CRAnotify documentation
The user manual for the Cyber Resilience Act compliance cockpit (Reg. (EU) 2024/2847). Here you will find the complete flow — from the report received to the filing on the ENISA platform — the rules by which the engine decides, how evidence is preserved, and everything about accounts, subscription and integrations.
Where to start
On a first visit, three pages are enough to be operational: create the organisation, complete the initial setup and read the flow at a glance. If instead a report has just arrived and time is short, go straight to Guided triage: the first thing to fix is the moment of awareness, because the 24 hours run from there.
Getting started
What CRAnotify is, how to create the organisation, and what to configure on day one.
Compliance flow
From the report received to the filing on the ENISA platform, step by step.
Registry and evidence
The activity registry, its integrity, the defence dossier, and reconstruction as of a date.
Products and bill of materials
The register of products with digital elements, the bill of materials, VEX assessments, controls, technical documentation and upstream suppliers.
Reporting channel
The public form to embed in your site and its anti-abuse defences.
Alerts and communications
Transactional email, the clock's reminders, and chat channels.
Account and administration
Users, security, subscription, API, personal data, exercise mode.
Reference
Glossary, states, address map and troubleshooting.
Conventions used here
The manual describes the software as it behaves today, not as we would like it to behave. Where the Regulation and the application use different words for the same thing, the translation is given in the glossary.
codeAddresses, field names and exact values to type.Notice. CRAnotify supports compliance work. It does not replace legal advice and it does not file on your behalf: the report to the ENISA single platform and to the CSIRT remains an act of the manufacturer. The assessments the engine proposes reconstruct the scheme of Art. 14 and must be confirmed by whoever carries responsibility for compliance.