Skip to content

CRACI

Helsinki pre-seed startup automating EU Cyber Resilience Act compliance and software-supply-chain documentation inside CI/CD pipelines.

Visit Website ↗ + Add to Compare Claim This Company
37/100Emerging / Unranked

Overview

CRACI builds a compliance-automation tool that plugs into CI/CD workflows to track software components, monitor vulnerabilities and generate the documentation manufacturers will need to demonstrate compliance with the EU Cyber Resilience Act (CRA), which introduces mandatory cybersecurity obligations for digital products sold in the EU starting in 2026 (with staggered reporting duties beginning September 2026 and full enforcement from 2027). The product generates SBOMs, tracks vulnerability handling and builds audit trails intended for notified-body conformity assessments.

Founded in 2025 in Helsinki by Juho Niemi, Dennis Marttinen, Jaakko Sirén and Petteri Pulkkinen, the company raised a €1.4 million (~$1.5M) pre-seed round in May 2026 led by Lifeline Ventures, with participation from First Fellow Partners and Wave Ventures. The company is very early-stage — a four-person founding team building toward a hard regulatory deadline rather than an established product with a track record.

Innovation Matrix Assessment

Innovation Velocity 4/10

Small founding team moved from idea to a working CI/CD-integrated product and a pre-seed round within about a year, but the product is unproven at scale.

Operational Value 5/10

Directly addresses a concrete, deadline-driven compliance burden (CRA documentation and SBOM generation) that will affect many EU-facing software vendors, but adoption is unverified.

Market Momentum 2/10

€1.4M pre-seed only, no disclosed customers or revenue; momentum is essentially pre-market.

Category Disruption 3/10

Rides a real regulatory tailwind (CRA) shared by many competitors (e.g., Cycode, established SBOM vendors); not a novel technical approach on its own.

Real-World Efficacy 2/10

No independent evidence of the product working in production; entirely pre-launch/early-access based on available reporting.

Enduring Relevance 6/10

CRA compliance is a multi-year, EU-wide regulatory requirement, so the underlying need will persist regardless of this specific vendor's fate.

Why CISOs Should Care

CISOs and product-security teams at EU-facing software vendors face a hard compliance deadline; automated SBOM and documentation generation could reduce manual audit-prep effort.

What Makes It Different

Narrowly scoped to one regulation (CRA) and embedded directly in CI/CD rather than being a general GRC or SBOM platform retrofitted to cover the rule.

The Matrix Verdict

37/100 — EMERGING / UNRANKED

Emerging tier: real regulatory relevance and a credible funded team, but pre-seed stage with no disclosed customers means it is far too early to claim meaningful market validation.

Editorial Note: Claims vs. Verified Findings

Funding, investors, and founding team are independently confirmed by EU-Startups and Tech.eu; product efficacy and adoption claims are unverified vendor statements.

Sources