EU Cyber Resilience Act · for iOS & Mac developers

Selling an app in the EU? The CRA's reporting clock already applies to you.

Since 11 September 2026, makers of apps sold in the EU must report actively exploited vulnerabilities to ENISA within 72 hours. Full requirements, including technical documentation and CE marking, follow in December 2027. Check in two minutes whether your app is in scope.

11 Sep 2026Reporting obligations live
11 Dec 2027All CRA requirements apply
24h · 72h · 14dEarly warning · notification · final report

Am I in scope?

1. What do you ship?
2. Is it available to users in the EU?
3. How does it make money?
4. What does it do? (pick the closest)
5. Your company

What Pinwatch does for a one- or two-person studio

SBOM from Package.resolved

Swift Package Manager and CocoaPods dependencies turned into a CycloneDX SBOM on every build, from Xcode Cloud, GitHub Actions or your Mac.

Alerts only when it matters

Daily checks against OSV, CISA's exploited list, ENISA's EU vulnerability database and EPSS. You hear about actively exploited issues, not every CVE.

Incident desk

Records when you became aware, runs the 24h, 72h and 14-day clocks, and pre-fills the text for ENISA's Single Reporting Platform.

Trust page + paperwork

Hosted security.txt, disclosure policy and report inbox. Technical-file skeleton, EU declaration of conformity and support-period statement.

The scanner is open source. Try it on your project today:

pipx install cra-scan
cra-scan scan path/to/YourApp   # writes sbom.cdx.json and checks every pinned package

Pricing

Scanner
Free
  • Open-source CLI + GitHub Action
  • SBOM + vulnerability check
Indie
€149/year
  • Up to 3 apps
  • Daily exploited-vulnerability watch
  • Incident desk + trust page
  • Document pack
  • Founding price €99/year, for life — reserve it free on the waitlist
Studio
€399/year
  • Up to 15 apps or SDKs
  • Everything in Indie

Get early access

We store your email only to contact you about Pinwatch. See the privacy notice.