PPWR 12 August 2026: the Packaging and Packaging Waste Regulation becomes applicable. What changes → CRA 11 September 2026: reporting of exploited vulnerabilities and severe incidents becomes mandatory under Article 14. What changes →
● Beta · PPWR · CRA · FCM

European compliance: from obligation to resource.

Most companies treat compliance as a last-minute checklist. We built a tool that turns your product documents into a structured, regulation-by-regulation picture of exactly where you stand — and what needs to change.

Product · PPWR Analysis
Art. 4
Material requirements
Compliant
Art. 7
Recycled content
Non-compliant
Art. 11
Labelling
N/A

Compliance documents pile up. Clarity doesn't.

Your team collects datasheets, legal texts and internal checklists across spreadsheets, emails and shared folders. When a regulation changes — or an audit arrives — nobody has a single, reliable picture of where each product actually stands.

📁

Scattered documents

Datasheets, emails and checklists spread across systems with no single source of truth.

🔄

Manual re-checks

Every time a regulation updates, the work starts over from scratch.

👥

No shared view

Compliance, product and legal teams work from different versions of the same reality.

Three steps from document to compliance picture.

1

Upload

Drop in your datasheets and technical product files.

2

Analyse

AI maps your documents against the regulation's articles.

3

Act

See gaps, override assessments, track progress over time.

Three regulations in the beta today.

Each one is modelled article by article, not as a generic checklist. Adding a regulation doesn't change how your team works.

PPWR Available

Packaging and Packaging Waste

Material requirements, recycled content, recyclability, minimisation and labelling — assessed against your packaging technical files.

Regulation (EU) 2025/40
CRA New

Cyber Resilience Act

Essential cybersecurity requirements for products with digital elements, plus the Article 14 reporting duties that apply from 11 September 2026.

Regulation (EU) 2024/2847
FCM New

Food Contact Materials

Declarations of conformity along the whole supply chain — including when the finished article is made for you by a third-party manufacturer.

Regulation (EC) No 1935/2004
12 Aug
2026

The PPWR becomes applicable

From 12 August 2026 the requirements of Regulation (EU) 2025/40 apply to packaging placed on the EU market. Some obligations — recycled content targets and harmonised labelling among them — follow later dates, but the technical documentation behind them is needed well before that.

The CRA reporting clock starts in September.

Article 14 of the Cyber Resilience Act applies more than a year before the rest of the regulation. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to their coordinating CSIRT and to ENISA — on a timetable measured in hours, not weeks.

11 Sep
2026

Article 14 becomes applicable

Reporting obligations start on this date. The remaining obligations of Regulation (EU) 2024/2847 — including the essential requirements and CE marking — follow on 11 December 2027.

24h

Early warning

An actively exploited vulnerability or severe incident must be flagged within 24 hours of becoming aware of it.

72h

Notification

A full notification follows within 72 hours, with the corrective and mitigating measures taken or planned.

14d

Final report

For vulnerabilities, a final report is due within 14 days of a corrective measure being made available.

You cannot meet a 24-hour deadline with a document hunt.

Meeting Article 14 is not really a reporting problem — it is a preparation problem. When the clock starts, you need to already know what the product contains, which requirements applied to it, and who signed off on what.

  • Your product is mapped against the essential requirements in Annex I, article by article
  • Scope and product class are assessed explicitly, so you know whether the CRA applies at all
  • Vulnerability handling requirements are tracked as requirements, not as intentions
  • Every assessment carries a timestamp and an author, ready for the report and for the audit that follows
  • Technical documentation and the EU declaration of conformity are generated from the same analysis
Product · CRA Analysis
Art. 13
Manufacturer obligations
Compliant
Annex I, Part II
Vulnerability handling
Non-compliant
Art. 14
Reporting readiness
In progress

Food contact materials, including what you don't manufacture yourself.

Under Regulation (EC) No 1935/2004, the operator who places a food contact material on the market answers for it — even when someone else made it. If you buy the finished article from a converter who also sources the substrate, inks, adhesives and coatings, your compliance rests entirely on the declarations that come up the chain to you.

Full-service contract manufacturing, checked end to end.

When your supplier both buys the materials and makes the article, you never see most of the evidence behind it. The platform reads the declarations of conformity you do receive and tells you what they actually cover — and what they leave open.

  • Each supplier declaration of conformity is mapped to the composition it genuinely covers
  • Gaps are named: missing migration data, an ink or adhesive with no declaration, a component outside its intended conditions of use
  • Declared conditions of use — contact time, temperature, food type — are compared against how your product is really used
  • Good Manufacturing Practice evidence under Reg. (EC) No 2023/2006 is tracked per site, including your converter's
  • Your own declaration of conformity is generated from what the chain actually supports, not from a template
Supply chain · FCM declarations
Converter
Declaration of conformity
On file
Substrate · PET film
Migration data
Covered
Printing ink
Conditions of use
Out of scope
Adhesive
Supplier declaration
Missing

Built for the people who actually read the regulations.

Every feature is designed around how compliance work actually happens.

🗂️

Article-by-article mapping

Each requirement is assessed individually, so you know exactly which articles are covered and which aren't.

🤖

AI assessment with human override

The AI gives you a starting point; your team has the final word.

📄

Automatic document generation

The technical file and declaration of conformity are generated directly from the analysis, ready for submission.

📋

Audit trail

Every change, override and annotation is logged with timestamp and author.

👥

Team collaboration

Multiple users in the same organisation share one live compliance view.

🔄

Regulation-agnostic architecture

The same workflow applies to any EU regulation, not just the one you're working on today.

Compliance tells you where your product needs to improve. We help you hear it.

Regulations aren't written to create paperwork. They encode what the market, regulators and society expect from your products. When you can see exactly which requirements you're missing — and why — compliance stops being a burden and starts being a development brief. That's what we built this for.

● Beta · PPWR · CRA · FCM

In beta now: PPWR, Cyber Resilience Act and food contact materials.

We started with the EU Packaging and Packaging Waste Regulation. The beta now also covers the Cyber Resilience Act — including the Article 14 reporting duties that apply from 11 September 2026 — and food contact materials, with particular attention to articles made for you by third-party manufacturers. Other EU regulations follow the same workflow.

Apply for beta access

Trusted by early compliance teams.

We're in beta. A small group of compliance teams are already using the platform — and telling us what to fix.

Questions we get asked.

The platform works. You can upload documents, run analyses and see results today. Some features are still being refined, and we actively involve beta users in shaping what comes next.

No. You can upload standard product documents — datasheets, technical files, specification sheets, supplier declarations. The platform handles the rest.

Three, today: the Packaging and Packaging Waste Regulation (PPWR), the Cyber Resilience Act (CRA) and the food contact materials framework (FCM). The architecture is regulation-agnostic — we expand the library based on what beta users are actually working on.

Scope is the first thing the platform assesses. The CRA covers products with digital elements placed on the EU market, with a stricter regime for the important and critical categories. If your product is out of scope, you get that answer with the reasoning behind it — which is itself worth documenting.

It changes where the evidence lives, not who is responsible. If you place the product on the market under your name, the obligations are yours. This is exactly the case the food contact materials support was designed around: the platform works from the declarations and technical documents your manufacturer supplies, and tells you where they fall short of what you need.

You can invite team members and assign them to your organisation's workspace. Everyone shares the same compliance view in real time.

Yes. Documents you upload are processed and stored securely. We don't use your proprietary data to train models.

See where your products stand.

Join the beta. Upload your first product document and get a structured compliance picture in minutes. No commitment, no sales call required.