CRA · NIS 2 · IEC 62443
Turn your product obligations into a documented, auditable assessment.
GRC tools track your organisation's controls. TRA Studio works one level down — guiding small and mid-sized manufacturers through the Cyber Resilience Act's Annex I risk assessment and technical documentation, and mapping every CRA, NIS 2 and IEC 62443 requirement onto your secure development process. Product-level, self-service, no consultants.
Starter free until 31 Mar 2027 · No credit card · Data hosted in Germany
Built directly on the regulations that apply to you
CRA (EU) 2024/2847
Annex I product and vulnerability-handling requirements, and the technical documentation you must keep.
NIS 2 (EU) 2022/2555
Article 21 risk-management measures and Article 23 reporting obligations for essential and important entities.
IEC 62443-4-1
Secure product development lifecycle practices, scaled to a single team.
Everything you need to prove cyber resilience
One guided workflow from "am I affected?" to a shareable compliance dossier.
Guided TRA
A guided threat & risk analysis with pre-filled templates per product class — the tool has an opinion, so you don't need an in-house expert.
Requirement traceability
Map every CRA, NIS 2 and 62443 requirement onto a secure-development activity. Anything unmapped is flagged as a coverage gap.
Standards library
The full CRA set seeded and ready — import it and tailor your own copy (NIS 2, IEC 62443 and BSI TR-03183 coming soon).
Dossier & questionnaire export
Generate a shareable security dossier, or answer a customer's supplier questionnaire from what you've already captured.
Audit-ready by design
Append-only audit logging, full data export and MFA — the evidence and controls procurement asks for.
Your data in Germany
Hosted in Germany, with a transparent price and self-service onboarding. No integration project, no "contact sales" wall.
Too small for consultants, too regulated for a spreadsheet
If you build connected products or software, the CRA applies with no size discount — and NIS 2 may already reach you.
CRA has no SME exemption
A small device maker carries the full Annex I obligations by December 2027.
NIS 2 reaches SMEs
Essential or important from 50 staff or €10M turnover — many underestimate their exposure.
Supply-chain pressure
Even below the NIS 2 threshold, your regulated customers send you security questionnaires.
Simple, transparent pricing
Flat monthly plans, cancel anytime. Annual billing saves two months.
Single CRA
Find out where you stand.
- 1 User
- 10 Workflows
- 2 products / TRAs
- Guided TRA + templates
- Limited Standards library (CRA only)
- Dossier export (capped products)
- Community support
Starter
One product, a small team.
then €65/mo
- 20 Workflows
- 3 products / TRAs
- Guided TRA + templates
- Full Standards library
- MFA, audit log, JSON/CSV export
- Dossier export (capped products)
- Email support
Professional
A growing product portfolio.
- 200 Workflows
- Unlimited products / TRAs
- Everything in Starter, plus:
- Full, branded dossier & questionnaire export
- SBOM generation
- Priority support
Enterprise
Regulated buyers & procurement.
- Custom seats & products
- SSO / SAML, SCIM
- DPA, escrow, SLA
- Dedicated support
Prices are net (EUR), excl. VAT. Cloud hosting in Germany. On-premise is available for evaluation only — contact us.
