On 11 September 2026 the EU starts a stopwatch.
You get 24 hours.

The Cyber Resilience Act's Article 14 reporting duty goes live: when you become aware of an actively exploited vulnerability or a severe incident in your product, an early warning must reach ENISA and your national CSIRT within 24 hours — filed manually, on a form, by a named human with an EU Login. This free drill simulates that moment and scores whether you'd make it.

Start the 7-minute drill

Runs 100% in your browser Nothing uploaded, no signup Based on Regulation (EU) 2024/2847

The drill

Part 1 — does the duty apply to you? Part 2 — a simulated incident, 12 questions. Honest answers only; the score is for you, not for us.

Part 1 · Scope triage

1/3 — Do you make a product that is or contains software (an app, device, firmware, SaaS-adjacent product, library sold commercially)?

Article 14 Reporting Operations Pack

Everything the drill says you're missing, pre-built. Not theory — working files your team fills in during the real 24 hours.

$99 one-time · instant download · 30-day refund
  • 24-hour early-warning working files — vulnerability and incident variants, fields matching the notification content required by Article 14
  • 72-hour notification working files — both variants, with prompts for the exploit description, measures taken, and user mitigations
  • Final report working files — 14-day (vulnerability) and 1-month (incident) versions
  • Incident clock workbook — awareness timestamping guidance + deadline tracker
  • Escalation & RACI sheet — who declares awareness, who drafts, who submits, who informs users
  • Evidence log template — the timestamped trail that proves you filed in time
  • Executive brief + customer notice templates — Article 14(8) user-information duty covered
  • security.txt & disclosure-policy generator — plus a completed example
  • One tabletop scenario with a fully completed example run — rehearse before 11 September

Editable files (open in Word/Excel/Google Docs). Explicitly not legal advice — built for engineering and ops teams to execute, with counsel reviewing.

FAQ

My product shipped years ago. Am I off the hook?

No — this is the part that surprises people. The reporting duty applies from 11 September 2026 to products with digital elements already on the EU market, even though most other CRA obligations only bite from December 2027. If it's still in use and you learn of an actively exploited vulnerability, the clock runs.

What exactly counts as a "severe incident"?

Under Article 14(5): an incident that negatively affects — or could affect — your product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data, or that enables the introduction or execution of malicious code. Routine bugs and ordinary patches are out of scope.

Where do the reports go?

Through ENISA's Single Reporting Platform, simultaneously to ENISA and to the CSIRT designated as coordinator for you (normally the Member State of your main EU establishment). The platform is scheduled to be operational by 11 September 2026; submission is a manual form — there is no API.

What happens if I don't report?

Article 14 sits in the CRA's penalty regime, with administrative fines that can reach millions of euros depending on the breach — and non-compliance is visible: your CSIRT knows whether you filed. The bigger operational risk is scrambling: a missed 24-hour window is not recoverable after the fact.

Is any of my data collected by this site?

No. The drill runs entirely in your browser; answers never leave your machine. The exported report is generated locally.

Is this legal advice?

No. This is an educational readiness exercise built from the regulation text and official guidance (linked below). Scope and obligations should be confirmed with qualified counsel.

More free tools: CRA reporting deadline calculator · printable Article 14 checklist · security.txt generator

Sources: Regulation (EU) 2024/2847 (Cyber Resilience Act) · European Commission — CRA reporting obligations · ENISA — Single Reporting Platform. This site is independent and not affiliated with the EU, ENISA, or any CSIRT. Educational material, not legal advice.