Open Source & DeveloperModule ADefault PDEAudited: September 2026 (Active SRP Era)

Complaro / OCCTET

European Open-Source CRA Verification Engine & On-Premises Compliance Core

Executive Conformity Assessment Verdict

The undisputed champion for open-source maintainers, privacy-sensitive defense labs, and budget-conscious engineering teams who refuse to send intellectual property to third-party clouds.

Open-source, self-hosted conformity assessment engine built by the European open-source cybersecurity community.

Verified Pricing TierFree Open Source
Deployment ModelSelf-Hosted FOSS
Applicable CRA RouteModule A
Target Product TierDefault PDE
Statutory Audit

Statutory Capability & Article Coverage Matrix

How Complaro / OCCTET performs against non-negotiable statutory mandates of Regulation (EU) 2024/2847.

Technical Documentation Dossier
Annex VIIPartial / Template Export
EU Declaration of Conformity
Annex VTemplate Only
Coordinated Vulnerability Disclosure (CVD)
Article 10 & RFC 9116Workflow Only
24-Hour ENISA Early Warning Dispatch
Article 14 (Active Sept 2026)Runbook / Guidance
Substantial Modification Diff Engine
Article 22Manual Check
Binary Firmware Disassembly & SCA
Annex I Part I (1)(a)Ingest Only
Air-Gapped / Island-Mode Deployment
Data Sovereignty & IP ProtectionNative Air-Gapped / Island-Mode
Multi-Act Cross-Walk Coverage:CRA Open Source Exemption RulesCybersecurity Act
Technical Architecture

Architectural Fit & Deployment Analysis

Can be deployed as a local Docker container or integrated into internal GitLab runners. Analyzes local software repositories, validates SBOM formats, and checks open CVE lists locally.

Zero data leakage risk. For manufacturers working on classified systems, proprietary embedded microcode, or defense-adjacent PDE, Complaro ensures no telemetry ever leaves the premises.

Lacks enterprise support. If the European Commission updates harmonized standard schemas, community updates may take weeks to merge into the main branch.

Verified Key Strengths
Zero software licensing cost; fully backed by European Commission Horizon Europe research grants
Complete data sovereignty with local, 100% air-gapped on-premises or private server execution
Extensible Python/CLI architecture supporting custom rule development and CI/CD pipelines
Pre-built incident reporting templates matching the ENISA Single Reporting Platform format
Structural Limitations & Gaps
Requires internal DevOps expertise to deploy, configure, update, and maintain
No commercial vendor SLA, guaranteed uptime, or indemnification backing
User interface is developer-oriented; less polished than commercial SaaS platforms
Commercial Model

Pricing, Packaging & Total Cost of Ownership (TCO)

Free Open Source
Entry Tier
Community FOSS: €0 (100% free open-source software funded under Horizon Europe)
Mid / Scale Tier
Self-Hosted Enterprise: €0 (Run locally in internal Docker / Kubernetes clusters)
Enterprise Tier
Commercial Support: Optional third-party consulting integration support
Hidden Cost Factors:
  • Internal DevOps engineering time for hosting, maintenance, and database updates
TCO Verdict:Zero software licensing costs; investment is purely internal engineering deployment and maintenance.
Statutory Honesty Notice • Article 32 & Article 24

Open source maintainers who commercialize products remain fully liable under Article 10. Using an open-source tool does not transfer legal liability to the tool's authors.

Recommended Complementary Directory ToolsView All 18 Evaluated Tools
Recommended Pair
Anchore Enterprise
Inspect in Directory
Recommended Pair
CVD Portal
Inspect in Directory
Recommended Pair
Sbomify
Inspect in Directory

This Site Uses No Cookies

Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.