Pricing

Priced for manufacturers, delivered with implementation.

Start free with one product, subscribe when you are ready, and add an implementation engagement if you want your workspace configured with you. Every plan includes SBOM ingestion, vulnerability intelligence, the CRA Reporting Command Center, evidence and audit log. Prices excl. VAT.

Evaluation

Explore Vellaci with one product.

Free

1 product · 3 seats · 10 SBOMs/month · 10-year retention

  • 1 product
  • 3 seats
  • SBOM ingestion and vulnerability matching
  • CRA reporting workflow

Readiness

For smaller manufacturers establishing CRA processes.

€490/month
billed monthly · excl. VAT

5 products · 10 seats · 200 SBOMs/month · 10-year retention

  • Up to 5 products
  • 10 seats
  • GitHub integration
  • Vulnerability intelligence (OSV, KEV, EPSS)
  • CRA Reporting Command Center
  • Evidence vault and readiness framework
  • PDF/CSV/ZIP reports

or talk to us

Growth

Most chosen

For multiple products and security teams.

€990/month
billed monthly · excl. VAT

25 products · 30 seats · 2,000 SBOMs/month · 12-year retention

  • Up to 25 products
  • 30 seats
  • Everything in Readiness
  • Advanced audit exports
  • Priority support

or talk to us

Enterprise

Advanced governance, SSO, integrations and support.

€1,490/month
billed monthly · excl. VAT

Custom products, seats and SBOM volume

  • Unlimited products
  • Enterprise SSO (SAML)
  • Custom retention
  • Implementation partner
  • Custom contracts
Layer 1 · recurring

SaaS subscription

Recurring compliance operations: the workspace, continuous SBOM matching, server-computed deadlines, evidence vault, audit log, exports. Monthly or annual, per plan below.

Layer 2 · one-time

Implementation engagement

Initial setup, migration, inventory, workflow definition, documentation structure and onboarding, delivered by Vellaci operators inside your workspace. Deliverables, prerequisites, timeline and exclusions are listed for each package.

Layer 3 · optional

Specialist support

Legal, conformity-assessment or security-testing expertise outside the SaaS, delivered by your advisers or independent partners. Vellaci coordinates and records; it never substitutes.

What each plan includes

The same questions a procurement or security review asks, answered per plan. Limits are enforced in the product; everything else is included, not an add-on.

QuestionEvaluationfreeReadiness€490/monthGrowth€990/monthEnterprise€1490/month list
Who it is forTechnical evaluators proving the workflow on one real product before any conversation.Smaller manufacturers (1–5 products) establishing CRA processes and Article 14 reporting for the first time.Manufacturers with multiple products (6–25) and a security team that needs governance across owners.Large portfolios (26+ products) with SSO, procurement and negotiated terms.
Product limits1 productUp to 5 products, unlimited versionsUp to 25 productsCustom (unlimited by default)
Team access3 seats · owner, admin, member roles10 seats · seven roles incl. external advisers30 seats · custom fields, saved views, bulk actionsCustom seats · SAML/OIDC SSO · enforced MFA · SCIM prepared
SBOM ingestion10 SBOMs/month · upload, API, CLI, GitHub200 SBOMs/month · upload, API, CLI, GitHub, GitLab2,000 SBOMs/month · CI ingestion · SBOM diff · release gatesCustom volume · partner and CI pipelines
Vulnerability monitoringOSV, GitHub advisories, CISA KEV, EPSS · continuous re-matchingOSV, GitHub advisories, KEV, EPSS · exploitation signals · explainable priorityEverything in Readiness · per-organisation priority weights · policies with violationsEverything in Growth · two-person approvals · custom retention of intelligence
Incident workflowFull incident and CRA reporting workflow (24h / 72h / final)Incidents, reportability review, reporting cases with server-computed deadlines, drillsEverything in Readiness · Jira / Linear / Slack / Teams / PagerDuty routingEverything in Growth · continuity sheet · partner portal
Evidence retention10-year retention · checksummed vault10-year retention · classification · legal hold12-year retention · retention policies · scheduled reports15-year retention · custom residency options on request
ReportingPDF / CSV / ZIP exportsExecutive reports · submission-ready notifications · VEXEverything in Readiness · scheduled and auditor packagesEverything in Growth · contract reporting
Audit supportHash-chained audit log · organisation exportAudit log · auditor read-only access · signed exportsAdvanced audit exports · auditor mode · access reviewsEnterprise security review under NDA · questionnaire · SOC 2 readiness mapping
Support levelDocumentation and e-mailE-mail, next business day · optional implementation engagementPriority e-mail · quarterly readiness check-inNamed contact · implementation partner · custom SLA in contract

