MYSWE Research
SOURCE REPORT

← CRA Clock

CRA Clock — S0A demand and economics screen

Prepared 2026-09-18. Claim tsk_20260918031508_1i5q9. Currency USD; cents in screening.json.

Sources read

  • research/keyword-research-2026-09-07/REPORT.md and analysis.json — Google Ads search-volume/ideas pulls for US/UK/DE, retrieved 7–8 Sept 2026, cached, $0.72 of a $10 allowance spent.
  • ventures/cra-clock/research/google-ads/66b130d8918f936f2418914b2acb696cd8fa6b10b5803e8ee391c8c579fcd527.json — a second, more current Google Ads keywords_for_keywords-style pull, US only, retrieved 2026-09-18T03:20:31Z, covering monthly volumes September 2025 → August 2026 (the most recent complete month the API returns; September 2026, the actual deadline month, is not yet in the dataset).
  • ventures/cra-clock/brief.md, venture.json (stage S1 since 2026-09-04, entered by Yuval override before the gate criterion existed), metrics.json (all zero — no qualified exposures, signups, or customers recorded).
  • European Commission CRA reporting-obligation pages cited in the 7 Sept report: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting, https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation (obligations begin 11 Sept 2026, main obligations 11 Dec 2027).

No new paid API calls were made in this task; the fresh Google Ads file above was already cached in the venture folder when this task started and is used as-is with its recorded retrieval timestamp.

Demand — buyer-language keywords and intent

Head/context terms (US, English, Google Search, avgMonthlySearches = trailing-12-month average unless noted; Aug-2026 = the freshest single month observed):

TermSep-2025Aug-2026 (freshest)Trend over the windowRead
cyber resilience act1,0001,600+60%Broad awareness/informational, not a purchase signal
cra reporting requirements3050modest riseInformational ("what do I have to do"), not tool-shopping
cra vulnerability reporting0 (first non-zero Dec-25)20rising off a zero baseCloser to buyer language, still tiny
cyber resilience act reporting0 for 11 of 12 months10first appearance in Aug-26 onlyToo new/small to call a trend
enisa reporting platform0 for 5 of 12 months20rising off a zero baseBuyer-adjacent, still tiny
cra compliance requirements/checklist010flatInformational
cra reporting tool, cra compliance tool, cisa kev monitoring, continuous sbom monitoring, enisa vulnerability reporting, eu software compliance, sbom vulnerability monitoring, vulnerability disclosure softwareno measurable volume in any month, US, all 12 monthsThese are the terms closest to "I want to buy this exact product." Google Ads reports no data at all, not zero-but-rounded.
sbom software320110decliningBroader tooling category, falling not rising
sbom management17030decliningSame
vulnerability management software1,600390decliningAdjacent category, seasonal/declining, not CRA-driven
software composition analysis880390decliningSame
cisa kev (the feed itself)2,4002,900stable/risingHigh baseline, but this is a general threat-intel term used far beyond CRA-obligated manufacturers
psirt / dependency-track720–880 / 590–720880 / 590flatExisting-workflow and competitor-brand terms, stable — no deadline effect

The 7 Sept report additionally found Germany at 6,600/month and UK at 1,300/month for the bare term "cyber resilience act," and confirmed provider grouping/anomaly caveats (e.g., a $470 CPC "vpat services" outlier from the sibling venture — not applicable here but a reminder these are noisy estimates, not audited traffic).

Read on the brief's central bet. The brief predicted "an unusually clean read: if vendors are going to panic, they will do it in the fortnight around 11 September 2026." The freshest data we have runs only through August 2026 — the month *before* the deadline — because Google Ads historical volumes lag roughly a month behind real time (today is 2026-09-18, seven days after the deadline). At that last observed point: the broad awareness term is up 60% year-over-year, a handful of exact reporting-intent terms went from zero/near-zero to 10–20/month, and the *exact* tool-purchase phrases ("cra reporting tool," "cra compliance tool," "enisa reporting platform" at any prior month, "cisa kev monitoring") show no measurable search volume at all, even one month out from a hard legal deadline. Several adjacent SBOM/vulnerability-tooling terms actually declined across the same 12 months. This is evidence against, not for, the "deadline forces urgent tool-shopping" hypothesis — but the single most informative data point (actual deadline-week searches, September 2026) is not yet observable in this dataset. Treat this as unresolved, not zero.

