Four months. That's all the runway CRACI Corporation Oy has to convince European manufacturers that they need help—badly—navigating one of the continent's most demanding cybersecurity regulations.
The Helsinki-based startup announced a €1.4 million pre-seed round on May 8, 2026, positioning itself as a lifeline for companies scrambling to meet the EU Cyber Resilience Act's first major compliance hurdle: a September 11, 2026 deadline requiring manufacturers to report actively exploited vulnerabilities to regulators within 24 hours, with subsequent follow-ups required. Miss that window, and you're operating in murky legal territory. Miss it badly enough, and you're looking at fines up to €15 million.
Lifeline Ventures led the round. First Fellow Partners, Wave Ventures, and Lucas Käldström—a recognized name in the Kubernetes developer community—joined in.
When Compliance Becomes Product Infrastructure
The CRA entered into force on December 10, 2024, but September is when the regulation starts showing its teeth. By December 11, 2027, full enforcement kicks in, complete with penalties that can reach 2.5 percent of a company's global annual turnover for serious violations. Not exactly a rounding error.
CRACI's pitch is straightforward, if ambitious: treat compliance as part of your build pipeline, not an afterthought. The platform plugs directly into CI/CD tools—GitHub Actions, GitLab CI, Jenkins, CircleCI—automatically generating Software Bills of Materials (SBOMs) in industry-standard SPDX and CycloneDX formats. It monitors vulnerabilities in real time and, crucially, handles the gnarlier part: filing those 24-hour incident reports to ENISA's Single Reporting Platform.
"Compliance ships with every build," the company says—a formulation that sounds slick but also reflects a genuine shift in how software teams might need to think about regulatory burden.
The platform also tackles the CRA's ten-year documentation retention requirement, spitting out compliance reports in PDF, HTML, CSV, Excel, and JSON. Perhaps more telling, CRACI has already built modules for adjacent regulations like NIS2, which targets telecom and critical infrastructure providers. That suggests the founders aren't betting on a single regulatory moment but rather a broader wave of European digital governance.
Who's Actually Using This?

Customer traction remains opaque. CRACI's announcement name-checks Hamina Wireless, a Finnish company specializing in network planning software, as an early adopter, though no independent confirmation of this or broader customer adoption has emerged in public channels—a common challenge for startups announcing momentum before it's fully materialized.
The founding team brings technical credibility: Juho Niemi (CEO), Dennis Marttinen (CTO), Jaakko Sirén (CPO), and Petteri Pulkkinen (CISO). According to Niemi's LinkedIn activity in May, the company grew from those four co-founders to a 13-person team within six months of its October 2025 incorporation. Fast, though not unprecedented for a well-funded European startup in growth mode.
Juha Lindfors, a partner at Lifeline Ventures, offered measured praise in the funding announcement: "CRACI's founders combine rare technical expertise." It's the kind of language investors deploy when they're confident but also aware the hard work lies ahead.
Crowded Field, Narrow Window

CRACI enters a market already populated by established vulnerability scanners—Snyk, Mend.io, Black Duck—though those platforms focus primarily on detection rather than end-to-end compliance orchestration. A handful of newer entrants are chasing the same regulatory tailwind: CRA Evidence, CRA Ready, cramio, and Seentrix among them.
The startup is currently running an aggressive promotional strategy: a Pro plan priced at €30 per month (down from the standard €330) through the end of 2026. That tier covers up to 20 users and one actively monitored SBOM. Additional SBOMs cost €300 monthly each—pricing that could add up quickly for larger manufacturers juggling dozens of products.
Whether that promotional window generates enough early adopters to create network effects before competitors gain traction remains an open question. CRACI's timeline is unforgiving. The September deadline isn't moving, and neither are the companies that will face it unprepared.
If the founders are right about the market—that compliance automation is infrastructure, not overhead—they've timed their entry well. If they're wrong, or even just early, four months won't feel like much of a head start.
