Pricing
Priced for manufacturers, delivered with implementation.
Start free with one product, subscribe when you are ready, and add an implementation engagement if you want your workspace configured with you. Every plan includes SBOM ingestion, vulnerability intelligence, the CRA Reporting Command Center, evidence and audit log. Prices excl. VAT.
Evaluation
Explore Vellaci with one product.
1 product · 3 seats · 10 SBOMs/month · 10-year retention
- 1 product
- 3 seats
- SBOM ingestion and vulnerability matching
- CRA reporting workflow
Readiness
For smaller manufacturers establishing CRA processes.
5 products · 10 seats · 200 SBOMs/month · 10-year retention
- Up to 5 products
- 10 seats
- GitHub integration
- Vulnerability intelligence (OSV, KEV, EPSS)
- CRA Reporting Command Center
- Evidence vault and readiness framework
- PDF/CSV/ZIP reports
or talk to us
Growth
Most chosenFor multiple products and security teams.
25 products · 30 seats · 2,000 SBOMs/month · 12-year retention
- Up to 25 products
- 30 seats
- Everything in Readiness
- Advanced audit exports
- Priority support
or talk to us
Enterprise
Advanced governance, SSO, integrations and support.
Custom products, seats and SBOM volume
- Unlimited products
- Enterprise SSO (SAML)
- Custom retention
- Implementation partner
- Custom contracts
SaaS subscription
Recurring compliance operations: the workspace, continuous SBOM matching, server-computed deadlines, evidence vault, audit log, exports. Monthly or annual, per plan below.
Implementation engagement
Initial setup, migration, inventory, workflow definition, documentation structure and onboarding, delivered by Vellaci operators inside your workspace. Deliverables, prerequisites, timeline and exclusions are listed for each package.
Specialist support
Legal, conformity-assessment or security-testing expertise outside the SaaS, delivered by your advisers or independent partners. Vellaci coordinates and records; it never substitutes.
What each plan includes
The same questions a procurement or security review asks, answered per plan. Limits are enforced in the product; everything else is included, not an add-on.
| Question | Evaluationfree | Readiness€490/month | Growth€990/month | Enterprise€1490/month list |
|---|---|---|---|---|
| Who it is for | Technical evaluators proving the workflow on one real product before any conversation. | Smaller manufacturers (1–5 products) establishing CRA processes and Article 14 reporting for the first time. | Manufacturers with multiple products (6–25) and a security team that needs governance across owners. | Large portfolios (26+ products) with SSO, procurement and negotiated terms. |
| Product limits | 1 product | Up to 5 products, unlimited versions | Up to 25 products | Custom (unlimited by default) |
| Team access | 3 seats · owner, admin, member roles | 10 seats · seven roles incl. external advisers | 30 seats · custom fields, saved views, bulk actions | Custom seats · SAML/OIDC SSO · enforced MFA · SCIM prepared |
| SBOM ingestion | 10 SBOMs/month · upload, API, CLI, GitHub | 200 SBOMs/month · upload, API, CLI, GitHub, GitLab | 2,000 SBOMs/month · CI ingestion · SBOM diff · release gates | Custom volume · partner and CI pipelines |
| Vulnerability monitoring | OSV, GitHub advisories, CISA KEV, EPSS · continuous re-matching | OSV, GitHub advisories, KEV, EPSS · exploitation signals · explainable priority | Everything in Readiness · per-organisation priority weights · policies with violations | Everything in Growth · two-person approvals · custom retention of intelligence |
| Incident workflow | Full incident and CRA reporting workflow (24h / 72h / final) | Incidents, reportability review, reporting cases with server-computed deadlines, drills | Everything in Readiness · Jira / Linear / Slack / Teams / PagerDuty routing | Everything in Growth · continuity sheet · partner portal |
| Evidence retention | 10-year retention · checksummed vault | 10-year retention · classification · legal hold | 12-year retention · retention policies · scheduled reports | 15-year retention · custom residency options on request |
| Reporting | PDF / CSV / ZIP exports | Executive reports · submission-ready notifications · VEX | Everything in Readiness · scheduled and auditor packages | Everything in Growth · contract reporting |
| Audit support | Hash-chained audit log · organisation export | Audit log · auditor read-only access · signed exports | Advanced audit exports · auditor mode · access reviews | Enterprise security review under NDA · questionnaire · SOC 2 readiness mapping |
| Support level | Documentation and e-mail | E-mail, next business day · optional implementation engagement | Priority e-mail · quarterly readiness check-in | Named contact · implementation partner · custom SLA in contract |
Implementation packages
One-time engagements delivered by Vellaci operators with time-bound, logged access to your workspace. Quoted per engagement; indicative fees below. The engagement ends with a live workspace that continues on a platform plan — nothing is rebuilt or migrated.
