Your workspace for Cyber Resilience Act compliance.
Classify each product, record the assessment, and file an Article 14 report inside the deadline, in one place. Your compliance stays documented, audit-ready, and defensible.

— days until Article 14 reporting becomes mandatory on 11 September 2026. — days until full conformity and CE marking on 11 December 2027.
Does your company meet the CRA disclosure baseline?
Enter your domain. The scan checks the two Article 13(2) contact requirements, an RFC 9116 security.txt and a discoverable disclosure policy. No signup.
Probes /.well-known/security.txt and five CVD policy paths. No data is shared with third parties. Up to five scans per hour.
Three Ways to Comply
From free intake to offline templates and complete automated conformity.
The Cyber Resilience Act asks for more than a contact address. Pick the entry point that matches how far along your team is. Each one imports into the next.
Where a notified body is still requiredRead the condition →
Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
Vulnerability Intake
Branded disclosure portal, 48-hour acknowledgment tracking, and RFC 9116 security.txt. Free forever.
Create free CVD portal →Docs-as-Code & Office
37 fillable templates in DOCX, PDF, and Markdown. Import them into the workspace later.
Browse template packages →Full CRA Compliance
Classification, STRIDE risk assessment, Annex I sign-off, and the EU Declaration of Conformity.
Explore CRA workspace →One journey, from first disclosure to CE marking.
Receive disclosures
A branded portal on your own subdomain, with a published policy and 48-hour acknowledgment tracking. Free.
Create a free portal →File on the clock
An actively exploited vulnerability starts the 24-hour, 72-hour, and 14-day Article 14 timers. The filing package is prepared for you.
How Article 14 filing works →Classify and assess
Classify under Annex III and IV, pick the Article 32 conformity route, and run the risk assessment.
Classify your product →Declare conformity
Close the Annex I gaps, assemble the technical file, and draw up the EU Declaration of Conformity.
See how self-assessment works →Industry Context
“Organisations increasingly recognise that software development nowadays requires an active, positive response to vulnerability reports, which strengthens security and is becoming a strong selling point when handled properly.”
EU buyers and market surveillance authorities increasingly expect manufacturers to show a documented CRA position. CVD Portal gives you a structured assessment, the technical file to back it, and a published disclosure process.
CRA Entered Into Force
Regulation (EU) 2024/2847, published in the Official Journal on 20 November 2024
Article 14 Reporting Begins
Vulnerability notification obligations apply to products in scope
Full Conformity Deadline
Annex I essential requirements, technical documentation, and CE marking apply
Simple, transparent pricing
See full pricing →Every module at scale, lifecycle support for 25 products, integrations, EUDI identity
Do you need VEX documents for CRA compliance?
The Cyber Resilience Act never uses the word VEX. It still makes exploitability the legal test, and it still requires you to share vulnerability information about third-party components. ENISA surveyed 334 organisations and found 76 percent rate supplier exploitability claims as critical or important. Here are the four statuses, the five justifications, the three competing formats, and how to choose one.
11 min readCRA ComplianceDoes RED DA work count toward CRA compliance?
The RED cybersecurity Delegated Regulation is repealed with effect from 11 December 2027, the day the Cyber Resilience Act applies in full. Test evidence built against EN 18031 carries forward into the CRA technical file. The vulnerability monitoring duty that starts on 11 September 2026 does not, because RED DA never asked for it. Here is what transfers, what does not, and the volume arithmetic that decides your tooling budget.
10 min readCRA ComplianceWho keeps a camera secure when the installer disappears?
A Hikvision Europe security director argued in August 2026 that the customer owns the system and should never depend on one installer to keep control of it. The Cyber Resilience Act turns that design argument into a manufacturer duty that runs for at least five years.
7 min readAchieve complete CRA compliance before the deadlines arrive
Launch your free vulnerability disclosure portal, download offline template packages, or start your 14-day Compliance trial for product classification, STRIDE risk assessment, and the EU Declaration of Conformity. Still mapping your obligations? Start with the EU Cyber Resilience Act guide.