Booking and reservation platforms handle personal data (names, emails, phone numbers, payment details) and operate in a high-availability environment where downtime means lost revenue for your clients. Article 13 of Regulation (EU) 2024/2847 requires the manufacturer to produce technical documentation, assess cybersecurity risks — including data confidentiality and system availability per Annex I — and declare conformity. CRACheck generates the 8-document dossier in 15-25 minutes for €149. The mobile app, the embeddable widget, and the cloud engine are documented as one regulated product.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
You enter your product data. CRACheck structures the documentation per Article 31 + Annex VII.
You developed the widget. You are the manufacturer under Article 3(13). The widget is software placed on the EU market when your client embeds it in their website. Your client embeds it; you manufactured it. Documentation obligations rest with the manufacturer.
If your platform distributes any installable or embeddable code — a mobile app, a JavaScript widget, an API client — that code is a product with digital elements under Article 3(1). The "service" framing does not create a CRA exemption when downloadable components exist.
PCI DSS governs cardholder data environments. CRA governs product cybersecurity documentation, risk assessment, and conformity declaration. Different scope, different deliverables. PCI DSS does not produce an Article 31 technical dossier.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Default classification confirmation for booking platform software.
Art. 31 + Annex VII: mobile app, embeddable widget, cloud booking engine, payment integrations, and calendar API connections.
Booking-specific: payment fraud, reservation tampering, personal data exposure through widget, API rate limiting, and availability threats during peak booking periods.
Annex II for business clients and consumers: security properties, data handling, update policy, and incident contact.
Art. 28 + Annex V.
Vulnerability disclosure policy for booking platform: widget security reports, API vulnerability reports, payment handling issues.
ENISA template per Article 14 for booking platform incidents. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.
CRA milestones and platform support period.
Mira antes de comprar — Descargar dossier de muestra (PDF, empresa ficticia) — Estructura real, artículos reales, formato real. Datos ficticios.
Generated from your data, in your browser. No data leaves your device.
Generates CRA documentation for your booking platform covering all components: mobile app, widget, API, and cloud engine.
Does not test your payment processing. Does not audit your widget security. Does not verify PCI DSS compliance. Does not load-test your booking engine.
CRACheck documents. Your engineering validates. Both needed.
Article 64 of Regulation (EU) 2024/2847.
Non-compliance with essential requirements or manufacturer obligations.
Missing documentation or conformity assessment.
Misleading information to authorities.
| Criteria | Hospitality tech consultant | Generic CRA consultant | DIY | CRACheck |
|---|---|---|---|---|
| Time | 6-12 weeks | 8-16 weeks | Weeks | 15-25 minutes |
| Cost | €10,000-€20,000 | €10,000-€20,000 | Staff hours | €149 |
| Covers app + widget + cloud | If briefed | Partially | If capable | Yes |
| CRA-specific output | Custom report | Custom report | DIY | 8 PDFs |
Hotel booking engine, restaurant reservation module, event ticketing system — each separately marketed product needs its own dossier. Volume: 10 at €99, 30 at €79.
Request Volume PricingCRACheck generates a structured document according to Article 31 and Annex VII of Regulation (EU) 2024/2847 from the information you provide. The accuracy of that information is your responsibility as the manufacturer.
We guarantee document structure follows Article 31 + Annex VII and legal references are correct.
CRACheck is not legal advice.
Eight documents. Article 31 + Annex VII fully structured. Regulation (EU) 2024/2847. Your data stays on your device. The ZIP you download is yours forever.