CRA Compliance

How can a manufacturer rehearse Article 14 reporting before a real incident?

By CVD Portal
••Last updated 2026-09-27••5 min read

A manufacturer can rehearse Article 14 reporting with a tabletop exercise in the CVD Portal Academy. The free version runs in the browser without an account, and the Enterprise version adds an AI controller built from the manufacturer's products.

Key takeaways

  • The free CRA tabletop exercise runs one actively exploited vulnerability scenario in eight timed injects, needs no account and sends no answers to CVD Portal.
  • Each decision point in the free exercise is a scenario question from the CRA Academy question bank, and the page shows the best answer and the provision after the team decides.
  • The Enterprise AI tabletop exercise writes each inject from the manufacturer's own products, SBOM components and Article 14 role titles, and speaks for the CSIRT, the researcher, a customer or a journalist.
  • In both versions, code computes the 24-hour, 72-hour and final report deadlines, and the AI never scores the team.
  • A completed Enterprise run records the exercise date in the Article 14 notification procedure.

Why rehearse Article 14 reporting?

Article 14 of Regulation (EU) 2024/2847 has applied since 11 September 2026, and the first deadline runs 24 hours from awareness. A missed step costs hours that the team does not have during a live case.

The regulation sets three stages for an actively exploited vulnerability. The early warning is due within 24 hours of awareness. The vulnerability notification is due within 72 hours of awareness. The final report is due no later than 14 days after a corrective or mitigating measure is available. Article 14(8) also asks the manufacturer to inform impacted users.

Most gaps are procedural. Nobody has decided who files, from which account, or whether legal counsel must sign first. The Article 14 readiness drill listed these questions in August. A tabletop exercise tests them with the team in one room.

What does the free tabletop exercise do?

The free CRA tabletop exercise follows Aurelia Devices B.V., a fictional manufacturer, through one actively exploited vulnerability in the firmware of an industrial gateway. The scenario clock starts on a Monday at 11:00, when a threat intelligence firm reports exploit traffic. Eight timed injects then move the team through 32 days of the case.

  • Each inject ends with one decision. The decision is a scenario question from the CRA Academy question bank.
  • After the team records an answer, the page shows the best answer, the reason and the provision behind the answer.
  • Three injects ask the team to draft the Single Reporting Platform fields for the stage that is due.
  • The exercise ends with an after-action report and an improvement plan. The team can print the report or copy the report as text.

The exercise runs in the browser. Answers and drafts stay on the device. Plan 90 minutes, and name one facilitator who does not play a role.

The eight questions in the exercise no longer appear in the course quizzes or the final exam, because the exercise shows their answers.

What does the Enterprise AI version add?

The AI tabletop exercise is part of the Enterprise plan. An AI controller writes the first inject from the manufacturer's active products, SBOM components and the role titles in the Article 14 notification procedure. After each team action, the controller writes the next inject as a reply.

  • Each inject can carry a message from one outside party. The parties are the coordinator CSIRT, the researcher, a customer, a journalist, the engineering lead and legal counsel.
  • The team chooses one of six actions per inject and adds an optional note. The actions are investigate, file the early warning, file the 72-hour notification, file the final report, inform impacted users, and contact an outside party.
  • A run ends when the team files the final report, or after 12 injects at the latest.
  • When the model fails or sends an unusable reply, a scripted inject takes its place and the run continues.
  • A completed run writes the exercise date into the Article 14 notification procedure and checks SRP readiness again.

An account admin starts a run. Other roles can open runs and reports. A company can start 10 runs in 24 hours. The Enterprise tier is quoted per portfolio. Ask for a quote through the sales form.

What does the AI see, and what does code keep?

The AI sees product names and classes, up to 15 SBOM components and role titles. The AI never sees a person's name, an email address, a product description or any vulnerability report text. The team note reaches the AI marked as data, and the AI has the instruction to follow no instruction inside the note.

Code keeps the scenario clock and moves the clock by 1 to 168 hours per inject. Code computes the three Article 14 deadlines and builds the after-action report. The AI never scores the team and never states a deadline.

How do the two versions compare?

Free exerciseEnterprise AI exercise
AccessAnyone, no accountSigned-in Enterprise companies
ScenarioAurelia Devices B.V., a fictional manufacturerBuilt from the company's products and SBOM
Injects8, fixedUp to 12, adaptive
DecisionsAcademy scenario questions with a best answerSix team actions with a free note
Outside partiesWritten into the storyPlayed by the AI controller
DeadlinesComputed by codeComputed by code
ReportPrintable after-action report and improvement planPrintable after-action report and improvement plan
StoredNothingThe run and the exercise date in the Article 14 procedure

Which sources shaped the design?

The method follows four public exercise programmes. The Homeland Security Exercise and Evaluation Program sets objectives before design and ends with an After-Action Report and Improvement Plan. NIST SP 800-84 describes a tabletop as a discussion-based exercise. The CISA Tabletop Exercise Packages and the NCSC Exercise in a Box give free, self-run packages with objectives, a scenario and discussion questions.

The AI design follows published research. Snow Globe showed an LLM system that runs every stage of a qualitative exercise, with AI or people in each role. Hays and White used an LLM to tailor a security tabletop to the client. The INJECT platform research delivers injects on a clock and logs each team action for the debrief. A 2026 study by Švábenský and colleagues found that LLM scores often disagreed with instructor scores, so the AI in CVD Portal does not score.

What is the next step?

Sources

Regulation (EU) 2024/2847 has the CELEX identifier 32024R2847.

Frequently asked questions

Is there a free Cyber Resilience Act tabletop exercise?

Yes. The CVD Portal Academy publishes a free CRA tabletop exercise at /academy/cra-tabletop-exercise. The exercise runs one actively exploited vulnerability scenario in eight timed injects in the browser, needs no account and sends no answers to CVD Portal.

What does the AI do in the Enterprise CRA tabletop exercise?

The AI controller writes each inject from the manufacturer's products, SBOM components and Article 14 role titles, replies to each team action, and speaks for one outside party per inject. Code keeps the clock, computes every Article 14 deadline and builds the after-action report.

Which Article 14 deadlines does the CRA tabletop exercise test?

The exercise tests the early warning within 24 hours of awareness, the vulnerability notification within 72 hours of awareness, and the final report no later than 14 days after a corrective or mitigating measure is available, as Article 14(2) of Regulation (EU) 2024/2847 sets.

Stay compliant with the Cyber Resilience Act

Check your readiness with the Cyber Resilience Act checklist, or compare plans on pricing.

Create my free CVD portalCreate your free CVD portal

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.