Pricing

Free to receive and track vulnerability disclosures. Article 14 filing on Reporting. CRA self-assessment and the EU Declaration of Conformity on Compliance.

Deadline 1: Reporting Tier

11 September 2026

Article 14 reporting obligations take effect. Manufacturers must notify ENISA of actively exploited vulnerabilities and severe security incidents within 24h / 72h / 14 days.

Applies to products with digital elements in CRA scope
Deadline 2: Compliance Tier

11 December 2027

Full CRA conformity. Annex I risk assessment, product classification, technical documentation, the conformity assessment and the EU Declaration of Conformity.

Applies to all new products placed on the EU market

Free

€0/forever

Free forever. Receive and track vulnerability disclosures with a public portal, SLA tracking and an audit trail.

Typical fit: any manufacturer that needs a compliant public disclosure channel today.

Disclosure intake and tracking
  • Unlimited products covered for disclosure
  • Public vulnerability submission portal
  • Submission tracking with unique IDs
  • 48h acknowledgment SLA tracking
  • CVD policy (auto-published)
  • Actively exploited vulnerability flagging
  • Severe security incident tracking
  • Submission type classification (vulnerability / incident / both)
  • PGP encrypted communication
  • Compliance audit trail
  • 1 team member

Includes 14-day Compliance trial

September 2026 Reporting

Reporting

€99/month

Billed annually as €1,188

Article 14 authority filing plus the full CRA vulnerability handling process (Annex I Part II)

Typical fit: SMEs with products on the EU market that must file Article 14 notifications from September 2026.

Everything in Free, plus
  • Unlimited products covered for disclosure
  • Single Reporting Platform (SRP)-ready submission package*
  • Article 14 notification workflow (24h / 72h / 14d)
  • SBOM registry (SPDX / CycloneDX)
  • Hardware component registry
  • CVSS 3.1 / 4.0 severity scoring
  • Remediation decision & timeline tracking
  • CSAF 2.0 (Common Security Advisory Framework) advisory export
  • NVD and EU Vulnerability Database (EUVD) threat intelligence feeds
  • Monitoring source configuration
  • Security test & review scheduling
  • CRA-CVD obligation matrix (26 articles, 105 artifacts)
  • 8 auto-drafted policy documents
  • Compliance analytics dashboard
  • Coordinator assignment workflow
  • Post-release action tracking
  • Up to 3 team members
  • Priority support

14-day free trial · No credit card required

December 2027 Conformity

Compliance

€299/month

Billed annually as €3,588

CRA self-assessment for default-class products. Risk assessment through to the EU Declaration of Conformity (Module A)***

Typical fit: SMEs running the CRA self-assessment under Module A ahead of December 2027.

Everything in Reporting, plus
  • Annex I Part I cybersecurity risk assessment
  • STRIDE threat modelling (six-category threat taxonomy) and control mapping
  • Product classification (default / Class I / II / critical)
  • Conformity route selection (Art. 32 modules)
  • 21-requirement Annex I self-assessment checklist
  • Clause 6 and 7 artifact drafting with gap analysis
  • EU Declaration of Conformity draft (Annex V)
  • Technical documentation index and export (Annex VII)
  • CE marking guidance (Art. 29-30)
  • Annex II user-information sheet and support period
  • Monitoring triggers and immutable assessment snapshots
  • CRA exposure scanner
  • 3 CRA product assessments included, then €99 per assessment each month
  • Up to 5 team members

14-day free trial · No credit card required

Everything, at scale

Enterprise

€1,499/month

Billed annually as €17,988

Every module at scale, with 25 CRA product assessments included and dedicated support

Typical fit: manufacturers with large product portfolios, SSO and API integration needs, or notified-body evidence requirements.

Everything in Compliance, plus
  • 25 CRA product assessments included, then €99 per assessment each month
  • Notified-body conformity evidence package
  • Trust portal: cvd.yourdomain.com
  • Automated SBOM ↔ CVE supply chain alerts
  • EUDI Wallet identity verification (eIDAS 2.0)
  • Slack, Teams & Discord notifications + custom webhooks
  • CVE ID assistance
  • API access
  • SSO / SAML integration
  • Up to 10 team members
  • Custom branding & whitelabel
  • Customer-facing trust portal for approved viewers
  • Audit-ready compliance reports
  • Dedicated account manager
  • 99.9% uptime SLA

What becomes mandatory on 11 September 2026

Article 14, CRA Regulation (EU) 2024/2847 makes vulnerability and incident notification via ENISA's Single Reporting Platform (SRP) mandatory. It applies to products with digital elements in CRA scope. Receiving and tracking disclosures is free, and the SRP-ready filing package is on Reporting.

Actively Exploited Vulnerabilities
Art. 14(2)
24 hours
Early warning
Awareness of active exploitation
REPORTING
72 hours
Full notification
Exploit details + corrective measures
REPORTING
14 days
Final report
After corrective measure available
REPORTING
Severe Security Incidents
Art. 14(4)
24 hours
Early warning
Awareness of severe incident
REPORTING
72 hours
Incident notification
Incident details + impact assessment
REPORTING
1 month
Final report
After incident notification
REPORTING
Triggers mandatory reporting
  • !Reliable evidence of malicious exploitation in the wild
  • !Severe incident impacting security of a product with digital elements
  • !Zero-day vulnerabilities under active attack
Does not trigger mandatory reporting
  • Good-faith security research with no evidence of malicious exploitation
  • Vulnerabilities discovered but not yet exploited
  • Voluntary reports under Article 15 (still recommended)

Feature comparison

Free receives and tracks disclosures. Reporting adds Article 14 filing and the full CRA vulnerability handling process. Compliance adds the CRA self-assessment through to the EU Declaration of Conformity. Products that need a notified body use the same workspace to prepare the technical file for that route. Enterprise adds scale, integrations and third-party assurance.

