All apps

Pinwatch

Does the EU Cyber Resilience Act apply to your app? Check in two minutes, then keep an eye on your dependencies.

SecurityWeb

About

The EU Cyber Resilience Act puts security reporting duties on the makers of products sold in the EU, including apps for iPhone, iPad and Mac. Reporting obligations for actively exploited vulnerabilities began on 11 September 2026, and the full requirements follow on 11 December 2027. Pinwatch is built for the one- and two-person studios that have to work this out without a compliance team.

Today you can check whether your app is in scope with a free two-minute questionnaire, and run the open-source scanner, cra-scan, on your own machine or in CI. It turns your Swift Package Manager and CocoaPods dependencies into a CycloneDX SBOM and checks them against public vulnerability sources, with no account and no telemetry.

The hosted parts, a daily watch, an incident desk and a trust page, are planned and not built yet. You can join the waitlist on pinwatch.dev to reserve the founding price and be told when they open.

Features

Free scope check

Five questions tell you whether the Cyber Resilience Act applies to your app, and what that means for you.

SBOM from your dependencies

cra-scan reads Package.resolved and Podfile.lock and writes a CycloneDX 1.6 software bill of materials.

Exploited-vulnerability check

Every pinned package is checked against OSV, and flagged if CISA's or ENISA's lists mark it as actively exploited, with EPSS exploit probability.

Open source, no telemetry

The scanner is Apache 2.0, pure Python with no dependencies. It needs no account and sends nothing to Pinwatch.

Daily watch (planned)

Alerts only when a dependency becomes actively exploited, so you hear about what matters instead of every CVE.

Incident desk (planned)

Records when you became aware and tracks the 24-hour, 72-hour and 14-day reporting clocks, with the text pre-filled for ENISA's reporting platform.

Trust page and paperwork (planned)

A hosted security.txt, disclosure policy and report inbox, plus skeletons for the technical file and the EU declaration of conformity.

Pricing

Scanner free · hosted plans planned

  • ScannerOpen-source command line tool and GitHub ActionFree
  • IndiePlanned. Up to 3 apps, daily watch, incident desk, trust page and document pack€149 / year
  • StudioPlanned. Up to 15 apps or SDKs, everything in Indie€399 / year

The hosted plans are not open yet. Joining the waitlist on pinwatch.dev reserves a founding price of €99 a year, with no payment now.

Questions about the Cyber Resilience Act?