NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page looks like this. Production's CRA page opens with "Europe will no longer tolerate sloppy cybersecurity" and "If you can't guarantee your products will stay secure … you won't be allowed to sell them". That's a fear line built on an absolute. It also sells escrow as if it delivers CE marking, and its "Compliance outcome" column carries EU AI Act copy ("AI operations stay documented", "Article 11 documentation") that has nothing to do with the CRA. All of that is gone.
  • Audience: manufacturers of products with digital elements (Article 2(1) and the definition in Article 3, point 13).
  • Angle: the CRA makes support a multi-year obligation. Codekeeper keeps the code, build steps, SBOM and documentation recoverable for that period, and proves it builds.
  • Headline: the support period in five words, then the proof.
  • Hero mock: one product as an application, with the deposit contents the CRA story needs. Example values only.
Regulatory text was checked on EUR-Lex on 7 Oct 2026 in the consolidated text of Regulation (EU) 2024/2847 (CELEX 02024R2847-20241120). The fetch tool cuts that page off at Article 59, so Article 64 (penalties), Article 71 (dates) and the Annexes could not be read. See the notes on each section. Legal should confirm every quote against the Official Journal text before launch.
CRA · Regulation (EU) 2024/2847

Products you support for years. Code that still builds.

The Cyber Resilience Act asks manufacturers to handle vulnerabilities for the whole support period and to keep technical documentation available for years. Codekeeper keeps your code, build steps, SBOM and documentation recoverable, and proves it builds.

  • Trusted by 3,500+ teams
  • ISO/IEC 27001:2022 certified
  • A fresh SBOM with every rebuild
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 1, the exposure: dates first, then the obligations in the Regulation's own words.
  • Dates. Entry into force, 10 December 2024: EUR-Lex document metadata (first date of entry into force 2024-12-10) and the European Commission's CRA page. Reporting obligations from 11 September 2026 and main obligations from 11 December 2027: the Commission's CRA page ("Last update: 7 September 2026"), which says "The main obligations introduced by the Act will apply from 11 December 2027, with reporting obligations to apply as of 11 September 2026." Article 71 itself could not be fetched (see the hero note), so these are stated as dates, not quoted. Legal should confirm them against Article 71 before launch. Production's 11 June 2026 date for conformity assessment bodies is left out for the same reason.
  • Quotes. Article 13(8), first and fifth subparagraphs; Article 13(13); Article 13(23). All verbatim from the EUR-Lex consolidated text. The ellipsis in the second card replaces "Without prejudice to the second subparagraph,".
  • Left out: production's fines ("€15 million or 2.5%"). They sit in Article 64, which we could not read. Also left out: "a market worth €3 trillion", "cyberattack costs escalate 15% annually" (no source), and "banned from sale across all 27 member states" (fear line).
Sources: eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02024R2847-20241120; eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32024R2847 (metadata); digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act.

What the CRA asks

Support becomes a commitment measured in years.

Reporting obligations already apply. The main obligations follow in December 2027, and a support period of at least five years means the code you ship then has to stay buildable well into the 2030s.

10 Dec 2024the CRA entered into forceEUR-Lex · European Commission
11 Sep 2026reporting obligations apply, so they are already in effectEuropean Commission
11 Dec 2027the main obligations applyEuropean Commission
EUFor the support period
“Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.”
Regulation (EU) 2024/2847, Article 13(8)
EUAt least five years
“… the support period shall be at least five years. Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.”
Regulation (EU) 2024/2847, Article 13(8), third subparagraph
EUTechnical documentation
“Manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.”
Regulation (EU) 2024/2847, Article 13(13)
EUIf a manufacturer stops
“A manufacturer that ceases its operations and, as a result, is not able to comply with this Regulation shall inform, before the cessation of operations takes effect, the relevant market surveillance authorities as well as, by any means available and to the extent possible, the users of the relevant products with digital elements placed on the market, of the impending cessation of operations.”
Regulation (EU) 2024/2847, Article 13(23)

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

Step 2, the shift, for a manufacturer. A fix during year five depends on the code, the build steps and the dependencies from year one. The left column names the usual gaps without blame; the right column uses only confirmed facts: daily sync, automated check, rebuilds with SBOM and build steps, the Recoverability Certificate, and release or recovery terms.

