EU Cyber Resilience ActArticle 14applies from 11 September 2026
Are you in scope for the CRA 24-hour reporting duty, and could you actually report in time?
From 11 September 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers of products with digital elements to report an actively exploited vulnerability or a severe incident affecting product security to ENISA and their coordinating CSIRT: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report later. The clock starts at awareness, and it covers products you already shipped, not only new ones. Penalties reach €15 million or 2.5% of worldwide turnover.
This is a free 3-minute self-check. Answer honestly; it computes entirely in your browser and nothing you enter leaves your machine. It is informational, not legal advice.
1. Are you in scope?
2. Could you meet the obligation today?
Rate each capability. "Partial" means it exists but is informal, undocumented, or untested.
Your CRA Article 14 readiness
reporting readiness
Share your result
Copy a one-line summary (no answers, no data, just the score) to post or send to your team.
Close the gaps before the clock starts on you
Free: the moment you become aware of an exploited vulnerability, you need the three deadlines and pre-filled drafts in seconds, not a spreadsheet. Open the free browser deadline & notification tool → It computes the 24h / 72h / 14d dates, drafts the early warning and 72h notification, and exports a CSAF 2.0 advisory, entirely on your machine.
The paid setup service is paused. The tools on this site are free and open source (MIT). Questions: open an issue.