TRA Studio

CRA · NIS 2 · IEC 62443

Turn your product obligations into a documented, auditable assessment.

GRC tools track your organisation's controls. TRA Studio works one level down — guiding small and mid-sized manufacturers through the Cyber Resilience Act's Annex I risk assessment and technical documentation, and mapping every CRA, NIS 2 and IEC 62443 requirement onto your secure development process. Product-level, self-service, no consultants.

Starter free until 31 Mar 2027 · No credit card · Data hosted in Germany

Built directly on the regulations that apply to you

CRA (EU) 2024/2847

Annex I product and vulnerability-handling requirements, and the technical documentation you must keep.

NIS 2 (EU) 2022/2555

Article 21 risk-management measures and Article 23 reporting obligations for essential and important entities.

IEC 62443-4-1

Secure product development lifecycle practices, scaled to a single team.

Everything you need to prove cyber resilience

One guided workflow from "am I affected?" to a shareable compliance dossier.

Guided TRA

A guided threat & risk analysis with pre-filled templates per product class — the tool has an opinion, so you don't need an in-house expert.

Requirement traceability

Map every CRA, NIS 2 and 62443 requirement onto a secure-development activity. Anything unmapped is flagged as a coverage gap.

Standards library

The full CRA set seeded and ready — import it and tailor your own copy (NIS 2, IEC 62443 and BSI TR-03183 coming soon).

Dossier & questionnaire export

Generate a shareable security dossier, or answer a customer's supplier questionnaire from what you've already captured.

Audit-ready by design

Append-only audit logging, full data export and MFA — the evidence and controls procurement asks for.

Your data in Germany

Hosted in Germany, with a transparent price and self-service onboarding. No integration project, no "contact sales" wall.

Too small for consultants, too regulated for a spreadsheet

If you build connected products or software, the CRA applies with no size discount — and NIS 2 may already reach you.

CRA has no SME exemption

A small device maker carries the full Annex I obligations by December 2027.

NIS 2 reaches SMEs

Essential or important from 50 staff or €10M turnover — many underestimate their exposure.

Supply-chain pressure

Even below the NIS 2 threshold, your regulated customers send you security questionnaires.

Simple, transparent pricing

Flat monthly plans, cancel anytime. Annual billing saves two months.

2 months free

Single CRA

Find out where you stand.

Free
  • 1 User
  • 10 Workflows
  • 2 products / TRAs
  • Guided TRA + templates
  • Limited Standards library (CRA only)
  • Dossier export (capped products)
  • Community support
Free test phase

Starter

One product, a small team.

FreeFree until 31 Mar 2027

then €65/mo

  • 20 Workflows
  • 3 products / TRAs
  • Guided TRA + templates
  • Full Standards library
  • MFA, audit log, JSON/CSV export
  • Dossier export (capped products)
  • Email support
Planned

Professional

A growing product portfolio.

€349/mo
  • 200 Workflows
  • Unlimited products / TRAs
  • Everything in Starter, plus:
  • Full, branded dossier & questionnaire export
  • SBOM generation
  • Priority support
Planned

Enterprise

Regulated buyers & procurement.

Let's talk
  • Custom seats & products
  • SSO / SAML, SCIM
  • DPA, escrow, SLA
  • Dedicated support

Prices are net (EUR), excl. VAT. Cloud hosting in Germany. On-premise is available for evaluation only — contact us.