The archive · Developer & Business Tools · Product decision · 2025–2026
CRACI's CRA bet: automate EU software-security compliance; €1.4M pre-seed in May 2026
CRACI builds software-supply-chain tooling that automates EU Cyber Resilience Act compliance; Helsinki startup, founded 2025, raised €1.4M pre-seed in May 2026.
CRACI
What the business is
CRACI makes software-supply-chain security tooling that continuously tracks vulnerabilities, archives software bill of materials (SBOM) history and automates the documentation the EU Cyber Resilience Act requires, without adding separate workflows for engineering teams.
How it started
Juho Niemi, Dennis Marttinen, Jaakko Sirén and Petteri Pulkkinen founded CRACI in Helsinki in 2025 as the EU Cyber Resilience Act's obligations approached. Their premise: the CRA makes supply-chain visibility, documentation and lifecycle management mandatory for products with digital elements sold in the EU, and software teams will not meet that paperwork burden by hand.
What happened
Announced on 2026-05-08, CRACI closed a €1.4M pre-seed led by Lifeline Ventures with participation from First Fellow Partners and Wave Ventures, ahead of the CRA's first obligations phasing in from late 2026. The platform continuously manages vulnerabilities, archives SBOM history and tracks compliance status, which the founders position as the difference between fast market access and costly delays as the regulation lands across the European market.
No ending yet — it is still running.
Background
CRACI is a Helsinki cybersecurity startup founded in 2025 by Juho Niemi, Dennis Marttinen, Jaakko Sirén and Petteri Pulkkinen. It sells software-supply-chain security tooling purpose-built for the EU Cyber Resilience Act: continuous vulnerability tracking, archived software bill of materials history, and compliance status that engineers can maintain without a separate compliance workflow.
The bet is that the CRA turns supply-chain security from a nice-to-have into a purchase order for every company selling software or connected products in the EU. On 2026-05-08 CRACI announced a €1.4M pre-seed led by Lifeline Ventures with First Fellow Partners and Wave Ventures, timed ahead of the regulation's first obligations phasing in from late 2026. Finland's Talouselämä reported in June 2026 that the CRA is creating a new market for software tools that touches an estimated 600,000 companies.
CRACI's wedge is compliance automation rather than threat detection: instead of promising to stop attacks, it promises that vulnerability logs, SBOM archives and lifecycle documentation are always ready. The open question, common to every regulation-driven tool, is whether the market is a spike around the deadline or a durable category that keeps buyers renewing after compliance is routine.
What has to be true
- The CRA applies to products with digital elements sold in the EU, creating a large base of software sellers that never bought supply-chain security before.
- Automating compliance inside existing workflows (continuous vulnerability tracking, SBOM history) avoids the parallel-process tax that makes compliance projects stall.
- The founders timed the company to the rule: founded in 2025, funded in May 2026, with obligations phasing in from late 2026.
- Backers signal reach: Lifeline Ventures led the round, with First Fellow Partners and Wave Ventures participating.
What can be applied
New law, boring wedge: CRACI automated the CRA's paperwork (SBOMs, vulnerability logs, lifecycle docs) instead of promising to stop attacks; deadlines, not fear, created the purchase order.
Aftermath
As of its May 2026 announcement CRACI is a building-stage startup: the pre-seed funds product development and platform expansion ahead of the CRA's first obligations in late 2026. The founders argue that companies investing early in automated supply-chain security gain faster market access and stronger trust, while teams relying on manual processes risk delays and higher costs as the regulation applies across the European market.
Sources
- CRACI raises €1.4M for EU cybersecurity compliance platform
- Tuleva sääntely voi maksaa yrityksellesi miljoonia – Startup nappasi 1,4 miljoonan rahoituksen vastatakseen ongelmaan
- Helsinki startup CRACI raises €1.4M pre-seed to automate Cyber Resilience Act compliance for software supply chains
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card