← Academy

Free, no account, 90 minutes

How do you build a Cyber Resilience Act tabletop exercise?

Build a Cyber Resilience Act tabletop exercise from one realistic scenario, one clock starting at awareness, timed injects forcing each Article 14 decision, and an after-action report converting every missed decision into an improvement action.

Last updated 26 September 2026

Key takeaways

  1. The Article 14 clocks start at awareness, so the exercise clock starts at the first reliable evidence of exploitation.
  2. The early warning is due within 24 hours and the vulnerability notification within 72 hours of awareness.
  3. The final report for an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure is available.
  4. Each of the eight decision points comes from the CRA Academy question bank and ends with the best answer and its legal basis.
  5. The exercise ends with an after-action report and an improvement plan that the team can print.

Run the exercise

Scenario

Actively exploited vulnerability in a shipped product

Manufacturer: Aurelia Devices B.V., a fictional manufacturer

Product: G4 industrial gateway, firmware 3.2

An exploit for a flaw in the G4 gateway firmware is in use in the wild. The team runs the case from the first report to the final report to the coordinator CSIRT and ENISA.

Exercise objectives

Objective 1: Start the Article 14 clock at the earliest reliable evidence of exploitation, and keep a timestamped record of that evidence.
Objective 2: Send the early warning to the coordinator CSIRT and ENISA through the single reporting platform within 24 hours, with no sign-off gate in the path.
Objective 3: Send the vulnerability notification within 72 hours with the facts the team knows at that time.
Objective 4: Inform impacted users without undue delay, coordinate the disclosure date, and send the final report no later than 14 days after the first corrective or mitigating measure.

Optional. Name the participants and their exercise roles for the after-action report.

What does the exercise simulate?

The exercise follows Aurelia Devices B.V., a fictional manufacturer, through one actively exploited vulnerability in the firmware of an industrial gateway. The clock starts on a Monday at 11:00, when a threat intelligence firm reports exploit traffic through the Aurelia disclosure policy. Eight injects then move the team through 32 days of the case.

How is the exercise structured?

The method follows the Homeland Security Exercise and Evaluation Program, known as HSEEP. HSEEP sets exercise objectives before design, and records strengths, areas for improvement and corrective actions in an After-Action Report and Improvement Plan. The exercise here states four objectives and ends with both documents.

NIST SP 800-84 describes a tabletop exercise as a discussion-based session in which personnel talk through their roles and their responses to a scenario. The scenario here arrives as eight timed injects. Each inject ends with one decision. The facilitator reads the inject aloud, the team discusses, and the team records one answer.

Every decision point is a scenario question from the CRA Academy question bank. After the team records an answer, the page shows the best answer, the reason and the provision behind the answer. A missed decision also shows the consequence for the case.

What does each inject test?

Each row is one inject. The time is scenario time, counted from the first report.

Scenario timeInjectObjectiveProvision
Day 1, Monday 11:00Report through the disclosure policyObjective 1Article 14(2)(a)
Day 1, Monday 19:00Reproduction succeedsObjective 1Article 14(2)(a)
Day 1, Monday 21:00Who files the early warningObjective 2Article 14(2)(a)
Day 2, Tuesday 07:00Which channel to useObjective 2Article 14(1) and Article 16
Day 4, Thursday 05:00Root cause still unclearObjective 3Article 14(2)(b)
Day 5, Friday 11:00Workaround readyObjective 4Article 14(8)
Day 6, Saturday 11:00CSIRT asks for more timeObjective 4Annex I Part II
Day 32, Thursday 11:00Assurance reviewObjective 4Article 14(2)(c)

Which Article 14 fields does the team draft?

Three injects ask the team to draft the Single Reporting Platform fields for the stage that is due. The early warning asks for the title, the product and the Member States where the product is available. The vulnerability notification adds the nature of the vulnerability and the exploit, the measures taken, the measures users can take and the sensitivity of the information. The final report adds the date of the corrective measure, the full description, severity, impact, the malicious actor and the security update.

The field list comes from the same matrix CVD Portal uses to prepare a live Article 14 submission.

Who should take part?

Invite everyone who acts inside the first 24 hours. The usual group is the on-call engineer, the product security lead, the holder of the Single Reporting Platform account, legal counsel, communications and the product manager. Name one facilitator who does not play a role.

Plan 90 minutes. One inject takes about 10 minutes of discussion.

What happens after the exercise?

The page builds an after-action report with a rating for each objective and an improvement plan with one action for each missed decision. Print the report or copy the text into your own record. The answers and drafts stay in your browser and are not sent to our servers.

Record the exercise date in your Article 14 notification procedure. CVD Portal holds that date with the procedure and exports the date in the procedure document.

CVD Portal tracks the Article 14 clocks on a live case and prepares each Single Reporting Platform stage.

Enterprise teams can run the same exercise with an AI controller. It builds the scenario from their own products and plays the CSIRT, the researcher, a customer and a journalist. Open the AI tabletop exercise