Taking our first founding clients

CRA evidence, prepared for you and kept current.

SBOMs, exploited-vulnerability checks, VEX and ENISA report drafts for device makers with 10 to 249 staff. Your team reviews and signs. We do the preparation.

Or email [email protected]

Why now

The clock is running

The CRA arrives in steps. Your customers often ask for the evidence before the law does.

  1. 11 Sep 2026 In force

    ENISA reporting is live

    Manufacturers must report actively exploited vulnerabilities: an early warning in 24 hours, a notification in 72 hours and a final report within 14 days after a fix.

  2. Q4 2026 Customers ask

    OEMs ask their suppliers

    Large OEMs ask suppliers for CRA evidence. For example, Honeywell's supplier page asks each supplier for a CRA attestation or roadmap by Q4 2026, with a machine-readable SBOM per component.

  3. 11 Dec 2027 Main duties

    The main CRA duties apply

    Products on the EU market must meet the CRA requirements. This includes a technical file that shows how each product meets them.

What you get

The evidence, ready for your review

For each product family, we prepare the documents that your customers and the authorities can ask for.

An SBOM for every version

A software bill of materials in CycloneDX for each product version, with a note on gaps. SPDX on request.

A daily exploited-vulnerability check

Every day, we check each SBOM against CISA KEV, the EU Vulnerability Database (EUVD) and OSV.

With maintenance

VEX drafts

A VEX draft for each match, with the reason. Your engineer confirms each "not affected" status.

ENISA report drafts

Prefilled templates for the 24-hour early warning, the 72-hour notification and the final report. You file them.

A technical-file index

What exists, where it lives, and a list of gaps with owners. With draft policies for disclosure, security contact and support period.

Customer questionnaire answers

Answers to the CRA questionnaires that your customers send, based on the evidence. You sign and send them.

How it works

Four steps. The decisions stay with you.

We do the preparation. Your engineers check it, and your company signs and files.

  1. 01

    Intake call

    We talk about your products and what your customers ask for. We sign an NDA and a data processing agreement before we see any data.

  2. 02

    SBOM and inventory

    We list products, versions and support periods. We build an SBOM for each version, from your build or from build files that you send.

  3. 03

    Daily watch and drafts

    We check the SBOMs against exploited-vulnerability lists. We draft VEX, ENISA reports, policies and questionnaire answers.

  4. 04

    You review, sign, file

    Your engineers confirm each VEX status. You sign the documents and file each report.

We aim to finish the setup of one product family in 2 to 3 weeks.

Pricing

Fixed prices per product family

A product family is up to 3 related products on one code base.

Setup

€2,500

per product family, one time

  • An SBOM for each product version
  • An exploited-vulnerability report and VEX drafts
  • Draft policies for vulnerability handling
  • ENISA report templates, prefilled
  • A technical-file index with a gap list
  • Answers to the questionnaire that started the project
  • A 60-minute handover

Maintenance

€450 / month

per product family

  • A daily check against CISA KEV, EUVD and OSV
  • Review of up to 2 releases a month, with VEX updates
  • Up to 2 questionnaire or tender answers a month
  • A monthly evidence report
  • A quarterly review of support periods and policies
  • Up to 3 hours of incident support a month

Founding clients

€1,500 setup and a 12-month price lock

Relvault is new. The first 3 to 5 clients pay €1,500 for setup instead of €2,500. Their monthly price stays the same for 12 months. In return, we ask for honest feedback and, if you are satisfied, a short testimonial.

Ask about a founding place

Setup: you pay 50% at signing and 50% on delivery. Maintenance: invoiced monthly in advance. Prices exclude VAT.

Clear limits

What we do not do

We prepare technical evidence. Legal and conformity decisions stay with you and your advisers.

We do not

  • give legal advice;
  • certify products or decide conformity;
  • call a product "compliant";
  • file reports for you;
  • do penetration tests or EN 18031 test reports.

You keep

  • the EU declaration of conformity, which you sign;
  • each VEX status, which your engineer confirms;
  • each ENISA report, which you file;
  • questions of scope and product class, for your lawyer or test lab.

Who runs Relvault

Chhabi Acharya

Relvault is run by Chhabi Acharya, a software engineer based in Nepal. Relvault is new and small: when this site says "we", it means Chhabi.

He works with clients remotely, in English.

FAQ

Questions we expect

Do you certify our products?

No. We prepare evidence. We do not certify products or decide conformity, and we never call a product "compliant". You sign the EU declaration of conformity. Where the CRA requires it, a notified body assesses the product.

Is this legal advice?

No. We do not interpret the law for your case, for example the scope or the product class. When a question needs a lawyer, a test lab or a CRA consultancy, we tell you.

Do you need access to our code?

Not always. We can set up open-source SBOM tools in your build pipeline together with your engineers, or run them on build files that you send. We do not ask for long-lived access to your systems.

Where is my data?

By default, the evidence stays in your own repository. We keep working copies only while the work needs them, encrypted on Chhabi's work computer in Nepal, and we delete them when the contract ends. We sign an NDA and a data processing agreement before we see any data. We do not put your data into third-party AI tools without your written consent.

We already have an SBOM tool. Is this still useful?

Yes, if the work around the SBOM takes your engineers' time. We use your SBOMs as they are and add the rest: the exploited-vulnerability check, VEX drafts, ENISA report drafts, the technical-file index and questionnaire answers.

Why Nepal?

Chhabi lives in Nepal. The work does not need an office: SBOMs, checks and documents are remote work. Nepal is 3 h 45 min to 4 h 45 min ahead of Central European Time, so calls fit the European early afternoon. The GDPR applies to our work in full.

Do your customers already ask CRA questions?

Send a short email. Tell us what your product is and what your customers ask for.