Stavenor

The CRA reporting clock is already running.

Since 11 September 2026, every manufacturer of a connected product sold in the EU must report actively exploited vulnerabilities and severe incidents. The first report is due within 24 hours. The CRA 2026 Compliance Pack gets you ready to file, and builds your technical file for December 2027.

24 hEarly warningfrom the moment you become aware
72 hNotificationfrom the moment you become aware
14 daysFinal report, vulnerabilityafter a fix is available
1 monthFinal report, incidentafter the 72-hour notification

Plus an intermediate report whenever the coordinating CSIRT asks for one. Article 14, Regulation (EU) 2024/2847.

Four things most teams get wrong

  • The 24-hour filing is not a one-line alert.

    ENISA's platform requires eight fields at the early warning for a vulnerability, including a summary of up to 4,000 characters.

    The early warning, field by field
  • Your installed base is in scope.

    Reporting applies to products you placed on the market before December 2027, modified or not.

    Products already on the market
  • Reporting outlives support.

    Vulnerability handling ends with the support period. The duty to report does not.

    The support period
  • A vulnerable library is not always reportable.

    Under the Commission's guidance, it is reportable when it has been exploited in your product.

    Third-party components

What's in the pack

25 files. Word, Excel, PDF and Markdown. Delivered instantly.

Operating manual
37 pages in eleven parts, from deciding whether the CRA applies to you, to the roadmap for 11 December 2027.
17 templates
Every Article 14 filing form, built from all 39 fields of ENISA's reporting platform, with each field's character limit and required status. The internal procedure that defines when you became aware. A publishable vulnerability disclosure policy. The Annex I conformity matrix, the technical file index and the EU declaration of conformity.
6 tools
A gap analysis of 82 controls, a 90-day plan, a RACI matrix, a printable classification tree, a printable reporting clock for your on-call engineer, and the verification register.

Built from the sources, and it shows its working

Free CRA templates exist. Most are built from summaries of summaries. This pack was built from the text of the Regulation in the Official Journal, ENISA's own platform specifications and the European Commission's guidance.

Every one of its 124 regulatory claims is listed in a register with its source and a verification status, so you can check any line yourself. Along the way it corrects 19 errors that are widely repeated elsewhere. Where something is genuinely uncertain, the pack says so and tells you who to ask.

Free guides

Is it for you?

Made for

  • Manufacturers of connected devices, especially embedded Linux
  • Teams under 50 people, without a compliance department
  • Products on the Module A self-assessment route

Not made for

  • Class II and critical products, which need a notified body. The reporting parts still apply to you.
  • Large organisations with an in-house compliance function
  • Anyone looking for legal advice. This is documentation, not counsel.
€200one-time
  • 25 files, instant download
  • Single-organisation licence for internal use
  • Edition 2026.1, legal position as at 20 September 2026. No updates included.
  • Self-service. No support, not legal advice.
Get the pack