Free · nothing leaves your browser

On 11 September 2026 the EU starts a stopwatch.
You get 24 hours.

That is the Cyber Resilience Act's Article 14 reporting duty. The moment someone at your company understands that a vulnerability in your product is being actively exploited, or that a severe incident has hit it, the clock starts. An early warning has to reach ENISA and your national CSIRT within a day, filed by hand on a form by a named human with an EU Login.

We built two free things to help: a short drill that shows you where you would stall, and a step-by-step assistant for when it is actually happening.

Start the 7-minute drill I'm working an incident now

Runs entirely in your browser No signup, nothing uploaded Built from Regulation (EU) 2024/2847

Where would you like to start?

Three ways in, depending on what today looks like.

Getting ready

Twelve questions and a simulated 02:14 incident. You get a score, your gaps, and a report to take to your team.

Run the drill

Something is happening

The assistant walks you through scope, tracks, awareness time and routing, then writes your 24-hour early warning field by field.

Open the assistant

Just one answer

Give it your awareness time and it returns every Article 14 deadline in UTC, ready to paste into your incident channel.

Open the calculator

The readiness drill

Two parts, about seven minutes. First we check whether the duty reaches you at all. Then we run a simulated incident and score whether you could file in time. Answer honestly: the score is for you, and nobody else ever sees it.

Part 1 · Does this apply to you?

Question 1 of 3

Do you make a product that is, or contains, software?

An app, a device with firmware, a connected product, a library you sell commercially.

Article 14 Reporting Operations Pack

Everything the drill says you are missing, already built. These are working files your team fills in during the real 24 hours, not a theory deck.

$39 One-time payment · instant download · 30-day refund, no questions
  • 24-hour early-warning working files. Vulnerability and incident variants, with the fields Article 14 actually asks for.
  • 72-hour notification working files. Both variants, prompting you for the exploit description, the measures taken, and the mitigations available to users.
  • Final report working files. The 14-day version for vulnerabilities and the one-month version for incidents.
  • Incident clock workbook. Guidance on timestamping awareness, plus an Excel tracker that computes your 24h, 72h, 14-day and one-month deadlines from it.
  • Escalation and RACI sheet. Who assesses, who records the awareness time, who drafts, who submits, who informs users.
  • Evidence log template. The timestamped trail that shows you filed in time.
  • Executive brief and customer notice templates. The Article 14(8) duty to inform users, covered.
  • security.txt and disclosure-policy generator, with a completed example.
  • A tabletop scenario with a fully worked example run, so you can rehearse before 11 September.

Every document comes as .docx (Word or Google Docs) and print-ready .html. The evidence log and incident clock are .xlsx (Excel or Sheets). This is not legal advice: it is built for engineering and operations teams to execute, with your counsel reviewing.

Before you buy, have a look at the Terms, the Privacy Notice and the Refund Policy. Sold by our merchant of record, who handles payment and any applicable taxes. Questions first? Write to hello@cradrill.com and a human will answer.

Questions people actually ask

My product shipped years ago. Am I off the hook?

No, and this is the part that surprises people. Article 69(2) grandfathers products placed on the market before 11 December 2027 unless they are substantially modified. Article 69(3) then carves straight back out of that: "by way of derogation from paragraph 2 … the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027." So the reporting duty reaches your installed base from 11 September 2026, even where the rest of the CRA does not. If the product is in scope and you learn of an actively exploited vulnerability, the clock runs.

What exactly counts as a "severe incident"?

Article 14(5) gives two limbs. An incident that negatively affects, or is capable of affecting, your product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions. Or one that has led, or could lead, to malicious code being introduced into the product or into a user's systems. The "or functions" half is easy to miss: an incident that compromises critical functionality counts even if no sensitive data was touched. Routine bugs and ordinary patches are out of scope. "Actively exploited vulnerability" has its own separate definition in Article 3(42), and it requires reliable evidence that a malicious actor exploited it without the system owner's permission, so an authorised researcher's proof-of-concept does not qualify.

Where do the reports go?

Through ENISA's Single Reporting Platform, simultaneously to ENISA and to the CSIRT designated as your coordinator (normally the Member State of your main EU establishment). The platform is scheduled to be operational by 11 September 2026. Submission is a manual form and there is no API.

What happens if I don't report?

Article 14 sits in the CRA's highest penalty tier. Article 64 puts failures of the Article 13 and 14 obligations, alongside the Annex I essential requirements, at administrative fines of up to €15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher. Member States set the actual regime and are directed to weigh the size and resources of the offender, so small companies are not treated like large ones, but the tier is the severe one. The blunter operational risk is simpler: a missed 24-hour window cannot be recovered afterwards, and your CSIRT knows whether you filed.

Do you collect any of my data?

No. The drill runs entirely in your browser and your answers never leave your machine. The exported report is generated locally. The reporting assistant at /app/ goes further and loads no third-party scripts at all, which you can verify with your browser's network tab.

Is this legal advice?

No. This is an educational readiness exercise built from the regulation text and the official guidance linked below. Confirm your scope and obligations with qualified counsel.

More free tools: the reporting deadline calculator, a printable Article 14 checklist, a security.txt generator, and our scan of 623 European vendors.

Sources: Regulation (EU) 2024/2847 (Cyber Resilience Act), the European Commission on CRA reporting obligations, and ENISA on the Single Reporting Platform. This site is independent and not affiliated with the EU, ENISA, or any CSIRT. Educational material, not legal advice.