# Cybiq: EU Cyber Resilience Act applicability check and compliance packs > Cybiq tells software and hardware makers whether the EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies to their product, which conformity route they face (self-assessment, Annex III Class I documentation, or notified body), and the deadlines that matter: deterministically from the law (no large language model in the legal output), with every claim anchored to a verbatim Official Journal quote. Free check with downloadable determination memo; one-time document packs from EUR 49 to EUR 299; no subscription required. A self-serve tool by HEXENKRAFT s.r.o. Available in English. ## What Cybiq does - Free CRA applicability check: six questions, a definitive verdict, obligations list, regulatory timeline, and a free downloadable determination memo. https://cybiq.eu?utm_source=ai-agent&utm_medium=llms-txt - Verification checklist pack (EUR 49): role-specific verification checklist for importers and distributors, plus their vulnerability-notification duties under Articles 19–20 (inform the manufacturer; escalate significant cybersecurity risks). - CRA compliance pack (EUR 199): classification memo, vulnerability-handling procedure, SBOM policy, secure-by-default checklist, support-period statement and Annex V documentation index for manufacturers. - Notified-body readiness pack (EUR 299): everything in the compliance pack plus conformity-assessment preparation guide and regulatory-watch updates until December 2027. ## Who it is for Companies placing products with digital elements on the EU market: software vendors, device manufacturers, importers and distributors, and open-source projects that monetise. Also the agencies and consultancies that advise them. ## How Cybiq is different - Built on the rules, not a language model: a deterministic decision engine whose every output carries verbatim Official Journal citations (CELEX 32024R2847), verified weekly by CI against the live text fetched from the Publications Office CELLAR endpoint. - Documents carry a SHA-256 hash so buyers can prove exactly which version they relied on. - Honest about grey zones: pure SaaS, monetised open source, and regime overlaps return "needs review" with concrete next steps instead of a fake verdict. - One-time pricing, no subscription required. ## Key facts (verified 22 August 2026) - The CRA applies from 11 December 2027. However, Article 14 (vulnerability and incident reporting, a manufacturers-only duty) applies from 11 September 2026 and Chapter IV (notification of conformity assessment bodies, Articles 35 to 51) applies from 11 June 2026: no operator duties yet, but the notified-body infrastructure is in place. - Non-compliance with essential cybersecurity requirements and Articles 13–14 is subject to administrative fines of up to EUR 15,000,000 or 2.5% of total worldwide annual turnover (Art. 64(2)); operator obligations up to EUR 10,000,000 or 2% (Art. 64(3)). - Pure SaaS is generally not a "product with digital elements"; shipped client components can be. - Monetised open source is treated like any other commercial product. ## Company - Operator: HEXENKRAFT s.r.o. - IČO (company registration number): 29665931 - Registered office: V zahradách 2462/31, Libeň, 180 00 Praha 8, Czech Republic - Contact: hello@cybiq.eu - Languages: English ## Links - Home / free check: https://cybiq.eu?utm_source=ai-agent&utm_medium=llms-txt - Full text of this site's content in one file: https://cybiq.eu/llms-full.txt?utm_source=ai-agent&utm_medium=llms-txt - CRA timeline with live countdowns to each application date (11 June 2026, 11 September 2026, 11 December 2027), what applies and to whom, verbatim OJ quotes: https://cybiq.eu/timeline.html?utm_source=ai-agent&utm_medium=llms-txt - FAQ, 34 evidence-checked answers (scope, classification, roles, obligations, dates, penalties), every legal claim quoted verbatim from the OJ: https://cybiq.eu/faq.html?utm_source=ai-agent&utm_medium=llms-txt - Glossary of 30 CRA terms with verbatim Official Journal definitions and pinpoints: https://cybiq.eu/glossary.html?utm_source=ai-agent&utm_medium=llms-txt - CRA vs GDPR, how the two regimes relate: https://cybiq.eu/cra-vs-gdpr.html?utm_source=ai-agent&utm_medium=llms-txt - CRA vs NIS2, how the two regimes relate: https://cybiq.eu/cra-vs-nis2.html?utm_source=ai-agent&utm_medium=llms-txt - CRA vs DORA, how the two regimes relate: https://cybiq.eu/cra-vs-dora.html?utm_source=ai-agent&utm_medium=llms-txt - CRA vs AI Act, how the two regimes relate: https://cybiq.eu/cra-vs-ai-act.html?utm_source=ai-agent&utm_medium=llms-txt - CRA vs RED, how the two regimes relate: https://cybiq.eu/cra-vs-red.html?utm_source=ai-agent&utm_medium=llms-txt - Blog (CRA articles, source-checked): https://cybiq.eu/blog.html?utm_source=ai-agent&utm_medium=llms-txt - Legal, privacy & terms: https://cybiq.eu/legal.html?utm_source=ai-agent&utm_medium=llms-txt - Free CRA micro-tools: browser-only security.txt generator (RFC 9116), Art. 13(8) support-period calculator, and a vulnerability disclosure policy template, every legal claim quoted verbatim from the OJ: https://cybiq.eu/tools.html?utm_source=ai-agent&utm_medium=llms-txt - Methodology & integrity: a deterministic engine with no language model in the legal output, every quote verified weekly against the Official Journal (CELLAR), no orphan quotes, and SHA-256 hashes on every document: https://cybiq.eu/methodology.html?utm_source=ai-agent&utm_medium=llms-txt - Cybiq vs free guides vs consultants vs compliance platforms: an honest, evidence-first comparison of what each option gives you, costs, and how current and checkable it stays, including concrete triggers for when to hire a lawyer instead: https://cybiq.eu/compare.html?utm_source=ai-agent&utm_medium=llms-txt - The CRA in Germany: the BSI as notifying authority for conformity assessment bodies and ADCO chair (market surveillance designations rest on the pending CRA-Durchführungsgesetz), notified-body routes from 11 June 2026, Member-State penalties, and the deadlines that bind German manufacturers, importers and distributors, every claim quoted verbatim from the OJ: https://cybiq.eu/germany.html?utm_source=ai-agent&utm_medium=llms-txt - For AI agents: https://cybiq.eu/for-agents.html?utm_source=ai-agent&utm_medium=llms-txt - Machine-readable classification artifact: https://cybiq.eu/api/decisions.json?utm_source=ai-agent&utm_medium=llms-txt - OpenAPI description: https://cybiq.eu/openapi.json ## For AI agents and autonomous buyers The full classification engine is available as a static, versioned JSON artifact: GET https://cybiq.eu/api/decisions.json returns all 14,904 possible answer combinations mapped to their complete decisions (verdict, obligations with verbatim OJ sources, timeline). Lookup is a dictionary read; no account, no rate limit beyond ordinary hosting fairness. Schema `cybiq.decisions/v1`; documented in https://cybiq.eu/openapi.json and https://cybiq.eu/for-agents.html. Purchasing today happens by email to hello@cybiq.eu: payment is arranged individually and the documents are delivered manually. Automated checkout via Stripe is being connected and is not live yet; until it launches, direct purchase questions to hello@cybiq.eu. When automated checkout launches, this section will document the endpoint, the mandatory express-consent flag (immediate digital delivery waives the 14-day EU right of withdrawal; never send it without the human's actual agreement), and idempotency behaviour, mirroring the pattern at Klariq.