Implementation packages

One-time engagements delivered by Vellaci operators with time-bound, logged access to your workspace. Quoted per engagement; indicative fees below. The engagement ends with a live workspace that continues on a platform plan — nothing is rebuilt or migrated.

Vellaci Readiness

from €4,900 one-time

Teams with a small portfolio (1–5 products) that must be operational for Article 14 reporting within weeks.

Deliverables
  • Preliminary CRA scope assessment recorded per product with reasoning
  • Product registry with owners, lifecycle, classification and support period
  • A valid SBOM matched for every supported version
  • Vulnerability triage workflow with owners, reasons and SLAs
  • Incident process owners and awareness rule
  • CRA reporting runbook: assigned representative, ENISA platform access, contacts
  • One 24h / 72h reporting drill run and filed as evidence
  • Evidence baseline uploaded, classified and linked to requirements
  • Team invited with roles; MFA policy decided
  • Readiness review against the requirement framework with named owners for open gaps
Prerequisites
  • A decision-maker and a technical contact available for two 60-minute sessions per week
  • Product list with versions and, where they exist, SBOMs or repository access
  • Existing policies, test reports and risk assessments (any format)
  • Someone able to obtain ENISA Single Reporting Platform access for the organisation
Timeline
Four to six weeks depending on portfolio size and your team's availability; the plan and its progress are visible in your workspace from day one.
Not included
  • Legal opinions on scope, classification or reportability
  • Conformity assessment, notified-body engagement, CE marking
  • Penetration testing or security testing of your products
  • Writing your technical documentation for you (we structure it; your engineers fill it)
  • Migration of historical evidence beyond the baseline (see Implementation)
Your responsibilities
  • Decide scope, classification and awareness rule (Vellaci records the decision and the reasoning)
  • Provide SBOMs or repository access
  • Name the assigned representative and deputies
  • Attend the drill and the readiness review
Continues on
Readiness plan or Growth plan

Vellaci Implementation

from €9,500 one-time

Multi-product manufacturers (typically 6–25 products) migrating existing evidence, integrating trackers and CI, and standing up product-security processes across teams.

Deliverables
  • Everything in Vellaci Readiness, across the whole portfolio
  • GitHub / GitLab connected and repositories linked to products; CI SBOM upload configured
  • Jira / Linear linked for remediation tasks; Slack / Teams / PagerDuty routing for critical deadlines and exploited vulnerabilities
  • Existing evidence migrated, classified and linked to requirements
  • Policies and templates configured (triage, disclosure, remediation SLAs, retention)
  • Technical documentation workspace per product with Annex VII sections
  • Product-security process documentation and training for every role
  • Handoff with documented open items and an operational runbook
Prerequisites
  • Everything required for Readiness
  • Administrative access to the repository host, tracker and chat tools to be integrated
  • An inventory of existing evidence with owners
  • A product-security or compliance lead who will own the processes after handoff
Timeline
Six to ten weeks depending on the number of products, integrations and the volume of evidence to migrate.
Not included
  • Legal opinions and conformity assessment (as in Readiness)
  • Building or operating scanners, CI pipelines or SBOM generators — we connect to the ones you have
  • Remediation of vulnerabilities in your products
  • Custom development or data residency changes (contracted separately under Enterprise)
Your responsibilities
  • Integration administrators available during the integration phase
  • Owners assigned for every migrated evidence set
  • Process owners attend the training sessions
  • Sign-off on the handoff checklist
Continues on
Growth plan or Enterprise plan

Optional specialist support

Some questions need expertise the SaaS and the engagements deliberately do not claim. When they come up, this is who answers them and what Vellaci does around it.

