Free CRA Readiness Check collector — one command in your project folder, and within 24 hours you receive a report showing where your product stands with the EU Cyber Resilience Act: traffic-light readiness status, your full component inventory, and known vulnerabilities with severity.
This collector is open source for one reason: so you can verify exactly what leaves your machine.
Transmitted (JSON, ~a few kB):
- names, versions and package ecosystems of your dependencies (from lockfiles and build files: Conan, vcpkg, CMake, Cargo, npm/yarn/pnpm, Python, Go, Maven/Gradle, Meson, and more),
- the project folder name (hash it with
--anonymize), - scan statistics (number of build files, tool version).
Never transmitted: source code, file paths, file contents, configuration, credentials. See for yourself before sending anything:
embtrace-check . --dry-run # prints the exact payload, uploads nothing- Get your free one-time code at https://embtrace.dev/check (the report goes to the e-mail address you register there).
- Run the collector in your project folder:
pipx install embtrace-check # or: pip install embtrace-check,
# or download the standalone binary
embtrace-check . --code CHK-XXXX-YYYY- Your report arrives within 24 hours. The code is valid for one check.
More options: embtrace-check --help — including --output payload.json
for air-gapped environments (send the file by mail) and --with-tools to
additionally use native package-manager CLIs for higher-fidelity results.
| Code | Meaning |
|---|---|
| 0 | success |
| 1 | error (network, invalid code, …) |
| 2 | no components found — declare dependencies manually in embtrace-deps.yaml |
Data is processed exclusively on Innomatica's own servers in Germany and is never shared or sold. Full notes: https://embtrace.dev/check-privacy.
embtrace-check is the free entry point to
embtrace — the CRA/NIS2 compliance toolchain for
embedded software teams by Innomatica GmbH.
The server side (enrichment, vulnerability monitoring, reports) is a
commercial product; this repository contains the complete client.
Maintained by Innomatica; the roadmap follows the product. Issues and PRs are welcome — please report security topics per SECURITY.md.
MIT © 2026 Innomatica GmbH