≤ 24h — early warning
An actively exploited vulnerability, or a severe incident affecting your product's security, gets a minimal first notification. Partial information is expected — silence is not.
Everyone is preparing for the Cyber Resilience Act's 2027 requirements. The reporting duty starts earlier: from 11 September 2026, an actively exploited vulnerability in your product must reach ENISA and your national CSIRT within 24 hours of you becoming aware of it.
until Article 14 reporting obligations apply
Built on Regulation (EU) 2024/2847 and the Commission's CRA reporting guidance. An operations toolkit, not legal advice.
The clock starts when you become aware — which may be a Saturday night, from a stranger's email. If the person who reads that email doesn't know a duty exists, the deadline is already gone.
An actively exploited vulnerability, or a severe incident affecting your product's security, gets a minimal first notification. Partial information is expected — silence is not.
Nature of the vulnerability or incident, affected versions, mitigations available, indicators of compromise where you have them.
After a corrective measure is available (vulnerabilities), or within a month (severe incidents): root cause, fix, remediation status.
Your 24 hours run from awareness. Hearing it from a researcher on Tuesday beats reading it on social media on Friday. Generate a valid security.txt (RFC 9116) and a coordinated disclosure policy in one minute. No signup, nothing leaves your browser — a coordinated disclosure policy is also mandatory in the CRA's 2027 phase, so this is a free head start.
Serve security.txt at https://yourdomain/.well-known/security.txt as text/plain. The Expires field is mandatory under RFC 9116 — we set it 12 months out, so put a calendar reminder to refresh it.
The generator opens the channel. The Kit is what happens when a report arrives: is this even reportable, who decides, what exactly gets filed, and what proves you did it on time.
Consultancies sell CRA readiness as a custom engagement with a quote on request. This is the opposite: a fixed price, downloaded now, run by your own team the same day.
€99, whole company, all products. No scoping call, no rate card on request, no "contact sales" — you see the price before you decide.
Download, read, and wire the intake channel and runbook yourself. Time-to-ready is an afternoon, not a multi-week engagement.
Written for the software house without a compliance department — the segment consultancies price out. Plain operations, not a framework to learn.
Its essential requirements, CE marking and conformity assessment are — 11 December 2027. The reporting obligations under Article 14 start on 11 September 2026, more than a year earlier. That gap is the whole reason this kit exists.
Probably not for the CRA — cloud services largely sit under NIS2 instead. The trap is remote data processing that is part of a product you ship: the backend your app or device needs to work comes into scope with the product. The kit's scope check walks this properly, and tells you when the answer is "no".
Evidence of real-world exploitation — observed attacks, exploitation confirmed in the wild, a credible report of in-the-wild abuse. Not a CVE with no known exploitation, not a pentest finding, not a theoretical proof of concept. Awareness of exploitation starts the clock, not awareness of the bug.
File the early warning. It is deliberately minimal, it is not an admission of fault, and the duty is triggered by awareness. Regulators penalise silence, not caution — the runbook makes this the default so nobody has to make a judgement call at 2am.
No. It's an operations toolkit built on the regulation and the Commission's reporting guidance. For classification edge cases, ask counsel — with this in hand you'll be asking a €300 question instead of commissioning a project.
EU AI Act Article 50 lands first: AI interactions disclosed in the interface, AI-generated content labelled. Free widget, same one-afternoon approach.