Platform Capabilities
CRA Compliance Platform Features
CVD Portal covers every obligation of Regulation (EU) 2024/2847 in one place: from product classification and STRIDE risk assessment through Annex I essential requirements and the EU Declaration of Conformity to Article 14 authority filing.
Core Features (Every Tier, Including Free)
Essential coordinated vulnerability disclosure infrastructure for receiving and tracking reports under CRA Article 13.
Unlimited Products for Reporting
Receive vulnerability reports for every product you sell, with no per-product limit on any tier. The affected product is a field on each report.
Whitelabel Email Intake
Get security@yourcompany.cvdportal.com — a professional email address dedicated to vulnerability intake, automatically forwarded to your team.
Branded Submission Portal
A hosted public portal (yourcompany.cvdportal.com) where security researchers submit reports under your CVD policy and safe-harbor terms.
48-Hour Acknowledgment SLA Tracking
Automated tracking of your acknowledgment SLA (48 hours by default, configurable). Aligns with BSI TR-03183-3 guidelines for person-written replies.
Auto-Drafted CVD Policy Template
RFC 9116 compliant coordinated vulnerability disclosure policy template ready to customize with scope, guidelines, and PGP keys.
Centralized Triage Dashboard
Manage all incoming vulnerability reports in one place. Assign coordinators, update statuses, and maintain a timestamped audit trail.
PGP Encrypted Communication
Allow researchers to encrypt submissions using your PGP key for confidentiality and end-to-end security.
Reporting (Article 14 Authority Filing & Vulnerability Handling)
Mandatory authority reporting from 11 September 2026 and vulnerability lifecycle handling under Annex I Part II.
SRP-Ready Submission Package
Assembles the 24-hour early warning, 72-hour notification, and final report for ENISA Single Reporting Platform and national CSIRT filing.
Article 14 Deadline Timers
Hard countdown timers and alerts for actively exploited vulnerabilities (24h/72h/14d) and severe security incidents (24h/72h/1mo).
SBOM & Component Registry
Import SPDX and CycloneDX software bills of materials to map vulnerabilities across software dependencies and hardware components.
CVSS 3.1 & 4.0 Severity Scoring
Native CVSS calculator with vector string generator to assess base, temporal, and environmental vulnerability severity.
Machine-Readable CSAF 2.0 Advisories
Export Common Security Advisory Framework (CSAF 2.0) JSON advisories when security patches or remediations ship.
Threat Feeds & Monitoring
Integrated NVD and EU Vulnerability Database (EUVD) threat intelligence feeds to correlate public CVEs with internal components.
Compliance (CRA Self-Assessment & EU Declaration of Conformity)
Full CRA conformity workflow for default-class products under Module A, and technical file preparation for third-party routes.
Product Classification Engine
Classify products under CRA Annex III and IV (Default, Class I, Class II, Critical) and derive the mandatory Article 32 conformity assessment route.
STRIDE Risk Assessment Workspace
Conduct cybersecurity risk assessments per Article 13 with structured STRIDE threat modeling, likelihood/impact matrices, and control mapping.
21-Requirement Annex I Checklist
Track conformity against the 21 mandatory essential requirements of CRA Annex I Part I (security properties) and Part II (vulnerability handling).
EU Declaration of Conformity (DoC) Drafting
Generate Annex V EU Declarations of Conformity directly from verified assessment evidence, preventing drift between docs and engineering.
Annex VII Technical File Generator
Assemble and version the mandatory 10-year technical documentation dossier required for market surveillance inspections.
ENISA Secure by Design Tracker
Work through 22 ENISA Secure by Design and Default playbooks with gate sign-offs to evidence engineering due diligence.
Enterprise (Scale, Integrations & Third-Party Assurance)
Advanced identity verification, automated pipelines, custom domains, and dedicated compliance support.
Custom Domain & Branding
Host the disclosure portal on your own domain (security.yourcompany.com) with custom CSS and brand styling.
EUDI Wallet Identity Verification
Verify reporter and organization identity using the European Digital Identity (EUDI) Wallet under eIDAS 2.0 standards.
REST API & Webhooks
Full programmatic access to submissions, advisory generation, and status workflows with HMAC-SHA256 signed webhooks.
SSO & SAML 2.0 Integration
Single sign-on integration with Okta, Microsoft Entra ID (Azure AD), Google Workspace, and SAML 2.0 identity providers.
Notified-Body Evidence Dossier
Structured export package tailored for Notified Bodies conducting Module B+C, Module H, or EUCC scheme evaluations.
Dedicated Account Manager & SLA
Priority 99.9% uptime SLA, guaranteed response times, and a dedicated compliance engineer for onboarding support.