Built for the EU Cyber Resilience Act.
The Cyber Resilience Act is Europe’s product-security law for software. Because RAGSuite is software you host yourself, it’s in scope — and we’re engineering it to the CRA’s essential requirements, on a documented path to full conformity ahead of the 11 December 2027 obligations. Not legal advice; the honest state of play.
When each duty applies.
The CRA entered into force in December 2024 and phases in. Unlike the EU AI Act, these dates were not pushed back by the 2026 simplification debate.
- 10 Dec 2024
Entered into force
The Cyber Resilience Act (Regulation (EU) 2024/2847) became law.
- 11 Sep 2026
Reporting duties begin
Actively exploited vulnerabilities and severe incidents must be reported — a 24h / 72h / 14-day cascade via the ENISA Single Reporting Platform.
- 11 Dec 2027
Main obligations apply
Essential requirements, technical documentation, conformity assessment, the EU Declaration of Conformity, CE marking, support-period and SBOM duties.
In scope, on purpose.
Most AI tools are cloud-only, which keeps them outside the CRA’s product-security law. RAGSuite is self-hosted, so it sits inside that law — and we treat that as a feature. You get software built to a published European security bar, on infrastructure you control. You can’t inherit a standard a vendor never had to meet.
Security you can verify — not adjectives.
Signed, pinned releases
Every release is cryptographically signed (cosign) and version-pinned — verify before you run.
SBOM on every release
A machine-readable software bill of materials (CycloneDX) of what we ship.
Coordinated disclosure
A published security contact and a coordinated vulnerability disclosure policy.
Secure by default
Hardened defaults, local-by-default processing, nothing phones home.
Every control documented for due diligence · see the Trust Center →
Cloud-only sidesteps it. Self-hosted is built to it.
Both can be true — and that’s the point.
- Generally outside the CRA’s product scope
- You can’t inherit a standard the vendor never had to meet
- Data leaves your perimeter to their cloud
- Caught by NIS2 as a service, not product-security law
- In CRA scope as a product with digital elements
- Built to the CRA’s essential cybersecurity requirements
- Local-by-default, no egress, optional air-gap
- Signed releases, SBOM and coordinated disclosure
Open source — and honest about it.
RAGSuite’s core is Apache-2.0 and fully inspectable. That helps trust — but it does not make us exempt. Because we offer a commercial edition, NITSAN is the manufacturer under the CRA and carries the full obligations. We’d rather meet the bar than argue our way around it.
“Clever advertising today also means AI that’s accessible and sovereign. RAGSuite fits both.”
Security you can prove, on infrastructure you control — built to Europe’s product-security law.
The Cyber Resilience Act, answered
Is RAGSuite “CRA-compliant”?
We’re CRA-aligned — engineered to the CRA’s essential requirements, on a documented path to full conformity. Nobody can truthfully be “CRA-compliant” yet: the main obligations don’t apply until 11 December 2027 and the harmonised standards aren’t final. We’d rather tell you exactly where we are than over-claim.
Does the CRA apply to you — aren’t you open source?
It applies. The open-source exemption only covers software its maker doesn’t monetise. We offer a commercial edition, so NITSAN is the manufacturer and carries the full obligations. Apache-2.0 gives you inspectability and no lock-in — not a loophole.
Our AI vendor says the CRA doesn’t apply to them. Who’s right?
Both can be true — and it’s the point. Pure-SaaS tools generally fall outside the CRA’s product-security scope (NIS2 applies to them instead). Self-hosted software like RAGSuite is in scope, so you get software actually built to that bar.
Does the CRA add cost or delay for us?
No. The obligations sit with us as the manufacturer, not with you as the deployer. You get the security work; you don’t inherit the paperwork. This page is information, not legal advice.
RAGSuite is being engineered to the CRA’s essential requirements ahead of the 11 December 2027 obligations. We do not yet claim CRA conformity, CE marking or certification; those follow the formal conformity assessment. This page is information, not legal advice.
Talk to us about your CRA review.
Self-hosted software is in scope — and we build to it: signed releases, an SBOM, coordinated disclosure.