OpenAI 2026 hackathon

CRA Evidence OS

CRA Evidence OS turns scattered security documents into cited, review-ready CRA evidence for small EU software and device manufacturers using GPT-5.6.

Solo project by Dalibor Gobeljić · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #3,559 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

Company: CRA Evidence OS

Self-reported basis: The description is entirely self-reported and unverified, based on a Devpost submission for the OpenAI 2026 hackathon. No external corroboration exists.

What it appears to be: A vertical MVP tool for small EU manufacturers to prepare security evidence under the EU Cyber Resilience Act (CRA), using GPT-5.6 for structured evidence suggestions and deterministic logic for evidence management.

What changed: The project evolved from a hackathon prototype into a focused product with defined workflows, AI integration, and human review layers.

Single most important open question: Does the author’s self-reported vision of CRA Evidence OS align with a viable commercial product that can scale beyond a synthetic demo?

Back to contents

What The Product Actually Is

The description states that CRA Evidence OS is a documentation and evidence workspace for small EU software, IoT, and industrial-equipment manufacturers. It supports workflows including:

  • Evidence Review (using GPT-5.6 to convert technical sources into structured, cited suggestions)
  • Human Approval (suggestions remain untrusted until reviewed)
  • Evidence Graph (approved claims are connected to sources, versions, components, and controls)
  • SBOM Impact (deterministic logic identifies stale evidence when components change)
  • Incident Draft (assembles approved facts into 24/72-hour reporting records)
  • Dossier Export (prepares traceable records for professional review)

The system is built with Next.js, React, TypeScript, and uses GPT-5.6 for language reasoning tasks only — not for final compliance decisions.

It does not claim to certify CRA compliance, but rather to help teams prepare, connect, review, and maintain required evidence.

Inference: The product is a vertical MVP focused on a specific regulatory domain (CRA) and use case (evidence preparation), with AI as an assistant layer and deterministic logic for governance.

Back to contents

Positioning & Claim Evolution

The description states that the project was inspired by the EU Cyber Resilience Act, which requires manufacturers to report incidents within 24–72 hours. The team asked:

“Can AI help a small manufacturer maintain review-ready security evidence without pretending to replace security experts, legal advisers, or conformity assessors?”

This question evolved into CRA Evidence OS — a tool that does not claim to replace compliance experts, but instead supports them by structuring evidence and automating parts of the documentation process.

The product is positioned as:

  • A human-reviewed evidence preparation tool
  • Not a compliance chatbot
  • Not a universal document ingestion system
  • Not legal advice or a conformity assessment

Inference: The positioning is clear — it’s a supportive, not authoritative, tool for compliance documentation. It emphasizes transparency and traceability over automation.

Back to contents

Target Customer & ICP

The description states that CRA Evidence OS targets:

  • Small EU software, IoT, and industrial-equipment manufacturers
  • Those needing to comply with the EU Cyber Resilience Act (CRA)

It is designed for teams that must prepare review-ready security evidence, not for large enterprises or non-EU manufacturers.

Inference: The ICP is narrow — small-to-medium-sized EU manufacturers in regulated sectors, with a focus on compliance documentation and incident reporting under CRA.

Back to contents

Business Model & Pricing Evidence

Not evidenced.

The description does not mention any pricing model, monetization strategy, or business model.

Back to contents

Technical & Delivery Signals

The system is built using:

  • Next.js, React, TypeScript
  • GPT-5.6 for structured language reasoning
  • OpenAI Responses API
  • Structured schemas, deterministic logic for state transitions and impact detection
  • Server-side handling of secrets and citations
  • Model outputs validated against strict schemas

Key technical decisions include:

  • Separating AI reasoning from deterministic logic
  • Requiring human approval before evidence becomes “approved”
  • Preserving unknown facts instead of allowing the model to invent them
  • Using Codex for architecture, interface, API integration, testing, and deployment

Inference: The product is built with a strong emphasis on security boundaries, traceability, and human-in-the-loop governance. It avoids AI overreach by design.

Back to contents

Traction & Maturity Signals

Not evidenced.

The description does not mention any revenue, customers, usage metrics, or adoption data beyond the synthetic demo and hackathon submission.

Back to contents

Competitive Context

Not evidenced.

No information is provided about competitors, market size, or competitive positioning beyond the self-reported use case.

Back to contents

Key Risks & Red Flags

  • Unverified claims: The description is entirely self-reported and unverified.
  • No commercial traction: No evidence of revenue, customers, or usage beyond a demo.
  • AI dependency risk: Reliance on GPT-5.6 for structured output may not scale without human oversight.
  • Limited scope: The MVP is described as a “controlled synthetic vertical slice,” not a full product.
  • Regulatory complexity: CRA compliance is highly complex; the tool does not claim to replace experts, but its utility in real-world use remains unproven.

Back to contents

Diligence Questions To Ask The Founders

  1. What specific EU regulations or standards does this tool support beyond CRA?
  2. How does the system handle multi-tenant access control and data isolation in a production environment?
  3. Are there any plans to integrate with existing SBOM tools (e.g., SPDX, CycloneDX)?
  4. What is the current level of human involvement required for evidence preparation vs. AI-assisted tasks?
  5. Has the team tested the tool with real manufacturers or compliance teams?
  6. How does the system ensure that model outputs are not misused as final compliance decisions?
  7. What are the key assumptions about user behavior and adoption in a real-world setting?

Back to contents

Investment/Partnership Verdict

Not evidenced.

No financial data, funding history, or commercial traction is provided to assess viability for investment or partnership.

The description indicates that CRA Evidence OS is a self-contained MVP built during a hackathon, with a clear vision and strong product design. However, it lacks any evidence of:

  • Revenue
  • Customers
  • Market traction
  • Commercial scalability

It is not possible to determine whether this is a viable commercial opportunity or a promising prototype.

Inference: The project shows potential in a niche regulatory domain, but its current status is that of a proof-of-concept. It would require further development, testing, and market validation before it could be considered for investment or partnership.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.