Free tool
CRA reporting deadlines
Enter when you became aware of an actively exploited vulnerability or a severe incident. You get the three Article 14 deadlines, what each report must contain, and a calendar file.
Also part of it
- Submit through the single reporting platform. It reaches the CSIRT designated as coordinator in the Member State of your main establishment and ENISA at the same time.
- Inform affected users, and where appropriate all users, about the vulnerability or incident and what they can do, in a timely manner (Article 14(8)).
- If the vulnerability is in a third-party component, tell the person or organisation that maintains it (Article 13(6)).
- Record when you became aware and what you decided, and why. Every deadline starts from that moment.
A planning aid, not legal advice. The deadlines are calculated in your browser, in your local time zone; nothing you enter is sent anywhere.
Be ready before the clock starts
The first 24 hours are easily lost finding out who decides, which template to use and where to submit. Our planned package sets up the roles, triage, the reporting playbook and an exercise against the clock.
Get in touch
Work out what the CRA actually asks of your product
Send us the product category and target markets. We will map the likely CRA class, the conformity assessment route that follows from it, and where the Annex I obligations will bite hardest for what you build.
We reply within two working days.
Full contact detailsOpens our scheduling page in a new tab — pick a slot that suits you.
Worth including in a first message
- What the product is, and whether it contains software or connects to a network.
- Which markets you sell into, and your role — manufacturer, importer, or distributor.
- Whether the product is already on the market or not yet released.
Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.