- Audience: manufacturers of products with digital elements (Article 2(1) and the definition in Article 3, point 13).
- Angle: the CRA makes support a multi-year obligation. Codekeeper keeps the code, build steps, SBOM and documentation recoverable for that period, and proves it builds.
- Headline: the support period in five words, then the proof.
- Hero mock: one product as an application, with the deposit contents the CRA story needs. Example values only.
Products you support for years. Code that still builds.
The Cyber Resilience Act asks manufacturers to handle vulnerabilities for the whole support period and to keep technical documentation available for years. Codekeeper keeps your code, build steps, SBOM and documentation recoverable, and proves it builds.
- Trusted by 3,500+ teams
- ISO/IEC 27001:2022 certified
- A fresh SBOM with every rebuild
Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors
- Dates. Entry into force, 10 December 2024: EUR-Lex document metadata (first date of entry into force 2024-12-10) and the European Commission's CRA page. Reporting obligations from 11 September 2026 and main obligations from 11 December 2027: the Commission's CRA page ("Last update: 7 September 2026"), which says "The main obligations introduced by the Act will apply from 11 December 2027, with reporting obligations to apply as of 11 September 2026." Article 71 itself could not be fetched (see the hero note), so these are stated as dates, not quoted. Legal should confirm them against Article 71 before launch. Production's 11 June 2026 date for conformity assessment bodies is left out for the same reason.
- Quotes. Article 13(8), first and fifth subparagraphs; Article 13(13); Article 13(23). All verbatim from the EUR-Lex consolidated text. The ellipsis in the second card replaces "Without prejudice to the second subparagraph,".
- Left out: production's fines ("€15 million or 2.5%"). They sit in Article 64, which we could not read. Also left out: "a market worth €3 trillion", "cyberattack costs escalate 15% annually" (no source), and "banned from sale across all 27 member states" (fear line).
What the CRA asks
Support becomes a commitment measured in years.
Reporting obligations already apply. The main obligations follow in December 2027, and a support period of at least five years means the code you ship then has to stay buildable well into the 2030s.
“Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.”
“… the support period shall be at least five years. Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.”
“Manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.”
“A manufacturer that ceases its operations and, as a result, is not able to comply with this Regulation shall inform, before the cessation of operations takes effect, the relevant market surveillance authorities as well as, by any means available and to the extent possible, the users of the relevant products with digital elements placed on the market, of the impending cessation of operations.”
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
The shift
Keeping the code is the start. Keeping it buildable is the goal.
Years into a support period, a security fix depends on code, build steps and dependencies from years before. Teams change. Tools move on.
How support often works today
- Build knowledge spread across repositories, wikis and people
- An SBOM generated once, at release
- Older versions that haven't been rebuilt since they shipped
- Customers asking what happens if you stop
With Codekeeper
- Code, build scripts and documentation in one deposit, synced daily
- A fresh SBOM and build steps with every rebuild
- A dated Recoverability Certificate for the version you ship
- Release or recovery terms your customers can rely on
How it works
Set it up once. Prove it every quarter.
Each product you support is an application in one Codekeeper account.
Add each product
Software, SaaS or AI. Prices are per application, so you protect the products that carry support commitments.
Connect your repositories
Deposits sync daily through 50+ integrations. Add the technical documentation alongside the code.
Rebuild to prove it
Agentic Verification rebuilds the deposit in a sealed sandbox and regenerates the SBOM. Four rebuilds a year are included.
Agree what customers get
With Escrow, the deposit is released to them under agreed conditions. With Resilience, we recover it for them.
- Confirm before launch: which SBOM format the product exports (for example SPDX or CycloneDX) and whether it covers what Annex I, Part II, point (1) asks for. Until then the page says "an SBOM" and doesn't claim a format or CRA conformity.
The proof
Proof it builds. In hours, not weeks.
Press run. AI agents work out how the deposit is built and rebuild it in a sealed sandbox. Anything missing is flagged. A successful run issues a dated Recoverability Certificate.
With every successful rebuild
An SBOM that matches what you ship.
The SBOM is regenerated from the rebuild itself, so the inventory reflects the version in the deposit, not the one you documented last year.