Legal and regulatory opinion

When: Scope, classification or reportability calls that need a defensible legal position, or contract review for OEM / white-label arrangements.

Who: Your legal counsel or an independent EU product-regulation law firm; Vellaci provides the recorded facts and reasoning.

Vellaci: Records the decision, the adviser and the rationale in the audit trail.

Conformity assessment and notified body

When: Important (Class I / II) or critical products that need third-party assessment, or harmonised-standard mapping.

Who: A notified body designated under the CRA, or a conformity consultant.

Vellaci: Keeps the technical documentation, evidence and declaration drafts they ask for in one place.

Security testing and PSIRT support

When: Penetration tests, firmware analysis, or surge capacity during an active incident.

Who: Your security team or an independent testing firm; incident retainers with a partner.

Vellaci: Links test reports to products and requirements; runs the reporting workflow during the incident.

Which option is for whom

OptionChoose it whenTypical signalsNext step
Evaluation (free)Technical evaluators who want to see one real product, SBOM and vulnerability match before any conversation.One product, no urgency, security engineer leadingCreate a free workspace
Readiness plan (€490/month)Smaller manufacturers with up to five products establishing CRA processes and Article 14 reporting for the first time.1–5 products, a named compliance owner, Article 14 exposureStart Readiness
Growth plan (€990/month)Manufacturers with multiple products and a security team that needs advanced audit exports and priority support.6–25 products, several owners, auditor accessStart Growth
Enterprise (€1490/month list, contracted)Large portfolios needing SSO, custom retention, governance modules, an implementation partner and negotiated terms.26+ products, SSO required, procurement involvedTalk to sales
Vellaci Readiness (from €4,900, one-time)Teams that must be operational for reporting within weeks: scope, inventory, SBOMs, workflows, runbook, drill and evidence baseline configured with you.Deadline pressure, small team, first CRA programmeRequest Vellaci Readiness
Vellaci Implementation (from €9,500, one-time)Multi-product manufacturers migrating existing evidence, integrating trackers and CI, and standing up product-security processes across teams.Many products, integrations, existing documentation to migrateRequest Vellaci Implementation
Your evidence is never held hostage. If a subscription lapses, the workspace becomes read-only but remains readable and exportable — audit log, evidence, reporting cases and all. A complete organisation export is available at any time on every plan.

FAQ

Commercial questions.

Which option should we start with?
Technical evaluators who want to see their own SBOM matched start with the free Evaluation workspace. Teams that need to be operational for Article 14 reporting in weeks, not quarters, start with the free assessment, a 20-minute readiness review and, in most cases, Vellaci Readiness (from €4,900), which ends with a live workspace on the Readiness or Growth plan.
Can we start self-serve?
Yes. Create a free Evaluation workspace with one product, three seats and the full CRA reporting workflow. Readiness and Growth are activated through Stripe checkout from the billing page; Enterprise is contracted with sales.
How does a one-time implementation connect to the subscription?
Implementation is delivered inside your own workspace with time-bound, logged operator access. When the engagement ends, the same workspace continues on a platform plan; nothing is rebuilt, migrated or re-imported. The platform fee is what keeps SBOM matching, deadline computation, alerts and the audit log running.
What happens if a subscription lapses?
Your workspace becomes read-only but stays readable and exportable — for 30 days and beyond. We never hide your security evidence, and a full organisation export is always available.
Do you charge per SBOM or per seat?
Plans include products, seats and monthly SBOM volume. If you outgrow a limit you can move up a plan at any time; Enterprise contracts set custom limits and can include per-product pricing for large portfolios.
Is annual billing available?
Yes — annual plans include two months free and are activated in the same checkout when the annual toggle is shown; otherwise ask us and we will set it up. Enterprise contracts are typically annual or multi-year.
Are prices final?
List prices are shown excl. VAT and are what Stripe checkout charges. Enterprise and implementation engagements are quoted; volume, multi-year and partner terms are agreed with sales.

Not sure which plan?

The free assessment ends with a Vellaci fit recommendation; the readiness review confirms it with a person.