CRA Article 14 · Private by design

When a CRA incident hits, the reporting clock may already be running.

Answer a short assessment. Get the likely reporting path, exact statutory deadlines, missing-information checklist and staged report pack, without uploading incident details to us.

No account No AI processing No incident database
Your CRA Incident Pack
EU · Article 14
Early Warningexact deadline + draft
Notificationrequired fields + draft
Final Reportpath-specific workflow
Local Backupportable incident record
LOCAL PROCESSING: ON INCIDENT UPLOADS: 0
Built around Regulation (EU) 2024/2847 and ENISA’s Single Reporting Platform guidance.
From uncertainty to next action

Know what to prepare before you open ENISA’s portal.

Instead of interpreting the workflow under pressure, move through one guided sequence that turns incident facts into deadlines, required fields and staged reporting copy.

1. Assess the incident

Answer focused questions about the occurrence, exploitation or severity, EU availability, awareness time and your role.

2. See your reporting path

We map your answers to the relevant CRA workflow and show whether specialist review is still needed before you rely on the result.

3. Unlock and finish the pack

Get exact deadlines, complete each reporting stage, catch missing core information, and export clean copy for the official SRP.

Built for incident pressure

Reduce uncertainty before it steals your response time.

24h

Know the clock

Calculate the 24-hour and 72-hour milestones from your awareness time, with final-report timing that adapts to the reporting path.

See what is still missing

Turn a vague “are we ready?” into a concrete list of core information that still needs to be gathered for each stage.

Move faster at submission

Prepare readable report copy, Markdown and JSON locally, then transfer the final content into the official ENISA workflow.

EU

Follow the right path

Use separate preparation flows for actively exploited vulnerabilities and severe incidents instead of forcing both into a generic incident template.

Pick up where you left off

Your draft autosaves in local browser storage, so you can return without creating a cloud workspace or sending incident details to us.

Keep a portable backup

Export a structured JSON backup when you need to move the working file deliberately between devices.

Private by architecture

Your incident stays your incident.

Security incidents can contain the exact details you least want copied into another vendor’s cloud. CRA Report is designed so your narrative, product details, mitigations and draft reports can remain on your device.

No accountStart without creating a profile, workspace or password.
No AI processingYour incident text is not sent to an LLM or prompt API.
No incident databaseDrafts live in local browser storage instead of our cloud.
Local report generationTemplates and exports are assembled on your device.
Primary sources, not compliance folklore.

Regulatory workflows change. CRA Report is designed to be maintained against the Regulation, European Commission guidance and ENISA’s latest SRP documentation.

FAQ

Before you start.

What does CRA Report do?

CRA Report turns the facts you already have into a structured CRA incident workflow. It helps you identify the likely reporting path, calculate the 24-hour and 72-hour timeline, spot missing information, and prepare staged content for ENISA’s Single Reporting Platform. It does not submit notifications on your behalf.

Does CRA Report upload incident information?

No. Incident details stay in your browser. Drafts are stored locally on your device and report generation happens client-side, so sensitive incident content does not need to become another cloud dataset.

Does it use AI?

No. Classification assistance, deadlines, field checks and report templates use deterministic rules. Your incident descriptions are not sent to an AI model or external processing API.

When do CRA incident-reporting duties start?

The CRA reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. Manufacturers report through ENISA’s Single Reporting Platform.

Is CRA Report legal advice?

No. CRA Report is a preparation and workflow tool. Confirm applicability and final submission content against the Regulation, current ENISA guidance, and qualified counsel where appropriate.

If the clock is running, uncertainty is expensive.

Answer the assessment now. See the likely reporting path first, then decide whether to unlock the complete €59 incident pack.

Assess my incident