ScrutoraCode, cloud & consent

EU Cyber Resilience Act (Regulation 2024/2847), checked from the code up.

Findings arrive already citing the clause they touch, so nobody has to translate a rule id into an obligation before the work can start.

68Source codethe application itself
0InfrastructureTerraform, Kubernetes, pipelines
0Cloudthe account you actually run
01 · How it is checked

Rules, not a questionnaire.

FROM THE SOURCE

Values are followed across functions and files, so a finding is a real path from a real field to a real sink, not a keyword match.

CITED, NOT INFERRED

Each rule names the clause it answers to. Where a mapping is partial or advisory, the page says so rather than implying certainty.

THE SAME ENGINE

Nothing about this framework changes how the scan runs. Selecting it changes which obligations the same findings are reported against.

02 · What a scan cannot tell you

Code answers some obligations. Not all of them.

Every framework contains duties that are organisational rather than technical: appointing people, training them, keeping minutes, running assessments. No scanner can evidence those, and one that implies it can is selling you a false sense of finishing. What this covers is the part written in your software, which is the part nobody else can see.

03 · Related

Others in the same family.

ISO 27001 74SOC 2 70NIS2 62NIST SSDF 58
04 · Try itNOTHING LEAVES YOUR MACHINE

Scan against EU CRA.

Or run the container on your own runner. The scan happens in your pipeline and the source never reaches us.