That is the Cyber Resilience Act's Article 14 reporting duty. The moment someone at your company understands that a vulnerability in your product is being actively exploited, or that a severe incident has hit it, the clock starts. An early warning has to reach ENISA and your national CSIRT within a day, filed by hand on a form by a named human with an EU Login.
We built two free things to help: a short drill that shows you where you would stall, and a step-by-step assistant for when it is actually happening.
Start the 7-minute drill I'm working an incident now
Three ways in, depending on what today looks like.
Twelve questions and a simulated 02:14 incident. You get a score, your gaps, and a report to take to your team.
Run the drillThe assistant walks you through scope, tracks, awareness time and routing, then writes your 24-hour early warning field by field.
Open the assistantGive it your awareness time and it returns every Article 14 deadline in UTC, ready to paste into your incident channel.
Open the calculatorTwo parts, about seven minutes. First we check whether the duty reaches you at all. Then we run a simulated incident and score whether you could file in time. Answer honestly: the score is for you, and nobody else ever sees it.
Question 1 of 3
Do you make a product that is, or contains, software?
An app, a device with firmware, a connected product, a library you sell commercially.
Question 2 of 3
Is it available on the EU market?
Sold, licensed, or otherwise offered to customers in the EU.
Question 3 of 3
In the course of a commercial activity?
A pure hobby project or an unmonetised open-source release is not.
Everything the drill says you are missing, already built. These are working files your team fills in during the real 24 hours, not a theory deck.
Every document comes as .docx (Word or Google Docs) and print-ready .html. The evidence log and incident clock are .xlsx (Excel or Sheets). This is not legal advice: it is built for engineering and operations teams to execute, with your counsel reviewing.
Before you buy, have a look at the Terms, the Privacy Notice and the Refund Policy. Sold by our merchant of record, who handles payment and any applicable taxes. Questions first? Write to hello@cradrill.com and a human will answer.
No, and this is the part that surprises people. Article 69(2) grandfathers products placed on the market before 11 December 2027 unless they are substantially modified. Article 69(3) then carves straight back out of that: "by way of derogation from paragraph 2 … the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027." So the reporting duty reaches your installed base from 11 September 2026, even where the rest of the CRA does not. If the product is in scope and you learn of an actively exploited vulnerability, the clock runs.
Article 14(5) gives two limbs. An incident that negatively affects, or is capable of affecting, your product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions. Or one that has led, or could lead, to malicious code being introduced into the product or into a user's systems. The "or functions" half is easy to miss: an incident that compromises critical functionality counts even if no sensitive data was touched. Routine bugs and ordinary patches are out of scope. "Actively exploited vulnerability" has its own separate definition in Article 3(42), and it requires reliable evidence that a malicious actor exploited it without the system owner's permission, so an authorised researcher's proof-of-concept does not qualify.
Through ENISA's Single Reporting Platform, simultaneously to ENISA and to the CSIRT designated as your coordinator (normally the Member State of your main EU establishment). The platform is scheduled to be operational by 11 September 2026. Submission is a manual form and there is no API.
Article 14 sits in the CRA's highest penalty tier. Article 64 puts failures of the Article 13 and 14 obligations, alongside the Annex I essential requirements, at administrative fines of up to €15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher. Member States set the actual regime and are directed to weigh the size and resources of the offender, so small companies are not treated like large ones, but the tier is the severe one. The blunter operational risk is simpler: a missed 24-hour window cannot be recovered afterwards, and your CSIRT knows whether you filed.
No. The drill runs entirely in your browser and your answers never leave your machine. The exported report is generated locally. The reporting assistant at /app/ goes further and loads no third-party scripts at all, which you can verify with your browser's network tab.
No. This is an educational readiness exercise built from the regulation text and the official guidance linked below. Confirm your scope and obligations with qualified counsel.
More free tools: the reporting deadline calculator, a printable Article 14 checklist, a security.txt generator, and our scan of 623 European vendors.