Vellaci Readiness
from €4,900 one-timeTeams with a small portfolio (1–5 products) that must be operational for Article 14 reporting within weeks.
- Deliverables
- Preliminary CRA scope assessment recorded per product with reasoning
- Product registry with owners, lifecycle, classification and support period
- A valid SBOM matched for every supported version
- Vulnerability triage workflow with owners, reasons and SLAs
- Incident process owners and awareness rule
- CRA reporting runbook: assigned representative, ENISA platform access, contacts
- One 24h / 72h reporting drill run and filed as evidence
- Evidence baseline uploaded, classified and linked to requirements
- Team invited with roles; MFA policy decided
- Readiness review against the requirement framework with named owners for open gaps
- Prerequisites
- A decision-maker and a technical contact available for two 60-minute sessions per week
- Product list with versions and, where they exist, SBOMs or repository access
- Existing policies, test reports and risk assessments (any format)
- Someone able to obtain ENISA Single Reporting Platform access for the organisation
- Timeline
- Four to six weeks depending on portfolio size and your team's availability; the plan and its progress are visible in your workspace from day one.
- Not included
- Legal opinions on scope, classification or reportability
- Conformity assessment, notified-body engagement, CE marking
- Penetration testing or security testing of your products
- Writing your technical documentation for you (we structure it; your engineers fill it)
- Migration of historical evidence beyond the baseline (see Implementation)
- Your responsibilities
- Decide scope, classification and awareness rule (Vellaci records the decision and the reasoning)
- Provide SBOMs or repository access
- Name the assigned representative and deputies
- Attend the drill and the readiness review
- Continues on
- Readiness plan or Growth plan
Vellaci Implementation
from €9,500 one-timeMulti-product manufacturers (typically 6–25 products) migrating existing evidence, integrating trackers and CI, and standing up product-security processes across teams.
- Deliverables
- Everything in Vellaci Readiness, across the whole portfolio
- GitHub / GitLab connected and repositories linked to products; CI SBOM upload configured
- Jira / Linear linked for remediation tasks; Slack / Teams / PagerDuty routing for critical deadlines and exploited vulnerabilities
- Existing evidence migrated, classified and linked to requirements
- Policies and templates configured (triage, disclosure, remediation SLAs, retention)
- Technical documentation workspace per product with Annex VII sections
- Product-security process documentation and training for every role
- Handoff with documented open items and an operational runbook
- Prerequisites
- Everything required for Readiness
- Administrative access to the repository host, tracker and chat tools to be integrated
- An inventory of existing evidence with owners
- A product-security or compliance lead who will own the processes after handoff
- Timeline
- Six to ten weeks depending on the number of products, integrations and the volume of evidence to migrate.
- Not included
- Legal opinions and conformity assessment (as in Readiness)
- Building or operating scanners, CI pipelines or SBOM generators — we connect to the ones you have
- Remediation of vulnerabilities in your products
- Custom development or data residency changes (contracted separately under Enterprise)
- Your responsibilities
- Integration administrators available during the integration phase
- Owners assigned for every migrated evidence set
- Process owners attend the training sessions
- Sign-off on the handoff checklist
- Continues on
- Growth plan or Enterprise plan
Optional specialist support
Some questions need expertise the SaaS and the engagements deliberately do not claim. When they come up, this is who answers them and what Vellaci does around it.
Legal and regulatory opinion
When: Scope, classification or reportability calls that need a defensible legal position, or contract review for OEM / white-label arrangements.
Who: Your legal counsel or an independent EU product-regulation law firm; Vellaci provides the recorded facts and reasoning.
