Manufacturer obligations
Risk assessment, technical documentation, essential requirements, and reporting duties.
Seven connected compliance domains, one assessment classification through conformity, scored and exportable in under 90 minutes.
Answer four quick questions. If CRA doesn't apply to you, we'll say so no hard sell.
Article 14 vulnerability and incident reporting obligations apply to products with digital elements placed on the EU market from 11 September 2026. Annex I essential cybersecurity requirements become fully binding on 11 December 2027.
Article 14 early warning, notification, and final report deadlines start applying.
Annex I product-security and vulnerability-handling requirements become fully binding.
Penalties scale with the failure up to a percentage of global annual turnover for serious cases.
Most teams are still using spreadsheets and whoever last read the regulation carefully. That works until a CVE in your product gets actively exploited and someone asks: do we know our classification, our deadline, and what we're required to say? This assessment answers that question before it's asked under pressure.
Unlike a static questionnaire, each answer feeds the next domain, so by the end you have a connected picture of one product's compliance posture.
Places your product into Standard, Important Class I/II, or Critical and carries the correct CVSS reporting threshold through every later step automatically.
Pulls CVSS score, vector string, and cross-checks CISA/ENISA KEV because active exploitation overrides every other reporting threshold under Article 14(1).
Runs the Article 14 decision tree: exploited-in-the-wild override, Critical always-report rule, or classification-specific CVSS floor with a cited determination.
An 18-section structured case file manufacturer ID, SBOM table, root cause, preventive measures, cross-border impact across 27 Member States, and more.
Calculates 24-hour, 72-hour, and 14-day deadlines from awareness with live countdown, audience-aware drafting, and an on-time / late / overdue compliance log.
Full scored register against all 22 Part I (product security) and Part II (vulnerability handling) requirements with applicability, justification, and linked evidence.
Conformity routing, auto-drafted EU Declaration of Conformity, CE marking, importer/distributor checklists, tech docs index, market surveillance, and 10-year retention.
Concrete, exportable outputs you can take into legal review, GRC, or your Single Reporting Portal workflow.
Generated, editable draft
Generated, editable draft
22 requirements, item by item
On-time / late / overdue
Ready for SRP / GRC / CSIRT
Across every saved product
The CVSS floor that triggers a mandatory report differs by product tier. The assessment applies the right one instead of leaving it to whoever fills the form.
Active exploitation is a hard override under Article 14(1). The assessment checks this first every time — so a low-CVSS but actively exploited vulnerability never slips through.
Classification sets the threshold. The CVE pre-fills the case. The case drives deadlines. Register, conformity, and Annex II stay attached to the same product.
Data stays in local private storage. And unlike tools that stop at incident reporting, this covers conformity, CE marking, economic-operator obligations, and product lifecycle.
The assessment's structure follows the regulation's own structure — so what you fill in corresponds to what a reviewer will look for.
Risk assessment, technical documentation, essential requirements, and reporting duties.
Early warning within 24 hours, notification within 72 hours, final report within 14 days.
10-year documentation retention; fines up to €15M or 2.5% global turnover for essential-requirement breaches.
14 product-security requirements and 8 vulnerability-handling requirements, tracked per product.
Information to the user, and the EU Declaration of Conformity content requirements.
Technical documentation index, and conformity assessment procedures by product class.
Get a working CVE-to-decision workflow with classification and KEV logic already correct — before you need it under deadline pressure.
Walk away with a scored Annex I register, drafted DoC, and technical documentation index per product line — ready for audit.
Understand whether the product you ship creates CRA obligations, what conformity route it needs, and what's missing from technical documentation.
Use the structured output as the factual foundation for legal review, rather than starting from a blank page for each product.
Every subsequent product is faster — manufacturer identification, standards references, and support-period defaults carry forward.
A few minutes that set up everything downstream.
Get an immediate, cited reporting answer.
The structured form guides you through exactly what's required.
Then work through Annex I and conformity.
DoC, Annex II instructions, JSON export, and portfolio view.
No. The assessment mirrors the structure of Regulation (EU) 2024/2847 to give you an accurate, evidence-based starting point — always verify specific obligations against the regulation itself or your counsel.
No. It drafts submission-ready documents and a structured export built to match what a Single Reporting Portal or notified body would expect — sending it is a deliberate step you take afterward.
It's written to local, private storage tied to your session. Nothing leaves your environment unless you export, copy, or submit it yourself.
Yes — each product gets its own case, and the portfolio dashboard gives you a single view across all of them.
The assessment can run against a representative dataset for evaluation, or be connected to the live NVD API and CISA/ENISA KEV catalogs for production use.
Run the assessment on one real product. In under an hour you'll know your classification, reporting obligations, Annex I completion score, and exactly what's missing from your technical documentation — in writing, exportable, and ready to act on.
We collaborate with leading technology providers, research institutes, and mobility pioneers to advance the security of connected and autonomous vehicles.
Get insider updates and actionable insights from CRISKLE and our global partners—trusted by the world's mobility and security innovators.
Sign up for early access to feature rollouts, expert briefings, and key security alerts.