CapabilityFreeReportingComplianceEnterprise
Article 14 reporting: September 2026
Public submission portal with tracking IDs
48h acknowledgment SLA tracking
CVD policy (auto-published)
Actively exploited vulnerability flagging
Severe security incident tracking
Submission type classification
PGP encrypted communication
Compliance audit trail
Article 14 notification workflow (24h / 72h / 14d)
SRP-ready submission package*
Vulnerability handling (Reporting): December 2027
SBOM registry (SPDX / CycloneDX)
Hardware component registry
CVSS 3.1 / 4.0 severity scoring
Remediation decision & timeline tracking
CSAF 2.0 advisory export
NVD / EUVD threat intelligence feeds
Monitoring source configuration
Security test & review scheduling
CRA-CVD obligation matrix (26 articles)
8 auto-drafted policy documents
Compliance analytics dashboard
Coordinator assignment workflow
Post-release action tracking
CRA self-assessment (Compliance): December 2027
Annex I Part I cybersecurity risk assessment
STRIDE threat modelling and control mapping
Product classification (default / Class I / II / critical)
Conformity route selection (Art. 32 modules)
21-requirement Annex I self-assessment checklist
Clause 6 and 7 artifact drafting with gap analysis
EU Declaration of Conformity draft (Annex V)**
Technical documentation index and export (Annex VII)
CE marking guidance (Art. 29-30)
Annex II user-information sheet and support period
Monitoring triggers and immutable assessment snapshots
CRA exposure scanner
Enterprise scale
Notified-body conformity evidence package
Automated SBOM ↔ CVE supply chain alerts
API access
Custom branding & whitelabel
EUDI Wallet identity verification (eIDAS 2.0)
Slack, Teams & Discord notifications
Custom webhook integrations
CVE ID assistance
SSO / SAML integration
Customer-facing trust portal
Audit-ready compliance reports
Dedicated account manager
Products covered for vulnerability disclosureUnlimitedUnlimitedUnlimitedUnlimited
CRA product assessments3 included25 included
Team members13510

* ENISA provides no submission API at this stage. CVD Portal produces an SRP-ready package for one-step manual submission, and automated filing follows once ENISA publishes an API.

** No CRA harmonised standard is cited in the Official Journal yet, so no presumption of conformity is available. Compliance produces the documented evidence the regulation requires you to hold.

*** Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

Features evolve with EU regulatory requirements (CRA, NIS2, eIDAS 2.0). Feature availability may change as legislation is clarified or updated by the European Commission.

Frequently asked questions

What exactly must I comply with by 11 September 2026?

Article 14 of the CRA mandates that manufacturers notify ENISA of actively exploited vulnerabilities and severe security incidents via the Single Reporting Platform. You must submit an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days (vulnerabilities) or 1 month (incidents). This applies to products with digital elements in CRA scope, including ones still within their support lifecycle. The Free tier receives and tracks the disclosures behind these obligations, and the SRP-ready filing package is on Reporting.

Do the product limits restrict which products researchers can disclose vulnerabilities for?

No. Vulnerability intake is unlimited on every tier, including Free. Any product you sell can receive disclosures through your portal, with no per-product limit. The "3" and "25" figures count CRA product assessments, the guided self-assessment workspaces where each product is taken through classification, risk assessment and its EU Declaration of Conformity. A product on a third-party route uses the same workspace to prepare its technical file.

What does the Free tier cover?

The Free tier receives and tracks vulnerability disclosures. It gives you a public submission portal, submission tracking, acknowledgment SLA tracking, secure communication, and an audit trail. When you need to file under Article 14, Reporting adds the SRP-ready submission package for the 24h, 72h and final notifications.

When do I need the Reporting tier?

Reporting is where Article 14 filing happens. It adds the SRP-ready submission package for the 24h, 72h and final notifications, alongside the full CRA vulnerability handling that takes effect on 11 December 2027, covering SBOM management, security testing, remediation tracking and CSAF advisories. We recommend upgrading to Reporting well before you need to file.

Does Article 14 apply to products already on the market?

Yes. Reporting obligations apply to all products with digital elements falling within the CRA scope, including products placed on the market before 11 December 2027. If your product is still on the market and within its support lifecycle, you must notify actively exploited vulnerabilities from 11 September 2026.

Why is Free really free?

CVD Portal is free for receiving and tracking vulnerability disclosures because we want to be the disclosure layer for thousands of EU manufacturers. We make money when companies upgrade to file under Article 14 and run the full CRA workflow, with the SRP-ready submission package, SBOM management, security testing and CSAF advisories. That is the entire model. We do not sell data, run ads, or harvest vulnerability disclosures.

Who owns the disclosure data?

You do. You own every disclosure your portal receives. Full export in CSV and JSON is available on every plan, including Free, so you can take your data with you at any time.

What happens if I cancel?

Your portal stays read-only and your export stays available. You keep access to your submission history and audit trail, and you can download everything before you go.

Can I file under Article 14 on the Free tier?

The Free tier receives and tracks disclosures with the submission portal, SLA tracking and an audit trail. Filing under Article 14 is on Reporting, which adds the SRP-ready submission package for the 24h, 72h and final notifications plus the full CRA vulnerability handling for the December 2027 deadline.

What payment methods do you accept?

We accept all major credit cards. Enterprise customers can pay by invoice. You can upgrade, downgrade, or cancel at any time.