Market and acquisition

We still cannot enumerate the reachable buyer population: 20–200 person vendors shipping software/devices onto the EU market with no dedicated security team. No directory, registry, or list-building step has been run for this venture (that would be its own bounded task). Search volume cannot substitute for that count — the 7 Sept report's funnel math already showed a required ≈4,334 equivalent monthly search events at base assumptions to clear a $50K/yr contribution benchmark with 13 active customers; the exact-match reporting-tool phrases here return zero measurable volume, and even the closest buyer-language terms (cra vulnerability reporting, enisa reporting platform, cyber resilience act reporting) sum to roughly 50/month in the US, two orders of magnitude short. Broadening to the awareness term ("cyber resilience act," 1,600/month) closes the volume gap but reintroduces the report's original caveat: those are not qualified buyers, they are people reading about a new law.

Behavioral evidence is still zero. venture.json shows S1 was entered on 2026-09-04 by Yuval override ("gate not passed: no deadline") — i.e., before the S0A screen or a live deadline existed to justify it. metrics.json shows zero qualified exposures, plan selections, deposits, payment intents, or paying customers 14 days later, one week after the deadline passed. No paid traffic, landing page, or manual-fulfillment test has produced a single qualified prospect to date. This screen is not overriding that gap; it is flagging it as the reason S1 cannot yet answer the question the brief assigned it.

Durability

Unresolved by design of this screen — no customer conversation has happened. The brief's own durability hypothesis stands unverified: a manufacturer might buy once to get compliant for the deadline and cancel, rather than pay monthly between exploited-CVE events. dependency-track and psirt hold flat, moderate, non-seasonal volume year-round, which is *consistent with* an ongoing operational workflow existing at some vendors — but says nothing about whether *this* clock-and-paperwork product, rather than free SBOM tooling, earns a recurring subscription.

Economics — conservative / base / optimistic

Carried forward from the 7 Sept 2026 report's scenario model (analysis.json), using the brief's proposed $500/mo price (not approved for display) and unchanged since no new cost or conversion evidence exists:

ScenarioMonthly service costExpected paid lifetimeCAC incl. laborLifetime contribution/customer after CACYear-one contribution (illustrative)
Conservative$18012 mo$8,200−$4,360−$90
Base$10024 mo$1,350+$8,250+$504
Optimistic$5036 mo$350+$15,850+$13,536

These are the same illustrative assumptions as the prior report — 25/50/75% relevance, 10/25/50% impression share, 3/5/8% CTR, 0.5/2/5% paid conversion, $40/$25/$15 CPC — none of which have been measured against this venture's actual traffic, because no traffic has run. Base scenario needs about 13 active customers for a $50K/yr contribution benchmark (not an approved target), requiring roughly 4,334 monthly search-equivalent events; the exact-match terms observed here return closer to 0–50.

reachableAnnualProspects and acquisitionRate are recorded as null in screening.json. We have neither a credible enumeration of the qualified buyer population nor a measured conversion rate; inventing either would violate the "unknowns stay null" rule and would produce a false sense of resolution.

Decision: REVISE

Why not proceed: the exact buyer-language terms this product depends on ("cra reporting tool," "cra compliance tool," "enisa reporting platform," "cisa kev monitoring") show no measurable search volume even one month before the deadline; several adjacent categories are declining, not growing; and 14 days into S1 there is zero recorded customer behavior. Proceeding on the current evidence would be proceeding on the awareness-term volume alone, which the 7 Sept report already flagged as not a demand signal for a $500/mo reporting-clock service.

Why not stop: the single most decisive data point — actual search and inquiry behavior during and after the 11 Sept 2026 deadline week — is not yet observable in this dataset (Google Ads volumes lag about a month) and could move sharply once it lands, given the brief's stated ordering (a11y-drift was rejected for other reasons, and CRA remains "the most defensible position this portfolio has found" per the 7 Sept report). The domain question the brief itself flagged as load-bearing and unresolved — whether "manufacturer awareness" for CRA purposes can be triggered by a feed timestamp — has still not been checked against ENISA/legal guidance.

The assumption that kills this idea: that a hard legal deadline converts into urgent, findable purchase-intent search behavior from EU manufacturers before software has to exist. Twelve months of data through the month before the deadline do not show that conversion happening at the exact-match level.

Next cheapest behavioral test (do not build, do not spend):

  • Re-run the same Google Ads keyword pull once September/October 2026 data is available (roughly late October 2026) to see whether "cra reporting tool," "cyber resilience act reporting," and "enisa reporting platform" actually spiked in the deadline week — this costs one cached-comparable API call, not new spend.
  • Separately and cheaply, build a short enumerated list (LinkedIn company search, an EU manufacturer/hardware directory, or CE-marking registries) of a credible reachable population of 20–200-person EU-market manufacturers without a dedicated security function, to replace the null reachableAnnualProspects with an evidenced count rather than an assumption.
  • Only after both land: revisit whether the S1 registered-exposure test (a real priced offer to a qualified visitor) is worth authorizing, and at what price — this screen does not approve $500/mo for display.

Original file: ventures/cra-clock/screening.md. Figures reflect the report's preparation date; later updates may be in newer source files.