CVD Portal gives every manufacturer a free vulnerability disclosure portal, CRA classification, scoping tools and a training course. Article 14 reporting costs €99 per month, the Module A self-assessment €299 per month, and Enterprise is quoted per portfolio.
Key takeaways
- The free CVD Portal account covers the Article 13 disclosure channel with a public submission portal, 48-hour acknowledgment tracking and a published disclosure policy.
- The public CVD Portal tools need no account and cover scope, classification, maturity scoring, CVSS scoring, and SBOM and CSAF validation.
- The CVD Portal Reporting tier adds the Article 14 notification workflow and the vulnerability handling records of Annex I Part II.
- The CVD Portal Compliance tier adds the risk assessment, the Annex I checklist, the EU Declaration of Conformity draft and the Annex VII technical documentation.
- The CVD Portal Enterprise tier is quoted per portfolio and adds scale, API access, SSO and the notified-body conformity evidence package.
What can a manufacturer use without an account?
The public tools on cvdportal.com run without an account. Each one covers one early readiness step.
- The CRA scope page explains which products the regulation covers.
- The product classifier matches a product description against the Annex III and Annex IV categories.
- The CRA maturity assessment rates 25 practices across five domains. The tool runs in the browser and stores nothing on our servers.
- The CRA readiness checklist takes one product through the obligations.
- The article-by-article CRA guide explains each article. The worked examples page quotes the examples that the Commission published in its guidance.
- The templates page holds CRA policy and document templates.
- The free tools include CVSS 3.1 and 4.0 calculators, a CSAF validator, an SBOM validator, an Article 14 timeline, a reportability check and a security.txt generator.
- The standards hub tracks the EN 40000 series and the vertical standards, and links to the free CRA workshops that the standards bodies run for SMEs.
- The CRA training course teaches the regulation module by module.
- The CRA tracker records each regulatory event, and the newsletter sends the updates.
What does the free account include?
A free account gives the manufacturer the disclosure channel that Article 13 requires. The Free tier costs €0 and has no end date.
- A public submission portal on the company's own cvdportal.com subdomain, with a tracking ID for each report.
- Tracking of the 48-hour acknowledgment target.
- A published disclosure policy and security contact, with an RFC 9116 security.txt for the portal.
- PGP encrypted communication with the reporter.
- A flag for actively exploited vulnerabilities and a record for each severe security incident.
- A compliance audit trail.
- The product classification and vertical standards lookup.
- Unlimited products for vulnerability disclosure, and one team member.
Each new account includes a 14-day Compliance trial.
What does the Reporting tier add?
The Reporting tier costs €99 per month, or €1,188 billed annually. The tier adds the Article 14 reporting workflow and the vulnerability handling records that Annex I Part II requires.
Article 14 has applied since 11 September 2026. Manufacturers must notify ENISA and the national CSIRT of actively exploited vulnerabilities and severe incidents. The windows are a 24-hour early warning, a 72-hour full notification, then a final report at 14 days for vulnerabilities and 1 month for incidents.
- The Article 14 notification workflow for the 24-hour, 72-hour and 14-day reports.
- An SRP-ready submission package. ENISA provides no submission API at this stage, so CVD Portal produces a package for one-step manual submission to the single reporting platform.
- An SBOM registry for SPDX and CycloneDX files, and a hardware component registry.
- CVSS 3.1 and 4.0 severity scoring on each report.
- Remediation decision and timeline tracking.
- CSAF 2.0 advisory export.
- NVD and EUVD threat intelligence feeds.
- Up to 3 team members.
What does the Compliance tier add?
The Compliance tier costs €299 per month, or €3,588 billed annually. The tier adds the CRA self-assessment, from the risk assessment to the EU Declaration of Conformity. The CRA applies in full from 11 December 2027.
- The Annex I Part I cybersecurity risk assessment, with STRIDE threat modelling and control mapping.
- Product classification and the Article 32 conformity route selection.
- The Annex I self-assessment checklist.
- The ENISA Secure by Design and Default tracker.
