CRA Clock — S0A demand and economics screen
Prepared 2026-09-18. Claim tsk_20260918031508_1i5q9. Currency USD; cents in screening.json.
Sources read
research/keyword-research-2026-09-07/REPORT.mdandanalysis.json— Google Ads search-volume/ideas pulls for US/UK/DE, retrieved 7–8 Sept 2026, cached, $0.72 of a $10 allowance spent.ventures/cra-clock/research/google-ads/66b130d8918f936f2418914b2acb696cd8fa6b10b5803e8ee391c8c579fcd527.json— a second, more current Google Adskeywords_for_keywords-style pull, US only, retrieved 2026-09-18T03:20:31Z, covering monthly volumes September 2025 → August 2026 (the most recent complete month the API returns; September 2026, the actual deadline month, is not yet in the dataset).ventures/cra-clock/brief.md,venture.json(stage S1 since 2026-09-04, entered by Yuval override before the gate criterion existed),metrics.json(all zero — no qualified exposures, signups, or customers recorded).- European Commission CRA reporting-obligation pages cited in the 7 Sept report: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting, https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation (obligations begin 11 Sept 2026, main obligations 11 Dec 2027).
No new paid API calls were made in this task; the fresh Google Ads file above was already cached in the venture folder when this task started and is used as-is with its recorded retrieval timestamp.
Demand — buyer-language keywords and intent
Head/context terms (US, English, Google Search, avgMonthlySearches = trailing-12-month average unless noted; Aug-2026 = the freshest single month observed):
| Term | Sep-2025 | Aug-2026 (freshest) | Trend over the window | Read |
|---|---|---|---|---|
| cyber resilience act | 1,000 | 1,600 | +60% | Broad awareness/informational, not a purchase signal |
| cra reporting requirements | 30 | 50 | modest rise | Informational ("what do I have to do"), not tool-shopping |
| cra vulnerability reporting | 0 (first non-zero Dec-25) | 20 | rising off a zero base | Closer to buyer language, still tiny |
| cyber resilience act reporting | 0 for 11 of 12 months | 10 | first appearance in Aug-26 only | Too new/small to call a trend |
| enisa reporting platform | 0 for 5 of 12 months | 20 | rising off a zero base | Buyer-adjacent, still tiny |
| cra compliance requirements/checklist | 0 | 10 | flat | Informational |
| cra reporting tool, cra compliance tool, cisa kev monitoring, continuous sbom monitoring, enisa vulnerability reporting, eu software compliance, sbom vulnerability monitoring, vulnerability disclosure software | — | — | no measurable volume in any month, US, all 12 months | These are the terms closest to "I want to buy this exact product." Google Ads reports no data at all, not zero-but-rounded. |
| sbom software | 320 | 110 | declining | Broader tooling category, falling not rising |
| sbom management | 170 | 30 | declining | Same |
| vulnerability management software | 1,600 | 390 | declining | Adjacent category, seasonal/declining, not CRA-driven |
| software composition analysis | 880 | 390 | declining | Same |
| cisa kev (the feed itself) | 2,400 | 2,900 | stable/rising | High baseline, but this is a general threat-intel term used far beyond CRA-obligated manufacturers |
| psirt / dependency-track | 720–880 / 590–720 | 880 / 590 | flat | Existing-workflow and competitor-brand terms, stable — no deadline effect |
The 7 Sept report additionally found Germany at 6,600/month and UK at 1,300/month for the bare term "cyber resilience act," and confirmed provider grouping/anomaly caveats (e.g., a $470 CPC "vpat services" outlier from the sibling venture — not applicable here but a reminder these are noisy estimates, not audited traffic).
Read on the brief's central bet. The brief predicted "an unusually clean read: if vendors are going to panic, they will do it in the fortnight around 11 September 2026." The freshest data we have runs only through August 2026 — the month *before* the deadline — because Google Ads historical volumes lag roughly a month behind real time (today is 2026-09-18, seven days after the deadline). At that last observed point: the broad awareness term is up 60% year-over-year, a handful of exact reporting-intent terms went from zero/near-zero to 10–20/month, and the *exact* tool-purchase phrases ("cra reporting tool," "cra compliance tool," "enisa reporting platform" at any prior month, "cisa kev monitoring") show no measurable search volume at all, even one month out from a hard legal deadline. Several adjacent SBOM/vulnerability-tooling terms actually declined across the same 12 months. This is evidence against, not for, the "deadline forces urgent tool-shopping" hypothesis — but the single most informative data point (actual deadline-week searches, September 2026) is not yet observable in this dataset. Treat this as unresolved, not zero.