- Build steps, SBOM, Exit workbook and a deployable copy
- Four rebuilds a year included, on supported technology stacks; 12 a year for $299 a month more
- Runs on Codekeeper's own models, so code stays in our environment
- Missing items are flagged, and you add them to the deposit
| Component | Version | Type | Licence |
|---|---|---|---|
| openssl | 3.0.13 | Library | Apache-2.0 |
| mbedtls | 3.6.0 | Library | Apache-2.0 |
| lwip | 2.2.0 | Library | BSD-3-Clause |
| freertos-kernel | 11.1.0 | Library | MIT |
| gw-protocol | 2.4.1 | Private package | Proprietary |
| sensor-hal | 5.0.3 | Licensed component | Commercial |
- Confirm before launch: how long Codekeeper keeps earlier deposit versions. Article 13(13) asks for at least ten years, or the support period if longer. Production's "Technical file custody" page promises "versioned custody for the mandatory ten-year retention period"; that isn't in the confirmed facts, so this page doesn't claim a retention period.
- The three production pages linked below carry errors to fix (see the report): unverified fines, and Article 31 cited as the retention rule (it's Article 13(13)).
Evidence map
Evidence for each obligation.
What you can put in front of an assessor, a market surveillance authority or an enterprise customer, and which protection it comes with.
| CRA | Codekeeper evidence |
|---|---|
| Art. 13(8) Vulnerabilities handled for the support period | To ship a fix, the code has to build. Each rebuild proves it does, from the deposit alone. Recoverability CertificateRun reportBuild stepsEscrow Pro · Resilience Pro · Continuity |
| Art. 13(13) and 31(2) Technical documentation, kept and kept current | Documentation deposited alongside the code and synced daily, with an automated check of what's there. Vault reportSoftware Resilience CertificateEvery protection |
| Annex I, Part II, point (1) Software bill of materials | A fresh SBOM with every rebuild, so the inventory matches the version in the deposit. SBOMEscrow Pro · Resilience Pro · Continuity |
| Art. 13(23) If you cease operations | Your customers keep a route back: the deposit released to them under Escrow, or recovered for them by us under Resilience. Escrow AgreementResilience ArrangementEscrow · Resilience · Continuity |
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
Choose the protection
If you can't support it, who brings it back?
Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on.
Escrow
Deposit→Released to the customer→They recover
When the agreed conditions are met, the deposit is released to your customer. Escrow Pro adds proof it builds. Explore Escrow
From $199
Resilience
Deposit→Comes to us→We recover
The deposit comes to Codekeeper, and we run the recovery for your customers. Explore Resilience
From $399
Continuity
Live service kept on+We recover
Everything in Resilience Pro, plus the live environment kept paid and switched on for an agreed period while we recover. Explore Continuity
From $1,449
Prices per application per month. See all prices
Who it's for
For the people who make products, and the people who rely on them.
Connected product makers
Products with years of support ahead. Keep the code and its build steps in custody, and rebuilt where the stack is supported. Escrow Pro
Software vendors
Software sold in the EU with a support period to honour. Show buyers it builds without your team. Software
Their enterprise customers
Relying on a product for years? Ask for release terms and a Recoverability Certificate. Escrow Pro
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
Questions
Before you plan your support period.
Who does the CRA apply to?
Article 2(1): it “applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.” The obligations this page covers, such as the support period and the technical documentation, sit with the manufacturer under Article 13.
When do the obligations apply?
The CRA entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026, and the main obligations from 11 December 2027.
Will Codekeeper make our product CRA compliant?
No product can do that on its own. Codekeeper keeps the material you need to support the product recoverable, and gives you evidence: certificates, run reports, build steps and SBOMs. Whether it meets a specific requirement is for you and your assessor to decide.
What should go into the deposit?
Whatever it takes to rebuild the product: source code, build scripts, configuration and the technical documentation. The automated check confirms what's there, and a rebuild flags anything missing.
Is the SBOM in the format the CRA asks for?
Every successful rebuild produces an SBOM of what was built. The Commission may set the format and elements of the SBOM by implementing act (Article 13(24)), so check yours against the current rules with your assessor. The sample evidence pack includes an SBOM excerpt.
What happens for our customers if we stop trading?
Article 13(23) asks a manufacturer that ceases operations to inform market surveillance authorities and users. With Escrow, the deposit is released to your customers under the agreed conditions. With Resilience, Codekeeper runs the recovery for them.
Is our code safe with you?
Codekeeper is ISO/IEC 27001:2022 certified. Deposits are encrypted at rest, and rebuilds run on our own models in a sealed sandbox, so code stays in our environment. See the Trust Center.
Plan for the whole support period. Start with proof it builds.
We'll look at the products you support and show you what a deposit, a rebuild and an SBOM look like for one of them.