You sell WordPress products in the EU. The CRA now wants your paperwork.
Security audit trail. Software Bill of Materials. Vulnerability disclosure process. Missing any of them and you're selling non-compliant software — fines up to €15M or 2.5% of global turnover. One bundle produces all of it for your plugin. 48 hours. £99.
One product, one version, one price. Not legal advice — the artifacts, done properly.
This isn't a guideline. It's market access.
Three ways September goes badly for non-compliant products — and they're all mechanical, not judgement calls.
Administrative fines
Maximum penalty for supplying a non-compliant product with digital elements — whichever of €15M or 2.5% of total worldwide annual turnover is higher.
Marketplace enforcement
Envato, CodeCanyon and ThemeForest will ask for compliance documentation from sellers — they always do, eventually, and they delist first and negotiate later.
Enterprise procurement
EU enterprise and public-sector buyers already ask for SBOMs in RFPs. From September, "we don't have one" ends the conversation before it starts.
Three ways to get the same paperwork.
Manual audit, hand-written SBOM, 3–6 week lead time. Re-billed every major release. Right answer, wrong price for most sellers.
Read the regulation, hand-roll CycloneDX tooling, write your own VEX statements, hope you interpreted Annex I right. Possible. Miserable. Easy to get wrong.
Upload a ZIP, get the pack. Audit, SBOM, OpenVEX, receipt, templates — generated from the actual code, signed where it matters.
See exactly what £99 produces.
Real output formats, real signatures. This is what lands in your download folder — click through the artifacts. (Demo plugin shown.)
Nothing hand-waved.
What the Act demands → what the pack contains.
| Security by design and by default | Annex I, Part I §1 | 62-layer audit + Fix Plan — findings with evidence and the diff to close them |
| Identify and document components (SBOM) | Annex I, Part I §2 | SBOM (CycloneDX 1.6) — every dependency, version and license, machine-readable |
| Handle and remediate vulnerabilities | Annex I, Part I §3 | OpenVEX — per-CVE exploitability statements with corroboration |
| Vulnerability disclosure process | Annex I, Part I §4 | SECURITY.md + VDP with response SLAs + RFC 9116 security.txt |
| Technical documentation available to authorities | Annex I, Part I §5 | Signed provenance receipt — verifiable audit attestation for your exact ZIP |
Everything in the £99 bundle
Five artifacts, generated from one audit run. This is the paperwork the CRA expects to exist — produced properly, not templated.
Full security audit + Fix Plan
The same 62-layer pipeline we run for agencies: 58 deterministic scanners, 4 AI engines, and a structured remediation plan your developer (or AI agent) can apply line by line.
SBOM — CycloneDX 1.6
A machine-readable Software Bill of Materials from your composer.lock and package-lock.json — the artifact the CRA explicitly requires you to produce and maintain.
OpenVEX document
Per-CVE exploitability statements with corroboration evidence — the companion document procurement teams and enterprise buyers ask for alongside the SBOM.
Signed provenance receipt
An ed25519-signed attestation that your exact ZIP passed audit — publicly verifiable by anyone, no WP HealthKit account needed.
SECURITY.md + VDP + security.txt
A drop-in SECURITY.md, a Vulnerability Disclosure Policy with response SLAs, and an RFC 9116 security.txt — the process paperwork the CRA expects to exist.
Who this is for
Marketplace sellers
Envato, CodeCanyon, and ThemeForest authors selling into the EU. Marketplaces will ask for this documentation — they always do, eventually.
Premium plugin & extension shops
WooCommerce extensions, premium plugins, SaaS-connected plugins. If EU customers pay you, the CRA applies to your product.
Agencies building client products
You ship plugins or stores for EU clients. Hand them the audit, SBOM, and receipt as part of delivery — instant professionalism.
48 hours, start to pack
Checkout
£99 one-off. No subscription, no card-on-file tricks.
Upload your ZIP
The audit runs in minutes. Everything in the bundle generates automatically from the result.
Download the pack
Report, SBOM, OpenVEX, signed receipt, and templates — ready for your marketplace, buyers, and records.
The honest part: the CRA isn't one-and-done
The bundle makes you compliant today. The law expects you to stay that way as vulnerabilities are discovered — which is exactly what Living Audits does: your plugin's claims are re-verified continuously, and you get a signed challenge with evidence when a fact breaks (a PHP version EOLs, a CVE lands in a bundled library). Bundle buyers get 50% off Platform or Enterprise for their first 3 months — the code is on your confirmation page.
Questions sellers actually ask
Is this legal advice?
No. We produce the technical artifacts the CRA requires — the audit, SBOM, vulnerability documentation, and disclosure-process templates. Whether your specific product is in scope is a question for your lawyer. Our job is to make sure that if it is, the paperwork exists.
I only sell outside the EU — does this matter?
If any of your customers are in the EU, it applies to you regardless of where you're based. If you genuinely sell nowhere near the EU, you're out of scope — but most marketplaces will standardise on this documentation anyway, the way they did with GPL.
Is one bundle enough forever?
No — and we won't pretend otherwise. The CRA is a continuing obligation: vulnerabilities must be handled as they're discovered. The bundle gets you compliant today; monitoring keeps you there. Bundle buyers get 50% off Platform or Enterprise for 3 months, shown after checkout.
What exactly counts as my 'product'?
Each plugin or theme you sell. One bundle covers one product (one ZIP, one version). Re-run it per major release — most sellers bundle it into their release checklist.
The deadline doesn't move. The paperwork takes two days.
£99, one product, everything the CRA expects to exist. Do it this week and it's done.