CRAnotify Documentation

What CRAnotify is

CRAnotify is a compliance cockpit for the reporting obligations of Article 14 of the Cyber Resilience Act (Regulation (EU) 2024/2847). It takes an event — a reported vulnerability, a detected incident — and carries it along a traced path: qualification, verdict, pre-filled notification, manual filing on the ENISA platform, with an immutable registry of every decision and when it was taken.

The problem it solves

Art. 14 imposes very short deadlines: 24 hours for the early warning from the moment the manufacturer becomes aware of an actively exploited vulnerability or a serious incident, 72 hours for the update, then a final report. In practice the hard part is not filing: it is reaching the filing with a defensible decision and with proof that it was taken in time. Three things must be done well, under pressure:

  • Qualify the event — exploited vulnerability or serious incident? Is the precondition of the obligation actually met?
  • Date the awareness, because the deadline runs from there and not from when somebody finally noticed.
  • Document the reasoning, because in an inspection what counts is being able to show how you decided, not only what you decided.

CRAnotify holds the three together in one path, with a clock that does not stop and an append-only registry whose alterations are detectable.

What it does

Collects reportsFrom a public form you embed in your own site, or entered by hand by whoever receives them by email or internally.
Qualifies the eventA three-step triage, with the options modelled on the text of the Regulation and an explicit decision table.
Computes the deadlinesA clock anchored to the moment of awareness, with reminders at 16, 4 and 1 hour before expiry.
Pre-fills the notificationThe part determined by the engine (legal basis, type of communication, recipients) is already written; the facts are yours.
Accompanies the filingPrerequisites, a link to the platform, and the receipt issued by ENISA stored as evidence.
Preserves the evidenceA registry with a verifiable hash chain, and a printable defence dossier per case.

What it does not do

It does not file on your behalf. Transmission to the ENISA Single Reporting Platform and to the CSIRT is an act of the manufacturer and goes through your institutional credentials. CRAnotify prepares the content, takes you to the platform, and records the outcome when you upload the receipt.

  • It does not give legal advice. The engine reproduces the structure of Art. 14; responsibility for the qualification stays with whoever signs it.
  • It does not decide for you in doubtful cases. When the elements are insufficient, the verdict is «suspended» with a re-check reminder: an honest state beats an invented answer.
  • It does not scan for vulnerabilities. It connects to the tools you already use for the bill of materials (see SBOM), but it is not a scanner.

Who it is for

The manufacturer of products with digital elements within the scope of the Regulation: whoever places software or connected devices on the Union market under their own name or trademark. Inside the company, three roles typically use it, matching the configurable roles:

WhoWhat they do in CRAnotifyTypical role
Security / product leadQualifies events, runs the triage, prepares the notification and files it.Administrator or Assessor
Engineering teamReceives reports, verifies exploitation, maintains the product register.Assessor
Legal / complianceWatches the deadlines, consults the registry, produces the defence dossier.Read-only (with dedicated escalation)

When the obligations start

The reporting obligations of Art. 14 apply from 11 September 2026; the Regulation's essential requirements follow later. That means the first thing to have ready is not product conformity but the ability to report within 24 hours: escalation chain, intake channel, qualification procedure. That is exactly what this product sets up.

Good practice. Before that date, run at least one fake event end to end in exercise mode. A cold rehearsal reveals the gaps — wrong addresses, unreachable contacts, platform credentials never activated — while finding them is still cheap.

Next step

If you have no account yet: Creating the account and the organisation. If you do: Initial setup.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu