EU Cyber Resilience ActArticle 14applies from 11 September 2026

Finland: Traficom / NCSC-FI reporting route for CRA Article 14 →

When the regulator asks "when exactly did you become aware?", you will have one defensible answer, not a Slack scroll-back.

From 11 September 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers of products with digital elements to report an actively exploited vulnerability to ENISA and their coordinating CSIRT with an early warning within 24 hours, a detailed notification within 72 hours and a final report within 14 days of a corrective measure becoming available. The clock starts at awareness, not at confirmation, and the obligation covers products you already shipped, not only new ones.

CRA 24h Clock is a small command-line tool that runs on your machine. It records the moment of awareness, computes the three deadlines, produces pre-filled notification drafts and a CSAF 2.0 advisory, and keeps a hash-chained evidence log in which every submission is marked exactly once. Your vulnerability data never leaves your computer.

Try the free browser tool → No terminal, no install: enter your awareness moment and get the same 24h / 72h / 14d deadlines, draft notifications and a CSAF 2.0 download, entirely in your browser. No evidence-chain log across visits though — for that, use the CLI below.

Not sure if this even applies to you? Take the free 3-minute readiness check → It tells you whether you are in scope, which obligations bind you, and scores whether you could actually report in 24 hours. Runs in your browser; nothing you enter leaves your machine.

Run it right now

node cra-clock.mjs deadlines --aware 2026-09-11T08:00:00Z
Awareness began: 2026-09-11T08:00:00.000Z
   24 h  2026-09-12T08:00:00.000Z  Early warning to ENISA and the coordinating CSIRT
   72 h  2026-09-14T08:00:00.000Z  More detailed assessment, corrective measures
  336 h  not yet computable (earliest 2026-09-25T08:00:00.000Z, starts when remediation is available)  Final report. The deadline starts only when a corrective measure is available, so it cannot be computed yet.

Look at the third line. The tool refuses to give you a final-report date it cannot know. Article 14 ties that deadline to the moment a corrective measure becomes available, not to the moment you became aware. Until you record that moment, the deadline does not exist, and a tool that prints one anyway is inventing evidence you may later have to defend.

Record it and the clock starts:

node cra-clock.mjs deadlines --aware 2026-09-11T08:00:00Z --remediation 2026-10-01T08:00:00Z
Awareness began: 2026-09-11T08:00:00.000Z
Remediation available: 2026-10-01T08:00:00.000Z
   24 h  2026-09-12T08:00:00.000Z  Early warning to ENISA and the coordinating CSIRT
   72 h  2026-09-14T08:00:00.000Z  More detailed assessment, corrective measures
  336 h  2026-10-15T08:00:00.000Z  Final report after a corrective measure became available

The first two deadlines do not move. The third one does, because the regulation says so.

Requires Node.js 18+. No install step, no network access, no account.

Why a regulator-proof log, not a form-filler

After an incident, a market surveillance authority asks three questions, and all three are questions of evidence:

  1. When exactly did you become aware? The 24-hour clock runs from that moment.
  2. Who decided this was active exploitation? A name, not a committee.
  3. Was the notification submitted exactly once? ENISA's Single Reporting Platform is a manual web form with no public API, so retries and duplicates are a human problem.

CRA 24h Clock is built so that each of those questions has a one-command answer.

What it does

CommandWhat you get
awareRecords the awareness moment, the source and the person who made the call. Appends to a hash-chained log.
deadlinesThe 24 h / 72 h / 14 d deadlines from any awareness timestamp. Pure function: same input, same output, every time.
draftPre-filled notification drafts for each stage, with every field the regulation expects marked either filled or <<FILL>>.
submittedMarks a stage as submitted with your SRP reference, exactly once. A second attempt for the same stage is refused with a non-zero exit code, not silently absorbed.
csafA CSAF 2.0 advisory (OASIS mandatory fields validated) generated from the recorded event.
statusEvery open event, its deadlines, what is submitted, what is overdue.
verifyRe-computes the whole hash chain. If any line of the log was edited after the fact, including by us, it names the changed line and exits non-zero.

What it does not have

A competitor sells all four of those. If you need a hosted compliance suite, buy theirs. Genuinely. What their product page does not state is where your vulnerability data is hosted, and their audit trail is rows in their database. Which brings us to the two things this tool has that a hosted suite cannot give you:

It also does not:

Verify our claims yourself

Every factual claim on this page about the tool's behaviour is covered by a test you can run:

ClaimVerify with
Same awareness moment always produces the same three deadlines node cra-clock.mjs deadlines --aware 2026-09-11T08:00:00Z (run it twice)
A submission cannot be recorded twice; tampering with the log is detected; drafts carry the awareness moment; CSAF output has all OASIS-mandatory fields node cra-clock.test.mjs, 52 assertions, plain Node, no test framework
The tool makes no network calls grep -En "require\(.(https?|net|dgram|tls).\)|from 'node:(https?|net|dgram|tls)'|fetch\(" cra-clock.mjs csaf.mjs, zero matches

The tool is free

CRA 24h Clock itself costs nothing and has no licence fee. Download it, run it, keep it. There is no account, no activation and no phone-home, so there is nothing we could charge you for switching off.

The paid setup service is paused. The tool on this page is free and open source (MIT). Questions and bug reports: open an issue.

Read a sample CRA24 Watch bulletin (September 2026) →

Terms of service

License. CRA 24h Clock is released under the MIT licence. No fee is charged for the software, there is no licence to renew, and nothing about your use of it depends on being a customer. The software is provided as is, without warranty of any kind. The full text ships in the LICENSE file alongside the source.

No legal advice. CRA 24h Clock is an evidence and deadline tool. It is not legal advice, and using it does not by itself make you compliant with Regulation (EU) 2024/2847. You remain solely responsible for the content, accuracy and timely submission of your notifications.

Liability. To the maximum extent permitted by law, no liability is accepted for missed regulatory deadlines, fines or third-party claims.

Governing law. These terms are governed by the law of the Republic of Cyprus.

Privacy

This page sets no cookies, loads no third-party resources and runs no analytics or tracking scripts.

The tool runs entirely on your machine, sends no telemetry and makes no network connections. Your vulnerability data is never transmitted to us or anyone else by this software.