EU Cyber Resilience ActArticle 14free browser tool

CRA Article 14 Deadline & Notification Assistant

From 11 September 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) obliges manufacturers to report an actively exploited vulnerability with an early warning within 24 hours of becoming aware, a detailed notification within 72 hours, and a final report within 14 days of a corrective measure becoming available. This page computes those three deadlines from the moment you enter, drafts the three notifications, and builds a CSAF 2.0 skeleton you can download.

Everything below runs 100% in your browser. This page makes no network calls, loads no third-party script or font, sets no cookies and has no backend. What you type here — product name, vulnerability identifier, dates — never leaves your machine. That is the same promise the command-line tool cra-clock.mjs makes; this page is its browser companion.

Difference from the CLI: this page does not keep a persistent, tamper-evident hash-chained log across visits — closing the tab forgets everything, on purpose, because nothing is stored. For a real audit trail that survives reboots and proves nothing was edited after the fact, download cra-clock.mjs and run it on your machine (see README.md).

First time here, or not sure this applies to you? Take the free 3-minute readiness check → to confirm your scope and see whether you could actually report in 24 hours, then come back here when you have an event to time.

1. When did you become aware?

Enter times in UTC (the same convention ENISA's Single Reporting Platform and the CLI tool use). The 24h and 72h deadlines start here.

2. Your three deadlines

Enter an awareness moment above to see your deadlines.

3. Notification details

These fill the drafts below and the CSAF export. Anything left blank is marked <<FILL>> in the draft text so you cannot accidentally submit a gap.

What and who
CSAF 2.0 publisher identity only needed for the CSAF download

4. Draft notifications

Copy the one you need. Every draft says it is not legal advice and that this tool submits nothing — that line is not decorative, it is the point.

5. CSAF 2.0 advisory

A CSAF 2.0 (csaf_security_advisory) skeleton built from the fields above, with the OASIS-mandatory fields checked before download. A publisher name and namespace are required — the file is not generated without them, on purpose: a CSAF advisory with a made-up publisher is worse than no advisory.

What this page does not do

This page gives you the deadlines and the paperwork skeleton. It does not run a dry-run with your team, does not fill in your CSAF publisher identity for you, and does not check your real notification before you submit it.

The paid setup service is paused. The tools on this site are free and open source (MIT). Questions and bug reports: open an issue.