Finnish startup Craci raises €1.4M to automate EU Cyber Resilience Act compliance — with 112 days left
September 11, 2026. That is the date when the EU’s Cyber Resilience Act begins to bite — and when over 600,000 companies worldwide must start reporting actively exploited vulnerabilities to European regulators, or face fines of up to €15 million. That’s 112 days from now.
Craci, a Helsinki-based startup founded in 2025, has raised €1.4 million in pre-seed funding to help software companies get ready. The round was led by Lifeline Ventures — the early backer of Wolt and Supercell — with participation from First Fellow Partners and Wave Ventures.
The regulation that’s rewriting software development in Europe
The EU Cyber Resilience Act (Regulation EU 2024/2847) entered into force in December 2024 and is rolling out in stages. The first hard deadline — September 11, 2026 — requires manufacturers of all software and connected products sold in the EU to begin reporting actively exploited vulnerabilities and severe security incidents to ENISA, the EU cybersecurity agency, with brutal speed: an early warning within 24 hours, a full notification within 72 hours.
Full CRA compliance follows on December 11, 2027, covering security requirements, lifecycle management, software bill of materials (SBOM) documentation, and supply chain accountability across every component a product ships with.
The scope is sweeping. Unlike previous EU cyber regulations that focused on critical infrastructure operators, the CRA applies to any product “with digital elements” placed on the EU market — from enterprise software to consumer IoT devices. For software companies in particular, the regulation effectively turns cybersecurity into a condition for market access rather than a voluntary practice.
The problem Craci solves
Modern software applications are not monolithic. They are assembled from dozens or hundreds of third-party libraries, open-source components, and increasingly, AI-generated code. Knowing exactly what is inside your software — and whether any of it is vulnerable — is no longer optional under the CRA. Companies are fully accountable for every component they ship.
Most software teams manage this manually today, using spreadsheets, ad-hoc scanning tools, and fragmented workflows that were never designed for the speed or precision the CRA demands. When a new vulnerability is discovered in a dependency, teams need to know within hours whether their products are affected — not days.
Craci’s platform integrates directly into existing CI/CD pipelines — the automated workflows developers use to build and deploy software — to provide continuous, automated visibility across the entire software supply chain. It tracks components and dependencies, monitors for vulnerabilities, generates the security documentation and SBOM reports the CRA requires, and manages the compliance lifecycle end-to-end without disrupting development speed.
The founders: from idea to 13-person team in 6 months
The company’s origin story captures the speed at which the opportunity emerged. Co-founder Dennis Marttinen has described how, mid-conversation about the CRA’s implications, the idea crystallised into something that needed to be a company — and within six months, Craci had grown from four founders to a 13-person team and secured its first institutional funding. They were the first startup to graduate from Founders House Helsinki, Finland’s newest deep-tech incubator.
Why Lifeline Ventures backed it
“CRACI’s founders combine rare technical expertise with a deep understanding of how developers actually work. The CRA is rewriting the rules for software in Europe, and CRACI is building what this new era demands: a comprehensive compliance automation solution that fits into existing workflows. We’re excited to back the team.”
— Juha Lindfors, Partner at Lifeline Ventures
Lifeline Ventures is one of Finland’s most respected early-stage funds, with Wolt (acquired by DoorDash for $8.1 billion) and Supercell (valued at $10.2 billion) among its best-known bets. The fund’s participation is a meaningful signal — not just capital, but validation from investors who have backed globally scaled Finnish companies before.
The bigger picture: CRA as global standard-setter
The Cyber Resilience Act is already being compared to GDPR in terms of its global reach. Because it applies to any product sold in the EU — regardless of where it is built — software vendors outside Europe face a choice: build CRA-compliant processes for the EU market, or exit the world’s largest single market. Most will comply. And most will standardise globally around CRA-level requirements, effectively making the regulation a worldwide baseline for software security — just as GDPR reshaped global data privacy practices.
For Craci, that dynamic means a market opportunity that extends well beyond Europe’s borders from day one. With the September 11 reporting deadline now 112 days away and most companies still unprepared, the timing of this funding round is precise.
Craci is based in Helsinki, Finland. More information at craci.com.
Related articles: Mobility Signage raises €1.8M to fix public transport’s fragmented IT — BVG, Deutsche Bahn, and SSB already on board | Ghent’s Exhibitly raises €1.4M to personalise B2B event websites — 114 events signed in nine months | Where to Eat in Helsinki During Slush 2025
0 comments