Home / Tools / CRA Article 14 readiness

Free tool · no account · about two minutes

Could you file inside 24 hours?

Article 14 of the Cyber Resilience Act applies from 11 September 2026 — not December 2027 — and it reaches products you shipped years ago. 14 questions someone who owns the product can answer without looking anything up. The assessment appears on screen — nothing is gated and nothing you enter leaves your browser.

01

Whether this applies to you

What is your role for products you place on the EU market?Pick the one that describes your main position. Article 14 falls on manufacturers.

Do you still have products on the EU market that shipped more than two years ago?Including versions still in use by customers, not only what you actively sell.

Do you know your products’ classification under Annex III or IV?Important and default categories. The 72-hour notification asks for it.

02

Whether you would find out

Do you generate a software bill of materials as part of your build?Produced in CI and versioned with the release, rather than compiled by hand when asked.

Could you produce a bill of materials for something you shipped three years ago?

Is your component inventory continuously matched against vulnerability and exploitation sources?For example NVD, the EU vulnerability database (EUVD), and active-exploitation feeds such as CISA KEV.

Can a security researcher who finds a flaw in your product easily reach you?A published contact route, security.txt, or a documented disclosure policy.

Do your products depend on open source that no longer receives security patches?

03

Whether you could decide and file in time

Is there a named person authorised to judge that a vulnerability is being actively exploited?A specific person, not a team or a role in a policy document.

If exploitation evidence arrived on a Friday evening, would anyone see it before Monday?

Do you know which national CSIRT is your designated coordinator?

Do you have an internal template mirroring the mandatory early-warning fields?So the first filing is transcription rather than composition under time pressure.

Do the people who would file have working EU Login accounts?Access to ENISA’s platform is via EU Login. There is no API, so a human must be able to sign in.

Has anyone rehearsed this end to end?A tabletop exercise simulating an exploitation report arriving out of hours.

This tool reports what you tell it. It is not a compliance audit, not a conformity assessment, and not legal advice. DevSpark Ltd is not a notified body. We do the engineering that makes the obligation operable — bill of materials generation, correlation against exploitation feeds, and a reporting runbook your on-call can execute — and we recommend taking qualified legal advice on your specific obligations under Regulation (EU) 2024/2847. The background is set out in our article on the September deadline.