Free
$0
Use the working bounded app first. No signup gate and no forced upgrade before value.
Use free appEU CRA · 11 September 2026 · 24h / 72h · free path
Prepare the ownership, awareness timestamp, official submission route and evidence handoff needed for Cyber Resilience Act reporting obligations that apply from 11 September 2026.
Direct answer
From 11 September 2026, the CRA requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The Commission describes an early warning within 24 hours of awareness and a full notification within 72 hours through the CRA Single Reporting Platform. This browser-local preflight checks whether the operating chain is ready; it does not decide legal scope, reportability, severity or exploitation status.
$0 · no signup · browser local
Mark each control Yes, No or Unknown. The checklist runs locally and does not submit your answers.
0/7 answered
A named owner has checked the current CRA reporting scope for the affected product
Use the current Commission and Regulation text for the live scope decision. This checklist does not decide whether a product or event is legally reportable.
The first reliable awareness timestamp and supporting evidence are preserved
The 24-hour and 72-hour reporting windows run from awareness, so retain the timestamp and evidence trail rather than reconstructing it later.
Confirmed facts, product impact and unresolved assumptions are separated
Keep observations distinct from hypotheses. Do not use this tool to decide whether a vulnerability is actively exploited or an incident is severe.
A 24-hour early-warning owner and escalation path are assigned
Know who can assemble the early warning and who can approve or escalate it without waiting for a perfect investigation file.
A 72-hour full-notification owner and evidence-collection path are assigned
Identify the technical and operational owners who can expand the initial report with the fuller facts required after the early warning.
The CRA Single Reporting Platform route and organisational access are known
Use only the official CRA reporting route. Do not paste exploit details, credentials or confidential incident evidence into this checklist.
Final-report ownership, corrective-measure dates and retained submission evidence are planned
The Commission describes later final-report deadlines. Track corrective measures, dates, owners and proof of the submitted reporting trail.
Result
REVIEW
7 controls still Unknown. Verify them against the current official source.
Free deadline monitor · browser local
Track up to 3 deadlines in this browser, keep the last 12 readiness snapshots, and export a calendar reminder. Nothing is uploaded.
Free first · exactly three paid steps
Run CRA 24h / 72h Reporting Readiness Preflight before paying. The three paid tiers buy bounded written proof, diagnosis or an action pack; they do not silently imply a subscription, deployment, certification or legal/compliance decision.
Free
$0
Use the working bounded app first. No signup gate and no forced upgrade before value.
Use free appPaid Proof
$5
A bounded fit / no-fit check plus one concrete blocker or next step.
Bounded deliverable with a product-specific reference.
Buy $5 proofDiagnostic
$50
Up to three evidence-backed findings and a prioritised action path.
Bounded deliverable with a product-specific reference.
Buy $50 proofAction Pack
$99
Up to five prioritised actions plus an acceptance checklist for the next implementation step.
Bounded deliverable with a product-specific reference.
Buy $99 proofSafe intake: do not send passwords, secrets, production credentials, private customer data or sensitive files through the generic proof checkout. Exact scope is confirmed before substantive paid work begins.
Official sources
Boundary
Operational readiness only. This app is not legal advice, does not determine whether the CRA applies to a product or event, does not classify exploitation or incident severity, and does not submit a notification. Do not enter secrets, credentials, personal data or confidential vulnerability details.
Read the evidence-backed answer