes sbom.cdx.json and checks every pinned package