Market and acquisition
We still cannot enumerate the reachable buyer population: 20–200 person vendors shipping software/devices onto the EU market with no dedicated security team. No directory, registry, or list-building step has been run for this venture (that would be its own bounded task). Search volume cannot substitute for that count — the 7 Sept report's funnel math already showed a required ≈4,334 equivalent monthly search events at base assumptions to clear a $50K/yr contribution benchmark with 13 active customers; the exact-match reporting-tool phrases here return zero measurable volume, and even the closest buyer-language terms (cra vulnerability reporting, enisa reporting platform, cyber resilience act reporting) sum to roughly 50/month in the US, two orders of magnitude short. Broadening to the awareness term ("cyber resilience act," 1,600/month) closes the volume gap but reintroduces the report's original caveat: those are not qualified buyers, they are people reading about a new law.
Behavioral evidence is still zero. venture.json shows S1 was entered on 2026-09-04 by Yuval override ("gate not passed: no deadline") — i.e., before the S0A screen or a live deadline existed to justify it. metrics.json shows zero qualified exposures, plan selections, deposits, payment intents, or paying customers 14 days later, one week after the deadline passed. No paid traffic, landing page, or manual-fulfillment test has produced a single qualified prospect to date. This screen is not overriding that gap; it is flagging it as the reason S1 cannot yet answer the question the brief assigned it.
Durability
Unresolved by design of this screen — no customer conversation has happened. The brief's own durability hypothesis stands unverified: a manufacturer might buy once to get compliant for the deadline and cancel, rather than pay monthly between exploited-CVE events. dependency-track and psirt hold flat, moderate, non-seasonal volume year-round, which is *consistent with* an ongoing operational workflow existing at some vendors — but says nothing about whether *this* clock-and-paperwork product, rather than free SBOM tooling, earns a recurring subscription.
Economics — conservative / base / optimistic
Carried forward from the 7 Sept 2026 report's scenario model (analysis.json), using the brief's proposed $500/mo price (not approved for display) and unchanged since no new cost or conversion evidence exists:
| Scenario | Monthly service cost | Expected paid lifetime | CAC incl. labor | Lifetime contribution/customer after CAC | Year-one contribution (illustrative) |
|---|---|---|---|---|---|
| Conservative | $180 | 12 mo | $8,200 | −$4,360 | −$90 |
| Base | $100 | 24 mo | $1,350 | +$8,250 | +$504 |
| Optimistic | $50 | 36 mo | $350 | +$15,850 | +$13,536 |
These are the same illustrative assumptions as the prior report — 25/50/75% relevance, 10/25/50% impression share, 3/5/8% CTR, 0.5/2/5% paid conversion, $40/$25/$15 CPC — none of which have been measured against this venture's actual traffic, because no traffic has run. Base scenario needs about 13 active customers for a $50K/yr contribution benchmark (not an approved target), requiring roughly 4,334 monthly search-equivalent events; the exact-match terms observed here return closer to 0–50.
reachableAnnualProspects and acquisitionRate are recorded as null in screening.json. We have neither a credible enumeration of the qualified buyer population nor a measured conversion rate; inventing either would violate the "unknowns stay null" rule and would produce a false sense of resolution.
Decision: REVISE
Why not proceed: the exact buyer-language terms this product depends on ("cra reporting tool," "cra compliance tool," "enisa reporting platform," "cisa kev monitoring") show no measurable search volume even one month before the deadline; several adjacent categories are declining, not growing; and 14 days into S1 there is zero recorded customer behavior. Proceeding on the current evidence would be proceeding on the awareness-term volume alone, which the 7 Sept report already flagged as not a demand signal for a $500/mo reporting-clock service.
Why not stop: the single most decisive data point — actual search and inquiry behavior during and after the 11 Sept 2026 deadline week — is not yet observable in this dataset (Google Ads volumes lag about a month) and could move sharply once it lands, given the brief's stated ordering (a11y-drift was rejected for other reasons, and CRA remains "the most defensible position this portfolio has found" per the 7 Sept report). The domain question the brief itself flagged as load-bearing and unresolved — whether "manufacturer awareness" for CRA purposes can be triggered by a feed timestamp — has still not been checked against ENISA/legal guidance.
The assumption that kills this idea: that a hard legal deadline converts into urgent, findable purchase-intent search behavior from EU manufacturers before software has to exist. Twelve months of data through the month before the deadline do not show that conversion happening at the exact-match level.
Next cheapest behavioral test (do not build, do not spend):
- Re-run the same Google Ads keyword pull once September/October 2026 data is available (roughly late October 2026) to see whether "cra reporting tool," "cyber resilience act reporting," and "enisa reporting platform" actually spiked in the deadline week — this costs one cached-comparable API call, not new spend.
- Separately and cheaply, build a short enumerated list (LinkedIn company search, an EU manufacturer/hardware directory, or CE-marking registries) of a credible reachable population of 20–200-person EU-market manufacturers without a dedicated security function, to replace the null
reachableAnnualProspectswith an evidenced count rather than an assumption. - Only after both land: revisit whether the S1 registered-exposure test (a real priced offer to a qualified visitor) is worth authorizing, and at what price — this screen does not approve $500/mo for display.