Pricing
Free to receive and track vulnerability disclosures. Article 14 filing on Reporting. CRA self-assessment and the EU Declaration of Conformity on Compliance.
11 September 2026
Article 14 reporting obligations take effect. Manufacturers must notify ENISA of actively exploited vulnerabilities and severe security incidents within 24h / 72h / 14 days.
11 December 2027
Full CRA conformity. Annex I risk assessment, product classification, technical documentation, the conformity assessment and the EU Declaration of Conformity.
Free
Free forever. Receive and track vulnerability disclosures with a public portal, SLA tracking and an audit trail.
Typical fit: any manufacturer that needs a compliant public disclosure channel today.
- Unlimited products covered for disclosure
- Public vulnerability submission portal
- Submission tracking with unique IDs
- 48h acknowledgment SLA tracking
- CVD policy (auto-published)
- Actively exploited vulnerability flagging
- Severe security incident tracking
- Submission type classification (vulnerability / incident / both)
- PGP encrypted communication
- Compliance audit trail
- 1 team member
Includes 14-day Compliance trial
Reporting
Billed annually as €1,188
Article 14 authority filing plus the full CRA vulnerability handling process (Annex I Part II)
Typical fit: SMEs with products on the EU market that must file Article 14 notifications from September 2026.
- Unlimited products covered for disclosure
- Single Reporting Platform (SRP)-ready submission package*
- Article 14 notification workflow (24h / 72h / 14d)
- SBOM registry (SPDX / CycloneDX)
- Hardware component registry
- CVSS 3.1 / 4.0 severity scoring
- Remediation decision & timeline tracking
- CSAF 2.0 (Common Security Advisory Framework) advisory export
- NVD and EU Vulnerability Database (EUVD) threat intelligence feeds
- Monitoring source configuration
- Security test & review scheduling
- CRA-CVD obligation matrix (26 articles, 105 artifacts)
- 8 auto-drafted policy documents
- Compliance analytics dashboard
- Coordinator assignment workflow
- Post-release action tracking
- Up to 3 team members
- Priority support
14-day free trial · No credit card required
Compliance
Billed annually as €3,588
CRA self-assessment for default-class products. Risk assessment through to the EU Declaration of Conformity (Module A)***
Typical fit: SMEs running the CRA self-assessment under Module A ahead of December 2027.
- Annex I Part I cybersecurity risk assessment
- STRIDE threat modelling (six-category threat taxonomy) and control mapping
- Product classification (default / Class I / II / critical)
- Conformity route selection (Art. 32 modules)
- 21-requirement Annex I self-assessment checklist
- Clause 6 and 7 artifact drafting with gap analysis
- EU Declaration of Conformity draft (Annex V)
- Technical documentation index and export (Annex VII)
- CE marking guidance (Art. 29-30)
- Annex II user-information sheet and support period
- Monitoring triggers and immutable assessment snapshots
- CRA exposure scanner
- 3 CRA product assessments included, then €99 per assessment each month
- Up to 5 team members
14-day free trial · No credit card required
Enterprise
Billed annually as €17,988
Every module at scale, with 25 CRA product assessments included and dedicated support
Typical fit: manufacturers with large product portfolios, SSO and API integration needs, or notified-body evidence requirements.
- 25 CRA product assessments included, then €99 per assessment each month
- Notified-body conformity evidence package
- Trust portal: cvd.yourdomain.com
- Automated SBOM ↔ CVE supply chain alerts
- EUDI Wallet identity verification (eIDAS 2.0)
- Slack, Teams & Discord notifications + custom webhooks
- CVE ID assistance
- API access
- SSO / SAML integration
- Up to 10 team members
- Custom branding & whitelabel
- Customer-facing trust portal for approved viewers
- Audit-ready compliance reports
- Dedicated account manager
- 99.9% uptime SLA
What becomes mandatory on 11 September 2026
Article 14, CRA Regulation (EU) 2024/2847 makes vulnerability and incident notification via ENISA's Single Reporting Platform (SRP) mandatory. It applies to products with digital elements in CRA scope. Receiving and tracking disclosures is free, and the SRP-ready filing package is on Reporting.
- !Reliable evidence of malicious exploitation in the wild
- !Severe incident impacting security of a product with digital elements
- !Zero-day vulnerabilities under active attack
- Good-faith security research with no evidence of malicious exploitation
- Vulnerabilities discovered but not yet exploited
- Voluntary reports under Article 15 (still recommended)
Feature comparison
Free receives and tracks disclosures. Reporting adds Article 14 filing and the full CRA vulnerability handling process. Compliance adds the CRA self-assessment through to the EU Declaration of Conformity. Products that need a notified body use the same workspace to prepare the technical file for that route. Enterprise adds scale, integrations and third-party assurance.