Vellaci: Records the decision, the adviser and the rationale in the audit trail.
Conformity assessment and notified body
When: Important (Class I / II) or critical products that need third-party assessment, or harmonised-standard mapping.
Who: A notified body designated under the CRA, or a conformity consultant.
Vellaci: Keeps the technical documentation, evidence and declaration drafts they ask for in one place.
Security testing and PSIRT support
When: Penetration tests, firmware analysis, or surge capacity during an active incident.
Who: Your security team or an independent testing firm; incident retainers with a partner.
Vellaci: Links test reports to products and requirements; runs the reporting workflow during the incident.
Which option is for whom
| Option | Choose it when | Typical signals | Next step |
|---|---|---|---|
| Evaluation (free) | Technical evaluators who want to see one real product, SBOM and vulnerability match before any conversation. | One product, no urgency, security engineer leading | Create a free workspace |
| Readiness plan (€490/month) | Smaller manufacturers with up to five products establishing CRA processes and Article 14 reporting for the first time. | 1–5 products, a named compliance owner, Article 14 exposure | Start Readiness |
| Growth plan (€990/month) | Manufacturers with multiple products and a security team that needs advanced audit exports and priority support. | 6–25 products, several owners, auditor access | Start Growth |
| Enterprise (€1490/month list, contracted) | Large portfolios needing SSO, custom retention, governance modules, an implementation partner and negotiated terms. | 26+ products, SSO required, procurement involved | Talk to sales |
| Vellaci Readiness (from €4,900, one-time) | Teams that must be operational for reporting within weeks: scope, inventory, SBOMs, workflows, runbook, drill and evidence baseline configured with you. | Deadline pressure, small team, first CRA programme | Request Vellaci Readiness |
| Vellaci Implementation (from €9,500, one-time) | Multi-product manufacturers migrating existing evidence, integrating trackers and CI, and standing up product-security processes across teams. | Many products, integrations, existing documentation to migrate | Request Vellaci Implementation |
FAQ
Commercial questions.
- Which option should we start with?
- Technical evaluators who want to see their own SBOM matched start with the free Evaluation workspace. Teams that need to be operational for Article 14 reporting in weeks, not quarters, start with the free assessment, a 20-minute readiness review and, in most cases, Vellaci Readiness (from €4,900), which ends with a live workspace on the Readiness or Growth plan.
- Can we start self-serve?
- Yes. Create a free Evaluation workspace with one product, three seats and the full CRA reporting workflow. Readiness and Growth are activated through Stripe checkout from the billing page; Enterprise is contracted with sales.
- How does a one-time implementation connect to the subscription?
- Implementation is delivered inside your own workspace with time-bound, logged operator access. When the engagement ends, the same workspace continues on a platform plan; nothing is rebuilt, migrated or re-imported. The platform fee is what keeps SBOM matching, deadline computation, alerts and the audit log running.
- What happens if a subscription lapses?
- Your workspace becomes read-only but stays readable and exportable — for 30 days and beyond. We never hide your security evidence, and a full organisation export is always available.
- Do you charge per SBOM or per seat?
- Plans include products, seats and monthly SBOM volume. If you outgrow a limit you can move up a plan at any time; Enterprise contracts set custom limits and can include per-product pricing for large portfolios.
- Is annual billing available?
- Yes — annual plans include two months free and are activated in the same checkout when the annual toggle is shown; otherwise ask us and we will set it up. Enterprise contracts are typically annual or multi-year.
- Are prices final?
- List prices are shown excl. VAT and are what Stripe checkout charges. Enterprise and implementation engagements are quoted; volume, multi-year and partner terms are agreed with sales.
Read next
- Guide
CRA readiness checklist for software and connected-product manufacturers
A practical CRA checklist across governance, SBOM, vulnerability handling, disclosure, incidents, reporting, support period and documentation, with evidence to keep and current transition milestones.
- Docs
Your first 15 minutes
From sign-up to the first vulnerable component.
- Docs
Roles and permissions
Owner, admin, security, compliance, engineer, auditor, external advisor.
Not sure which plan?
The free assessment ends with a Vellaci fit recommendation; the readiness review confirms it with a person.