You sell WordPress products in the EU. The CRA now wants your paperwork.
From 11 September 2026, the EU Cyber Resilience Act expects a security audit trail, a Software Bill of Materials, and a vulnerability disclosure process for products with digital elements. One bundle produces all of it for your plugin — in about 48 hours, for £99.
One product, one version, one price. Not legal advice — the artifacts, done properly.
Everything in the £99 bundle
Full security audit + Fix Plan
The same 62-layer pipeline we run for agencies: 58 deterministic scanners, 4 AI engines, and a structured remediation plan your developer (or AI agent) can apply line by line.
SBOM — CycloneDX 1.6
A machine-readable Software Bill of Materials from your composer.lock and package-lock.json — the artifact the CRA explicitly requires you to produce and maintain.
OpenVEX document
Per-CVE exploitability statements with corroboration evidence — the companion document procurement teams and enterprise buyers ask for alongside the SBOM.
Receipt + SECURITY.md & VDP templates
A signed provenance receipt attesting your exact ZIP passed audit, plus a drop-in SECURITY.md and vulnerability-disclosure-policy template — the process paperwork the CRA expects to exist.
Who this is for
Marketplace sellers
Envato, CodeCanyon, and ThemeForest authors selling into the EU. Marketplaces will ask for this documentation — they always do, eventually.
Premium plugin & extension shops
WooCommerce extensions, premium plugins, SaaS-connected plugins. If EU customers pay you, the CRA applies to your product.
Agencies building client products
You ship plugins or stores for EU clients. Hand them the audit, SBOM, and receipt as part of delivery — instant professionalism.
48 hours, start to pack
Checkout
£99 one-off. No subscription, no card-on-file tricks.
Upload your ZIP
The audit runs in minutes. Everything in the bundle generates automatically from the result.
Download the pack
Report, SBOM, OpenVEX, signed receipt, and templates — ready for your marketplace, buyers, and records.
The honest part: the CRA isn't one-and-done
The bundle makes you compliant today. The law expects you to stay that way as vulnerabilities are discovered — which is exactly what Living Audits does: your plugin's claims are re-verified continuously, and you get a signed challenge with evidence when a fact breaks (a PHP version EOLs, a CVE lands in a bundled library). Bundle buyers get 50% off Pro or Agency for their first 3 months — the code is on your confirmation page.
Questions sellers actually ask
Is this legal advice?
No. We produce the technical artifacts the CRA requires — the audit, SBOM, vulnerability documentation, and disclosure-process templates. Whether your specific product is in scope is a question for your lawyer. Our job is to make sure that if it is, the paperwork exists.
I only sell outside the EU — does this matter?
If any of your customers are in the EU, it applies to you regardless of where you're based. If you genuinely sell nowhere near the EU, you're out of scope — but most marketplaces will standardise on this documentation anyway, the way they did with GPL.
Is one bundle enough forever?
No — and we won't pretend otherwise. The CRA is a continuing obligation: vulnerabilities must be handled as they're discovered. The bundle gets you compliant today; monitoring keeps you there. Bundle buyers get 50% off Pro or Agency for 3 months, shown after checkout.
What exactly counts as my 'product'?
Each plugin or theme you sell. One bundle covers one product (one ZIP, one version). Re-run it per major release — most sellers bundle it into their release checklist.
The deadline doesn't move. The paperwork takes two days.
£99, one product, everything the CRA expects to exist. Do it this week and it's done.