- Artifact drafting with a gap analysis. How do you run a Cyber Resilience Act gap analysis? describes the method.
- The EU Declaration of Conformity draft for Annex V.
- The technical documentation index and export for Annex VII.
- A supplier register that checks each supplier domain for a security.txt and a disclosure policy.
- Lifecycle support for 3 products, and up to 5 team members.
Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
What does the Enterprise tier add?
CVD Portal quotes the Enterprise tier per portfolio. Ask for a quote through the sales form. The tier is for large product portfolios, SSO and API integration, or notified-body evidence.
- Lifecycle support for 25 products.
- A notified-body conformity evidence package.
- API access with SSO and SAML integration.
- A customer-facing trust portal on the company's own domain.
- Automated SBOM to CVE supply chain alerts.
- AI-assisted vulnerability triage.
- EUDI Wallet identity verification under eIDAS 2.0.
- Slack, Teams and Discord notifications, and custom webhook integrations.
- CVE ID assistance.
- Up to 10 team members, a dedicated account manager and a 99.9% uptime SLA.
Which tier covers each CRA readiness need?
The rows follow the support needs that CRA readiness surveys ask manufacturers to rate. The free column needs no payment. The paid column names the lowest tier that adds to the free resource.
| Readiness need | Free | Paid tier |
|---|---|---|
| Clear guidance on CRA requirements | CRA guide and CRA tracker | Reporting adds the CRA-CVD obligation matrix |
| Practical guidance and tools | Free tools, templates and the readiness checklist | Compliance applies the steps to each product |
| Examples and best practices | Worked examples from Commission guidance | No paid add-on |
| Scope assessment | CRA scope page and product classifier | No paid add-on |
| Product classification | Product classifier and the classification lookup in the free account | Compliance adds the Article 32 route selection |
| Cybersecurity risk assessment | Maturity assessment for the organisation | Compliance adds the Annex I Part I risk assessment with STRIDE |
| Harmonised standards | Standards hub and the vertical standards lookup in the free account | No paid add-on |
| Conformity assessment | Product classes and notified bodies | Compliance adds the Annex V and Annex VII documents. Enterprise adds the notified-body evidence package |
| Vulnerability and incident management | Disclosure portal, acknowledgment tracking, exploited vulnerability flags and incident records | Reporting adds the Article 14 workflow, the SRP-ready package and CSAF export |
| Technical documentation | Templates | Compliance adds the Annex VII index and export |
| Third-party components and suppliers | SBOM validator in the free tools | Reporting adds the SBOM registry. Compliance adds the supplier register. Enterprise adds SBOM to CVE alerts |
| Access to experts | Contact form | Enterprise adds a dedicated account manager |
| Training and workshops | CRA training course and the workshop links on the standards hub | No paid add-on |
What is the next step?
Start with the obligation that applies first. Article 14 reporting applies today, and full conformity applies from 11 December 2027.
- Classify each product with the free product classifier.
- Score the organisation with the free CRA maturity assessment.
- Compare the tiers line by line on the pricing page.
- Ask for an Enterprise quote through the sales form.
Sources
Regulation (EU) 2024/2847 has the CELEX identifier 32024R2847.
Frequently asked questions
Which CRA compliance tools are free?
CVD Portal gives every manufacturer a free vulnerability disclosure portal with 48-hour acknowledgment tracking, a product classifier, a CRA maturity assessment, policy and document templates, CVSS calculators, SBOM and CSAF validators, and a CRA training course.
What does the CVD Portal Reporting tier add?
The Reporting tier costs €99 per month. It adds a workflow for Article 14 notifications, an SRP-ready submission package, an SBOM registry, CSAF 2.0 advisory export, remediation tracking, and NVD and EUVD threat intelligence feeds.
How much does the CVD Portal Enterprise tier cost?
CVD Portal quotes the Enterprise tier per portfolio, and the price comes from the sales team. The Enterprise tier covers 25 products, API access with SSO and SAML, a trust portal and a notified-body conformity evidence package.