The shift

Keeping the code is the start. Keeping it buildable is the goal.

Years into a support period, a security fix depends on code, build steps and dependencies from years before. Teams change. Tools move on.

How support often works today

  • Build knowledge spread across repositories, wikis and people
  • An SBOM generated once, at release
  • Older versions that haven't been rebuilt since they shipped
  • Customers asking what happens if you stop

With Codekeeper

  • Code, build scripts and documentation in one deposit, synced daily
  • A fresh SBOM and build steps with every rebuild
  • A dated Recoverability Certificate for the version you ship
  • Release or recovery terms your customers can rely on
Step 3, the model, from the manufacturer's side. The manufacturer is the depositor. Each product is an application; the protection decides what customers get. The integrations figure (50+, synced daily) and four rebuilds a year are confirmed facts. Step 4 is where the CRA's cessation clause meets Escrow and Resilience.

How it works

Set it up once. Prove it every quarter.

Each product you support is an application in one Codekeeper account.

1

Add each product

Software, SaaS or AI. Prices are per application, so you protect the products that carry support commitments.

2

Connect your repositories

Deposits sync daily through 50+ integrations. Add the technical documentation alongside the code.

3

Rebuild to prove it

Agentic Verification rebuilds the deposit in a sealed sandbox and regenerates the SBOM. Four rebuilds a year are included.

4

Agree what customers get

With Escrow, the deposit is released to them under agreed conditions. With Resilience, we recover it for them.

Step 4, the proof: show the SBOM, because CRA readers will look for it. The existing Agentic Verification film (59 s) explains the rebuild faster than copy can. The SBOM screen is an example in the same format as the Agentic Verification page; open-source names, versions and licences are real, the rest is fictional. Rebuilds run on supported technology stacks, which the list says.
  • Confirm before launch: which SBOM format the product exports (for example SPDX or CycloneDX) and whether it covers what Annex I, Part II, point (1) asks for. Until then the page says "an SBOM" and doesn't claim a format or CRA conformity.

The proof

Proof it builds. In hours, not weeks.

Press run. AI agents work out how the deposit is built and rebuild it in a sealed sandbox. Anything missing is flagged. A successful run issues a dated Recoverability Certificate.

With every successful rebuild

An SBOM that matches what you ship.

The SBOM is regenerated from the rebuild itself, so the inventory reflects the version in the deposit, not the one you documented last year.

  • Build steps, SBOM, Exit workbook and a deployable copy
  • Four rebuilds a year included, on supported technology stacks; 12 a year for $299 a month more
  • Runs on Codekeeper's own models, so code stays in our environment
  • Missing items are flagged, and you add them to the deposit
Step 4 continued: which document supports which provision. Row labels paraphrase the provisions; they aren't quotes. Article 31(2) (technical documentation "continuously updated, where appropriate, at least during the support period") and Article 13(24) (which refers to "the software bill of materials referred to in Part II, point (1), of Annex I") were checked on EUR-Lex. Annex I and Annex VII themselves could not be read, so the page doesn't describe what the SBOM must contain.
  • Confirm before launch: how long Codekeeper keeps earlier deposit versions. Article 13(13) asks for at least ten years, or the support period if longer. Production's "Technical file custody" page promises "versioned custody for the mandatory ten-year retention period"; that isn't in the confirmed facts, so this page doesn't claim a retention period.
  • The three production pages linked below carry errors to fix (see the report): unverified fines, and Article 31 cited as the retention rule (it's Article 13(13)).

Evidence map

Evidence for each obligation.

What you can put in front of an assessor, a market surveillance authority or an enterprise customer, and which protection it comes with.

