A spreadsheet may already be enough for your product list. Your issue tracker probably handles engineering work well. Before adding another subscription, find the piece of CRA work that keeps falling between them. Then ask a prospective tool to do that job in front of you.
Make a buying decision
Find out whether a dedicated CRA workspace earns its place
- 1Use one representative product and a clearly labelled practice case.
- 2Complete an assessment, hand over the work and inspect its Record.
- 3Choose the tool that solves the gap you actually observed.
Write down the gap before opening a demo
Maybe nobody can find the scope decision for a particular release. Maybe a ticket says “not reportable” without the facts behind that answer. Or the person preparing a notification has to ask three colleagues which deadline they are working towards. Pick one of those problems as the buying requirement.
I build CRA Operations, so this guide has a commercial interest. The test below is deliberately usable on our product and on the setup you already have. A product tour alone will not tell you which is better for your team.
When a spreadsheet and tickets are enough
A small product portfolio with an available owner, a controlled decision log and dependable links to evidence can work without a dedicated CRA application. Keep it if another person can retrieve the applicable product decision, understand the facts behind it and take over the next action.
The maintenance work still has to happen somewhere: review dates, changed facts, access permissions, report preparation and historical decisions. If your current tools handle those handoffs reliably, buying a second place to update the same status may add work.
Where people repeatedly reconstruct that context by chat, a dedicated workspace becomes worth testing. Look for fewer manual joins between product, case, assessment and evidence, rather than the longest list of compliance badges.
Use this case-file checklist to judge whether the evidence is complete.
Run this acceptance test with a colleague
Use non-sensitive practice data in a clearly labelled test workspace. Have one person enter the product and case, then let a second person take over without a narrated tour. Stop and note every place they need the first person’s memory.
In CRA Operations, begin with a product, add a vulnerability case and select the matching assessment from Assessments. Submit it, then inspect the linked result under Evidence. An unfinished questionnaire is not a retained decision.
- Product identity: can the colleague tell which product and version the case concerns?
- Decision trace: can they inspect the submitted facts, result and exact rule version?
- Changed facts: does a new assessment leave the earlier Record understandable?
- Ownership: can they find the person responsible and the next task without asking in chat?
- Access: can a read-only colleague inspect the case without changing it?
- Exit: can you export useful data, and is it clear what that export does not contain?
What CRA Operations does, and what you still do
CRA Operations connects products, vulnerability cases, assessment completions, reporting stages and tasks. Assessments run through ProseID; a completed Record identifies the rule version used. The workspace gives the team a place to return to that decision while the corrective work continues.
It does not scan your code, generate an SBOM or certify a product. It also does not file a notification with ENISA for you. Article 14 notifications use the official Single Reporting Platform; a saved assessment in CRA Operations is not proof of submission.
Settings provides JSON exports of products, cases and the evidence index. The evidence index links to the authoritative ProseID Records; it is not a complete offline copy of those Records. Check that distinction against your retention needs before deciding.
Sources: ENISA — Single Reporting Platform
Pay after the test answers your question
A new CRA Operations workspace includes 30 recorded assessments and two member places for evaluation, with no time-based expiry. Use those two places for the handoff test. Submitting an assessment and creating its Record consumes the allowance; drafting answers does not.
Paid plans differ by recorded-assessment allowance and member capacity. Count the people who will work in the workspace, including pending invitations, and allow for reassessments when facts change. Compare the current prices and limits before subscribing.
Your decision can be “keep the current setup”, “use CRA Operations for this product team”, or “we need a different capability”. If the test exposes a missing scanner or a need for specialist legal advice, purchasing a workflow application will not fill that gap.
This article explains an operational approach to CRA preparation. It does not replace the Regulation, official guidance or advice for a specific product and organisation.
Not lawyer-reviewed.
