Skip to main content

CRA Compliance Tool integration — shared workspace and SSO

The CRA risk-assessment and technical-documentation workflow is built into CVD Portal under Compliance → Products (https://cvdportal.com/products); see the Products workspace guide. This page covers the legacy integration for users of the standalone PortaRegulus CRA Compliance Tool, which could sync products into CVD Portal and open it through a sign-in handoff.

The standalone app has been retired and app.cra.portaregulus.com now redirects to https://cvdportal.com/cra, so there is nothing left to hand off from. What remains is the shared workspace that handoff created, described below. Sign in directly at https://cvdportal.com.

If you arrived from the CRA Compliance Tool

The sign-in handoff placed you in one of two accounts, and that is still where your data sits.

  • First-time users joined a shared integration workspace as a read-only Member. The header chip shows "Member · read-only". You can view submissions and their details, but changing status, severity, or settings requires a workspace admin.
  • If your email address already had its own CVD Portal account, you were signed into that account instead. Your own workspace does not contain the products or reports you saw in the CRA app. Those live in the separate shared integration workspace.

Shared-workspace users see a CRA Portal link at the bottom of the sidebar. It opens the CRA compliance front door at https://cvdportal.com/cra, in place of the old link back to the standalone app.

Products you did not create

Products in the shared workspace's hardware registry are synced from CRA app registrations. Each carries the CRA app's product id as its identifier, which keeps reports linked to the right product even after renames.

Where reports live

Vulnerability reports are called submissions here. See them under Submissions (https://cvdportal.com/submissions). The CRA app's Vulnerability Disclosure page, which showed the same reports filtered to one product, went away with the app.

You see only the reports filed against the products your account claims, not every report in the shared workspace. That applies everywhere, including direct API calls, so a report on another company's product returns "not found" rather than its contents.

What the shared workspace does not include

Compliance → Products is not available to shared-workspace accounts. Because several companies share this one workspace and its product records carry no per-account owner, opening that surface would show each of them the others' risk assessments, Annex I checklists, declarations of conformity and technical files. It is closed rather than filtered, and a plan upgrade does not open it.

The shared workspace covers vulnerability intake and triage. For CRA self-assessment work, use an account of your own at https://cvdportal.com/products, which is a workspace only your company is in.