3 September 2026
CRA reporting duty starts 11 September: free readiness check shows embedded teams where they stand, within 24 hours
Ostfildern, Germany, 3 September 2026. From 11 September, the EU Cyber Resilience Act (Regulation (EU) 2024/2847, Article 14) requires manufacturers to report actively exploited vulnerabilities within 24 hours, to the CSIRT designated as coordinator and to ENISA. The clock starts the moment the manufacturer becomes aware. Many embedded projects lack what it takes to meet that deadline: a current inventory of the software components they ship. If you do not know what is inside your product, you cannot tell whether an actively exploited flaw affects you.
Innomatica GmbH, based in Ostfildern near Stuttgart, has released the CRA Readiness Check for exactly that question — free of charge, once per company. A team requests a one-time code at embtrace.dev/en/check, runs a single command in the project folder and receives a PDF report by email: traffic-light status against EU 2024/2847, the component inventory, known vulnerabilities with a concrete update plan, and licence risks. There is a reason it takes up to 24 hours: every report is reviewed by hand before it goes out.
The collector is open source (MIT licence), runs inside the customer's project folder and
transmits metadata only to servers in Germany — essentially which components are
present in which versions; no source code, no file paths. What leaves the building can be
checked byte for byte beforehand with the
--dry-run
option. On the server, components are matched against public vulnerability databases; the
analysis rests on a deterministic parser pipeline covering eleven build systems. On one real
production project it inventoried 1,089 components, each with supplier, version, licence and
package identifier.
“You cannot hold a 24-hour deadline without a current component inventory,” says Ivan Maradzhiyski, founder of Innomatica GmbH. “The check is deliberately a starting point, not a certificate: it shows what is inside a product and where the known gaps are. It claims nothing beyond that.”
The free check reports CRA status; embtrace generates SBOMs either to CRA requirements or to BSI TR-03183-2 (v2.1.0), the technical guideline of the German Federal Office for Information Security — for manufacturers selling to public authorities or critical infrastructure, that guideline is the yardstick that counts. The check is aimed at smaller embedded teams and at importers who take on the CRA's manufacturer obligations for products from outside the EU. Available at: embtrace.dev/en/check
About Innomatica: Innomatica GmbH (Ostfildern, Germany) builds self-hosted tools for release management and CRA compliance in embedded software development.
Press contact: Ivan Maradzhiyski · [email protected] · embtrace.dev