Simple pricing. Two plans.
Basic is free forever for CRA operations. Talk to us when you need enterprise scale across the support period.
Basic
Manufacturers getting started with product inventory and CRA monitoring
- Products, releases & vendor SBOM upload
- Continuous CVE scanning & alerts
- Component-level triage
- Firmware-derived SBOM (on demand)
- Article 14 clock & SRP payload for exploits you declare
- Community blueprint catalog & CI/CD
Enterprise
OEMs and gateway makers running CRA operations at scale across the support period
- Everything in Basic
- Automatic exploit detection (KEV / EUVD)
- Unlimited seats & SSO / SAML
- On-premise / air-gapped deploy
- Evidence packs & audit logs
- Blueprint sharing for long-support rebuilds
- Dedicated SLA, onboarding & support
Frequently Asked Questions
Is Basic really free?
Yes. Basic is free forever, no credit card required. It includes products and releases, vendor SBOM upload, continuous CVE scanning, component-level triage, firmware-derived SBOM, Article 14 clock and SRP payload export for exploitations you declare, plus the community blueprint catalog and CI/CD.
What does Enterprise add?
Enterprise is built for OEMs and gateway makers running CRA operations at scale: automatic detection of actively exploited vulnerabilities (KEV / EUVD), unlimited seats, SSO / SAML, on-premise and air-gapped deployment, evidence packs and audit logs, blueprint sharing for long-support rebuilds, and a dedicated SLA with onboarding and support.
Does alloy-it submit Article 14 reports to ENISA?
No. Alloy helps you stamp awareness and export a copy-JSON payload for ENISA SRP / national CSIRT. Filing stays with your PSIRT and legal owners. Alloy is not CE-marking software and not a notified body.
How much does Enterprise cost?
Enterprise is priced to fit your organization and can be invoiced. Contact us and we'll put together a plan for your team.
Ready to get CRA-ready?
Start free with a product inventory, or book a walkthrough.