1. Assess the incident
Answer focused questions about the occurrence, exploitation or severity, EU availability, awareness time and your role.
Answer a short assessment. Get the likely reporting path, exact statutory deadlines, missing-information checklist and staged report pack, without uploading incident details to us.
Instead of interpreting the workflow under pressure, move through one guided sequence that turns incident facts into deadlines, required fields and staged reporting copy.
Answer focused questions about the occurrence, exploitation or severity, EU availability, awareness time and your role.
We map your answers to the relevant CRA workflow and show whether specialist review is still needed before you rely on the result.
Get exact deadlines, complete each reporting stage, catch missing core information, and export clean copy for the official SRP.
Calculate the 24-hour and 72-hour milestones from your awareness time, with final-report timing that adapts to the reporting path.
Turn a vague “are we ready?” into a concrete list of core information that still needs to be gathered for each stage.
Prepare readable report copy, Markdown and JSON locally, then transfer the final content into the official ENISA workflow.
Use separate preparation flows for actively exploited vulnerabilities and severe incidents instead of forcing both into a generic incident template.
Your draft autosaves in local browser storage, so you can return without creating a cloud workspace or sending incident details to us.
Export a structured JSON backup when you need to move the working file deliberately between devices.
Security incidents can contain the exact details you least want copied into another vendor’s cloud. CRA Report is designed so your narrative, product details, mitigations and draft reports can remain on your device.
Regulatory workflows change. CRA Report is designed to be maintained against the Regulation, European Commission guidance and ENISA’s latest SRP documentation.
Use the reporting library for the regulatory question. Use the incident assessment when the answer needs to become a timeline and report pack.
The full Article 14 timeline from first awareness through the final report.
Read guide → GuideWhen the first clock starts and what to prepare for the initial reporting stage.
Read guide → GuideWhat the fuller vulnerability or incident notification needs to cover.
Read guide → GuideHow the official submission system fits into the reporting workflow.
Read guide →CRA Report turns the facts you already have into a structured CRA incident workflow. It helps you identify the likely reporting path, calculate the 24-hour and 72-hour timeline, spot missing information, and prepare staged content for ENISA’s Single Reporting Platform. It does not submit notifications on your behalf.
No. Incident details stay in your browser. Drafts are stored locally on your device and report generation happens client-side, so sensitive incident content does not need to become another cloud dataset.
No. Classification assistance, deadlines, field checks and report templates use deterministic rules. Your incident descriptions are not sent to an AI model or external processing API.
The CRA reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. Manufacturers report through ENISA’s Single Reporting Platform.
No. CRA Report is a preparation and workflow tool. Confirm applicability and final submission content against the Regulation, current ENISA guidance, and qualified counsel where appropriate.
Answer the assessment now. See the likely reporting path first, then decide whether to unlock the complete €59 incident pack.