Complete EU Cyber Resilience Act compliance for manufacturers.
Sleep well knowing your CRA compliance is documented, audit-ready, and defensible. Launch your free vulnerability disclosure portal today, use offline template packages, or run the full CRA self-assessment workspace.
Article 13 Baseline Check
Does your company meet the CRA disclosure baseline?
Enter your company domain to verify whether you meet CRA Article 13(2) vulnerability contact requirements: an active RFC 9116 security.txt file and a discoverable coordinated vulnerability disclosure policy. Results in seconds, no signup required.
Probes /.well-known/security.txt + 5 CVD policy paths. No data is shared with third parties. Up to 5 scans per hour.
The price of doing nothing is written into the law.
Up to €15 million or 2.5% of worldwide turnover
Breaching the essential cybersecurity obligations carries administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher (Art. 64(2)).
Products can be restricted or pulled from the EU market
Market surveillance authorities can require corrective action, restrict availability, or prohibit a non-compliant product on the EU market.
Enterprise buyers ask for a published CVD process
Procurement and security teams increasingly require a documented coordinated vulnerability disclosure process before they sign.
The free plan receives and tracks disclosures. Article 14 filing is on Reporting. Here is what it includes.
Three Ways to Comply
From free intake to offline templates and complete automated conformity.
The Cyber Resilience Act demands more than a contact email. Choose the right entry point for your team: set up your free public intake portal in two minutes, use our standardized CRA template packages (DOCX, PDF, Git-native Markdown), or run the full automated cloud workspace covering classification, STRIDE threat models, Annex I gap closure, and the EU Declaration of Conformity.
Where a notified body is still required. Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
Vulnerability Intake
Branded public disclosure portal, 48-hour SLA tracking, and RFC 9116 security.txt to fulfill Article 13(2). Free forever.
Create free CVD portal →Docs-as-Code & Office
37 fillable templates in DOCX, PDF, and Git-native Markdown (SPEC-CRA-PKG). Importable directly into CVD Portal anytime.
Browse template packages →Full CRA Compliance
Product classification, STRIDE risk assessment, Annex I checklist, EU Declaration of Conformity, and Article 14 ENISA reporting.
Explore CRA workspace →One journey, from first disclosure to CE marking.
Receive disclosures
A branded disclosure portal on your own subdomain with a published CVD policy and 48-hour acknowledgment tracking. You cannot report what you never hear about, so this is what the reporting deadline rests on. Free.
File on the clock
When a vulnerability is actively exploited, the 24-hour, 72-hour, and 14-day Article 14 timers start. The SRP-ready filing package is prepared for manual submission, on Reporting.
Classify and assess
Classify each product under Annex III and IV, pick the Article 32 conformity route, and run the cybersecurity risk assessment.
Declare conformity
Close the Annex I gaps, assemble the technical file, and draw up the EU Declaration of Conformity for CE marking.
A working portal you can click through.
Researchers submit through a branded intake form with PGP support. Your team triages disclosures, tracks acknowledgment deadlines, and exports the evidence trail. Every submission is logged from the moment it arrives. Try it on the portal of Aurelia Devices B.V., a fictional manufacturer running on CVD Portal. We email you a single-use link, no account needed.

Industry Context
“Organisations increasingly recognise that software development nowadays requires an active, positive response to vulnerability reports, which strengthens security and is becoming a strong selling point when handled properly.”
EU buyers and market surveillance authorities increasingly expect manufacturers to show a documented CRA position. CVD Portal gives you a structured assessment, the technical file to back it, and a published disclosure process.
CRA Entered Into Force
Regulation (EU) 2024/2847, published in the Official Journal on 20 November 2024
Article 14 Reporting Begins
Vulnerability notification obligations apply to products in scope
Full Conformity Deadline
Annex I essential requirements, technical documentation, and CE marking apply
Simple, transparent pricing
See full pricing →Every module at scale, lifecycle support for 25 products, integrations, EUDI identity
Who Keeps a Camera Secure When the Installer Disappears?
A Hikvision Europe security director argued in August 2026 that the customer owns the system and should never depend on one installer to keep control of it. The Cyber Resilience Act turns that design argument into a manufacturer duty that runs for at least five years.
7 min readCRA ComplianceENISA Assessment Report: The End of SOG-IS, the Rise of EUCC, and Fixed-Time Testing for SMEs
ENISA published its 5-year cybersecurity assessment report covering 2021 to 2025. The data confirms the retirement of SOG-IS in February 2026, the operational launch of EUCC with 24 accredited laboratories, and the standardisation of fixed-time SME testing under EN 17640 (FiTCEM). Here is what the numbers mean for manufacturers preparing for the EU Cyber Resilience Act.
7 min readCRA ComplianceGermany's BSI Measured security.txt Adoption at 1.8 Percent. We Measured Manufacturers and Found the Same Hole
The BSI and the Allianz für Cyber-Sicherheit published a measurement of German website operators on 6 August 2026. Two independent scans of two different populations now point the same way, five weeks before Article 14 applies.
6 min readAchieve complete CRA compliance before the deadlines arrive
Launch your free vulnerability disclosure portal, download offline template packages, or start your 14-day Compliance trial for product classification, STRIDE risk assessment, and the EU Declaration of Conformity. Still mapping your obligations? Start with the EU Cyber Resilience Act guide.