PortaRegulus
HOME
06 // INTEL · ANNOUNCEMENT

Two products, one obligation.

We merged our CRA assessment workspace and the CVD Portal into a single platform.

PortaRegulus Intel CRA · Product 12 Jul 2026

Until this week, Porta Regulus ran two products. The CRA assessment workspace at cra.portaregulus.com carried classification, risk assessment and conformity documentation. CVD Portal at cvdportal.com carried coordinated vulnerability disclosure and the Article 14 reporting workflow. They are now one platform, and the reason is the regulation itself.

What changed

Everything now lives on cvdportal.com. The CRA compliance side has its home at cvdportal.com/cra, and cra.portaregulus.com redirects there. Both entries lead into the same dashboard, so a company signs in once and works on the same product records whether it arrived through the disclosure door or the compliance door. For the regulation itself, the EU Cyber Resilience Act guide explains every article and annex in plain English.

If you had an account on the old CRA workspace, it moved with its products, assessment states and generated documents. Existing logins keep working. Nothing needs to be re-entered.

Why we merged them

The Cyber Resilience Act does not treat conformity assessment and vulnerability handling as separate disciplines. Annex I Part II makes vulnerability handling an essential requirement, sitting inside the same technical file as your risk assessment and your Declaration of Conformity. The coordinated disclosure policy you publish, the security.txt you serve, the support period you commit to under Article 13(8) and the reports you file under Article 14 are all evidence in the same conformity story.

Running that story across two tools meant two product records, two evidence trails and a copy-paste seam exactly where an auditor will look. The merge removes the seam. A vulnerability handled in the disclosure workflow lands in the same audit log and the same technical file as the risk assessment that scoped it.

The timing matters too. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, and the full CRA applies from 11 December 2027. Companies preparing for both deadlines should build one body of evidence, once.

What one account covers now

On the conformity side, the platform walks a product through the full journey.

On the vulnerability side, everything CVD Portal already did stays in place.

Pricing

The free tier stays free and still covers the disclosure basics, a hosted portal, security.txt and intake. Paid tiers now follow the compliance journey. Reporting at €99 per month covers the September 2026 duties. Compliance at €299 per month carries the assessment engine, from classification through the Annex I checklist to the Declaration of Conformity draft. Enterprise at €1,499 per month adds the conformity evidence package, API access, SSO and unlimited scale. Existing customers keep the terms they signed up on.

What this does not claim

No platform makes you compliant, and we do not sell presumption of conformity. The harmonised standards that would confer it are still working their way toward Official Journal citation. What the platform does is structure the work the regulation actually asks for and keep the evidence in one place, so that the judgment calls that remain yours are made on top of a complete file.

The merged platform is live now. Start at cvdportal.com/cra if conformity is your entry point, or at cvdportal.com if you need a disclosure portal first. It is the same place either way. That is the point.

One file. One platform. Both deadlines.