The Cyber Resilience Act's Article 14 reporting duty goes live: when you become aware of an actively exploited vulnerability or a severe incident in your product, an early warning must reach ENISA and your national CSIRT within 24 hours — filed manually, on a form, by a named human with an EU Login. This free drill simulates that moment and scores whether you'd make it.
Part 1 — does the duty apply to you? Part 2 — a simulated incident, 12 questions. Honest answers only; the score is for you, not for us.
1/3 — Do you make a product that is or contains software (an app, device, firmware, SaaS-adjacent product, library sold commercially)?
2/3 — Is it made available on the EU market (sold, licensed, or offered to EU customers)?
3/3 — In the course of a commercial activity (not a pure hobby / unmonetised open-source project)?
Everything the drill says you're missing, pre-built. Not theory — working files your team fills in during the real 24 hours.
Editable files (open in Word/Excel/Google Docs). Explicitly not legal advice — built for engineering and ops teams to execute, with counsel reviewing.
No — this is the part that surprises people. The reporting duty applies from 11 September 2026 to products with digital elements already on the EU market, even though most other CRA obligations only bite from December 2027. If it's still in use and you learn of an actively exploited vulnerability, the clock runs.
Under Article 14(5): an incident that negatively affects — or could affect — your product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data, or that enables the introduction or execution of malicious code. Routine bugs and ordinary patches are out of scope.
Through ENISA's Single Reporting Platform, simultaneously to ENISA and to the CSIRT designated as coordinator for you (normally the Member State of your main EU establishment). The platform is scheduled to be operational by 11 September 2026; submission is a manual form — there is no API.
Article 14 sits in the CRA's penalty regime, with administrative fines that can reach millions of euros depending on the breach — and non-compliance is visible: your CSIRT knows whether you filed. The bigger operational risk is scrambling: a missed 24-hour window is not recoverable after the fact.
No. The drill runs entirely in your browser; answers never leave your machine. The exported report is generated locally.
No. This is an educational readiness exercise built from the regulation text and official guidance (linked below). Scope and obligations should be confirmed with qualified counsel.
More free tools: CRA reporting deadline calculator · printable Article 14 checklist · security.txt generator