CRACI
Helsinki pre-seed startup automating EU Cyber Resilience Act compliance and software-supply-chain documentation inside CI/CD pipelines.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
CRACI builds a compliance-automation tool that plugs into CI/CD workflows to track software components, monitor vulnerabilities and generate the documentation manufacturers will need to demonstrate compliance with the EU Cyber Resilience Act (CRA), which introduces mandatory cybersecurity obligations for digital products sold in the EU starting in 2026 (with staggered reporting duties beginning September 2026 and full enforcement from 2027). The product generates SBOMs, tracks vulnerability handling and builds audit trails intended for notified-body conformity assessments.
Founded in 2025 in Helsinki by Juho Niemi, Dennis Marttinen, Jaakko Sirén and Petteri Pulkkinen, the company raised a €1.4 million (~$1.5M) pre-seed round in May 2026 led by Lifeline Ventures, with participation from First Fellow Partners and Wave Ventures. The company is very early-stage — a four-person founding team building toward a hard regulatory deadline rather than an established product with a track record.
Innovation Matrix Assessment
Small founding team moved from idea to a working CI/CD-integrated product and a pre-seed round within about a year, but the product is unproven at scale.
Directly addresses a concrete, deadline-driven compliance burden (CRA documentation and SBOM generation) that will affect many EU-facing software vendors, but adoption is unverified.
€1.4M pre-seed only, no disclosed customers or revenue; momentum is essentially pre-market.
Rides a real regulatory tailwind (CRA) shared by many competitors (e.g., Cycode, established SBOM vendors); not a novel technical approach on its own.
No independent evidence of the product working in production; entirely pre-launch/early-access based on available reporting.
CRA compliance is a multi-year, EU-wide regulatory requirement, so the underlying need will persist regardless of this specific vendor's fate.
Why CISOs Should Care
CISOs and product-security teams at EU-facing software vendors face a hard compliance deadline; automated SBOM and documentation generation could reduce manual audit-prep effort.
What Makes It Different
Narrowly scoped to one regulation (CRA) and embedded directly in CI/CD rather than being a general GRC or SBOM platform retrofitted to cover the rule.
The Matrix Verdict
37/100 — EMERGING / UNRANKED
Emerging tier: real regulatory relevance and a credible funded team, but pre-seed stage with no disclosed customers means it is far too early to claim meaningful market validation.
Editorial Note: Claims vs. Verified Findings
Funding, investors, and founding team are independently confirmed by EU-Startups and Tech.eu; product efficacy and adoption claims are unverified vendor statements.
Sources
- EU-Startups — https://www.eu-startups.com/2026/07/spanish-cybersecurity-startup-8layers-extends-pre-seed-round-to-e2-5-million-total-funding/
- Tech.eu — https://tech.eu/2026/05/19/craci-raises-eur14m-for-eu-cybersecurity-compliance-platform/
- TechFundingNews — https://techfundingnews.com/craci-cyber-resilience-act-compliance/
Alternatives to CRACI
Chainalysis
The dominant, category-defining incumbent in blockchain analytics -- broad government and financial-institution adoption, a decade-plus track record, and…
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…