What CRAnotify is
CRAnotify is a compliance cockpit for the reporting obligations of Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847). It takes an event — a reported vulnerability, a detected incident — and carries it along a traced path: qualification, verdict, pre-filled notification, manual filing on the ENISA platform, with an immutable registry of every decision and when it was taken.
The problem it solves
Art. 14 imposes very short deadlines: 24 hours for the early warning from the moment the manufacturer becomes aware of an actively exploited vulnerability or a serious incident, 72 hours for the update, then a final report. In practice the hard part is not filing: it is reaching the filing with a defensible decision and with proof that it was taken in time. Three things must be done well, under pressure:
- Qualify the event — exploited vulnerability or serious incident? Is the precondition of the obligation actually met?
- Date the awareness, because the deadline runs from there and not from when somebody finally noticed.
- Document the reasoning, because in an inspection what counts is being able to show how you decided, not only what you decided.
CRAnotify holds the three together in one path, with a clock that does not stop and an append-only registry whose alterations are detectable.
What it does
What it does not do
It does not file on your behalf. Transmission to the ENISA Single Reporting Platform and to the CSIRT is an act of the manufacturer and goes through your institutional credentials. CRAnotify prepares the content, takes you to the platform, and records the outcome when you upload the receipt.
- It does not give legal advice. The engine reproduces the structure of Art. 14; responsibility for the qualification stays with whoever signs it.
- It does not decide for you in doubtful cases. When the elements are insufficient, the verdict is «suspended» with a re-check reminder: an honest state beats an invented answer.
- It does not scan for vulnerabilities. It connects to the tools you already use for the bill of materials (see SBOM), but it is not a scanner.
Who it is for
The manufacturer of products with digital elements within the scope of the Regulation: whoever places software or connected devices on the Union market under their own name or trademark. Inside the company, three roles typically use it, matching the configurable roles:
| Who | What they do in CRAnotify | Typical role |
|---|---|---|
| Security / product lead | Qualifies events, runs the triage, prepares the notification and files it. | Administrator or Assessor |
| Engineering team | Receives reports, verifies exploitation, maintains the product register. | Assessor |
| Legal / compliance | Watches the deadlines, consults the registry, produces the defence dossier. | Read-only (with dedicated escalation) |
When the obligations start
The reporting obligations of Art. 14 apply from 11 September 2026; the Regulation's essential requirements follow later. That means the first thing to have ready is not product conformity but the ability to report within 24 hours: escalation chain, intake channel, qualification procedure. That is exactly what this product sets up.
Good practice. Before that date, run at least one fake event end to end in exercise mode. A cold rehearsal reveals the gaps — wrong addresses, unreachable contacts, platform credentials never activated — while finding them is still cheap.
Next step
If you have no account yet: Creating the account and the organisation. If you do: Initial setup.