CRACodekeeper evidence
Art. 13(8)
Vulnerabilities handled for the support period
To ship a fix, the code has to build. Each rebuild proves it does, from the deposit alone.
Recoverability CertificateRun reportBuild stepsEscrow Pro · Resilience Pro · Continuity
Art. 13(13) and 31(2)
Technical documentation, kept and kept current
Documentation deposited alongside the code and synced daily, with an automated check of what's there.
Vault reportSoftware Resilience CertificateEvery protection
Annex I, Part II, point (1)
Software bill of materials
A fresh SBOM with every rebuild, so the inventory matches the version in the deposit.
SBOMEscrow Pro · Resilience Pro · Continuity
Art. 13(23)
If you cease operations
Your customers keep a route back: the deposit released to them under Escrow, or recovered for them by us under Resilience.
Escrow AgreementResilience ArrangementEscrow · Resilience · Continuity

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

Step 3 again, as a choice for the manufacturer's customers. Under Article 13(23) a manufacturer that stops has to tell its users. The three jobs answer the next question those users ask: who brings the product back? Prices are the 6 Oct "from" list; the lead is the agreed price logic sentence, word for word. The Escrow card says "Released to your customer" instead of the canonical "Released to you", because the reader here is the manufacturer (the depositor), not the beneficiary.

Choose the protection

If you can't support it, who brings it back?

Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on.

Released to your customer

Escrow

Deposit→Released to the customer→They recover

When the agreed conditions are met, the deposit is released to your customer. Escrow Pro adds proof it builds. Explore Escrow

From $199

Recovered by us

Resilience

Deposit→Comes to us→We recover

The deposit comes to Codekeeper, and we run the recovery for your customers. Explore Resilience

From $399

Kept switched on

Continuity

Live service kept on+We recover

Everything in Resilience Pro, plus the live environment kept paid and switched on for an agreed period while we recover. Explore Continuity

From $1,449

Prices per application per month. See all prices

Three readers of a CRA page. The first two are manufacturers in the Article 3 sense; the third is the enterprise customer who buys their products and asks for proof. Each card links to the protection that answers its question.

Who it's for

For the people who make products, and the people who rely on them.

Connected product makers

Products with years of support ahead. Keep the code and its build steps in custody, and rebuilt where the stack is supported. Escrow Pro

Software vendors

Software sold in the EU with a support period to honour. Show buyers it builds without your team. Software

Their enterprise customers

Relying on a product for years? Ask for release terms and a Recoverability Certificate. Escrow Pro

The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
The questions manufacturers ask first. Scope (Article 2(1), quoted from EUR-Lex), dates (Commission page, pending legal's check of Article 71), the compliance question, the deposit, the SBOM, and what happens if the manufacturer stops. Production's FAQ claimed escrow is "exactly what Europe requires for CE marking". That isn't in the Regulation text we checked and is gone. There's no fines answer, because Article 64 could not be verified.

Questions

Before you plan your support period.

Who does the CRA apply to?

Article 2(1): it “applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.” The obligations this page covers, such as the support period and the technical documentation, sit with the manufacturer under Article 13.

When do the obligations apply?

The CRA entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026, and the main obligations from 11 December 2027.

Will Codekeeper make our product CRA compliant?

No product can do that on its own. Codekeeper keeps the material you need to support the product recoverable, and gives you evidence: certificates, run reports, build steps and SBOMs. Whether it meets a specific requirement is for you and your assessor to decide.

What should go into the deposit?

Whatever it takes to rebuild the product: source code, build scripts, configuration and the technical documentation. The automated check confirms what's there, and a rebuild flags anything missing.

Is the SBOM in the format the CRA asks for?

Every successful rebuild produces an SBOM of what was built. The Commission may set the format and elements of the SBOM by implementing act (Article 13(24)), so check yours against the current rules with your assessor. The sample evidence pack includes an SBOM excerpt.

What happens for our customers if we stop trading?

Article 13(23) asks a manufacturer that ceases operations to inform market surveillance authorities and users. With Escrow, the deposit is released to your customers under the agreed conditions. With Resilience, Codekeeper runs the recovery for them.

Is our code safe with you?

Codekeeper is ISO/IEC 27001:2022 certified. Deposits are encrypted at rest, and rebuilds run on our own models in a sealed sandbox, so code stays in our environment. See the Trust Center.

The same close on every page. The CRA page closes on the support period, the obligation that runs longest, and on the proof that answers it. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Plan for the whole support period. Start with proof it builds.

We'll look at the products you support and show you what a deposit, a rebuild and an SBOM look like for one of them.