Get hired atCRACI×The Anti Job Board

CRACI

Continuous software supply chain compliance for the EU Cyber Resilience Act

4 open rolesPre-Seed · €1.4M<50 peopleHelsinki, Finland

Last verified August 15, 2026 · Updated daily

What CRACI is building

CRACI is a CI-integrated software supply chain platform that does three things the CRA requires and that no existing tool does together. First, it generates provably complete SBOMs (Software Bills of Materials) by building a continuously updated graph of every component, dependency, and transitive dependency across every product in your portfolio. Not a snapshot at build time. A live graph that updates as releases ship and as new vulnerabilities emerge against versions still in the field. Second, when a CVE drops, CRACI traces it upward through the graph to every affected product and release line, so the engineering team knows exactly what is exposed, in which version, across which products, within minutes rather than weeks. Third, it files the required ENISA vulnerability report automatically, before the CRA's 24-hour reporting clock runs out. The product positioning is precise: CRACI is your CI. Compliance ships with every build. The SBOM history is archived for as long as needed, covering the CRA's 10-year documentation retention requirement. Vulnerability handling lives in pull requests and issue trackers, not in a parallel compliance queue that engineers ignore. Hamina Wireless is already building with the platform.

Why this matters

The CRA comes into force in September 2026. From that date, every product with digital elements sold in the EU must meet a new cybersecurity baseline: proactive vulnerability handling, mandatory SBOM documentation, 24-hour reporting to ENISA when an actively exploited vulnerability is discovered, and 10 years of technical documentation retention after a product hits the market. The scope is enormous: over 600,000 companies worldwide are in scope. The penalty for non-compliance is loss of EU market access. The existing toolset is not adequate for this. Development-time scanners miss transitive dependencies that were clean at build but are not anymore. Manual compliance processes running on spreadsheets and Confluence pages work until a CVE drops at 11pm on a Friday and someone has 24 hours to file a report. The gap is not awareness. Every CISO CRACI has spoken to knows the deadline. What they do not have is the tooling that closes the loop from build to compliance without adding another manual process to their team's workflow. CRACI is building that tooling with a September 2026 hard deadline that makes every day of delay a commercial opportunity. Juho's founder quote is the product thesis compressed: "Those relying on manual approaches risk delays and higher costs." The CRA makes that risk explicit and financial, not just operational.

Investors: Lifeline Ventures (lead, Juha Lindfors), First Fellow Partners, Wave Ventures, Angel: Lucas Käldström (Upbound, cloud-native open-source veteran)

Open roles at CRACI

4 positions we're tracking. Roles are re-checked daily and removed when filled.

Platform / Security Engineer

Helsinki, Finland·Mid-level

First seen 2 months ago

Apply →

Compliance Automation / Policy Engineer

Helsinki, Finland·Mid-level

First seen 2 months ago

Apply →

Enterprise Sales / Customer Success (Nordic)

Helsinki, Finland·Mid-level

First seen 2 months ago

Apply →

Developer Relations / Technical Content

Helsinki, Finland·Mid-level

First seen 2 months ago

Apply →

Hiring outlook

Very High. Fresh capital, 13 people, a hard regulatory deadline 4 months away, and a careers page that says "No open positions at the moment. Check back soon." That is not a company that is done hiring. That is a company that has not opened the door yet. The September 2026 CRA deadline is the clock. Every enterprise customer conversation CRACI has between now and then is a sales and engineering workload multiplier.

Hiring intensity: 8/8

Working at CRACI

Founded in , CRACI is Continuous software supply chain compliance for the EU Cyber Resilience Act. They're now <50 people. Working at a AI company at this stage means broad remit, direct access to founders, and equity that still means something if the company works out.

The majority of roles are in Helsinki, Finland.

Frequently asked questions

How many jobs does CRACI have open?

As of May 2026, CRACI has 4 open positions.

Does CRACI hire remotely?

No remote roles right now — all positions are in Helsinki, Finland.

What roles is CRACI hiring for?

CRACI is hiring across Engineering, Sales. The most recent opening is Platform / Security Engineer.

How do I apply for a job at CRACI?

Use the apply links above, or check our guide to getting hired at CRACI.

Where is CRACI based?

CRACI is headquartered in Helsinki, Finland.

Get CRACI roles before they're posted

We track AI companies like CRACI daily and surface roles before they reach the job boards. Fewer applicants, faster replies, real hiring managers.

Get early access →

Related