| Capability | Free | Reporting | Compliance | Enterprise |
|---|---|---|---|---|
| Article 14 reporting: September 2026 | ||||
| Public submission portal with tracking IDs | ||||
| 48h acknowledgment SLA tracking | ||||
| CVD policy (auto-published) | ||||
| Actively exploited vulnerability flagging | ||||
| Severe security incident tracking | ||||
| Submission type classification | ||||
| PGP encrypted communication | ||||
| Compliance audit trail | ||||
| Article 14 notification workflow (24h / 72h / 14d) | — | |||
| SRP-ready submission package* | — | |||
| Vulnerability handling (Reporting): December 2027 | ||||
| SBOM registry (SPDX / CycloneDX) | — | |||
| Hardware component registry | — | |||
| CVSS 3.1 / 4.0 severity scoring | — | |||
| Remediation decision & timeline tracking | — | |||
| CSAF 2.0 advisory export | — | |||
| NVD / EUVD threat intelligence feeds | — | |||
| Monitoring source configuration | — | |||
| Security test & review scheduling | — | |||
| CRA-CVD obligation matrix (26 articles) | — | |||
| 8 auto-drafted policy documents | — | |||
| Compliance analytics dashboard | — | |||
| Coordinator assignment workflow | — | |||
| Post-release action tracking | — | |||
| CRA self-assessment (Compliance): December 2027 | ||||
| Annex I Part I cybersecurity risk assessment | — | — | ||
| STRIDE threat modelling and control mapping | — | — | ||
| Product classification (default / Class I / II / critical) | — | — | ||
| Conformity route selection (Art. 32 modules) | — | — | ||
| 21-requirement Annex I self-assessment checklist | — | — | ||
| Clause 6 and 7 artifact drafting with gap analysis | — | — | ||
| EU Declaration of Conformity draft (Annex V)** | — | — | ||
| Technical documentation index and export (Annex VII) | — | — | ||
| CE marking guidance (Art. 29-30) | — | — | ||
| Annex II user-information sheet and support period | — | — | ||
| Monitoring triggers and immutable assessment snapshots | — | — | ||
| CRA exposure scanner | — | — | ||
| Enterprise scale | ||||
| Notified-body conformity evidence package | — | — | — | |
| Automated SBOM ↔ CVE supply chain alerts | — | — | — | |
| API access | — | — | — | |
| Custom branding & whitelabel | — | — | — | |
| EUDI Wallet identity verification (eIDAS 2.0) | — | — | — | |
| Slack, Teams & Discord notifications | — | — | — | |
| Custom webhook integrations | — | — | — | |
| CVE ID assistance | — | — | — | |
| SSO / SAML integration | — | — | — | |
| Customer-facing trust portal | — | — | — | |
| Audit-ready compliance reports | — | — | — | |
| Dedicated account manager | — | — | — | |
| Products covered for vulnerability disclosure | Unlimited | Unlimited | Unlimited | Unlimited |
| CRA product assessments | — | — | 3 included | 25 included |
| Team members | 1 | 3 | 5 | 10 |
* ENISA provides no submission API at this stage. CVD Portal produces an SRP-ready package for one-step manual submission, and automated filing follows once ENISA publishes an API.
** No CRA harmonised standard is cited in the Official Journal yet, so no presumption of conformity is available. Compliance produces the documented evidence the regulation requires you to hold.
*** Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
Features evolve with EU regulatory requirements (CRA, NIS2, eIDAS 2.0). Feature availability may change as legislation is clarified or updated by the European Commission.
Frequently asked questions
What exactly must I comply with by 11 September 2026?
Article 14 of the CRA mandates that manufacturers notify ENISA of actively exploited vulnerabilities and severe security incidents via the Single Reporting Platform. You must submit an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days (vulnerabilities) or 1 month (incidents). This applies to products with digital elements in CRA scope, including ones still within their support lifecycle. The Free tier receives and tracks the disclosures behind these obligations, and the SRP-ready filing package is on Reporting.
Do the product limits restrict which products researchers can disclose vulnerabilities for?
No. Vulnerability intake is unlimited on every tier, including Free. Any product you sell can receive disclosures through your portal, with no per-product limit. The "3" and "25" figures count CRA product assessments, the guided self-assessment workspaces where each product is taken through classification, risk assessment and its EU Declaration of Conformity. A product on a third-party route uses the same workspace to prepare its technical file.
What does the Free tier cover?
The Free tier receives and tracks vulnerability disclosures. It gives you a public submission portal, submission tracking, acknowledgment SLA tracking, secure communication, and an audit trail. When you need to file under Article 14, Reporting adds the SRP-ready submission package for the 24h, 72h and final notifications.
When do I need the Reporting tier?
Reporting is where Article 14 filing happens. It adds the SRP-ready submission package for the 24h, 72h and final notifications, alongside the full CRA vulnerability handling that takes effect on 11 December 2027, covering SBOM management, security testing, remediation tracking and CSAF advisories. We recommend upgrading to Reporting well before you need to file.
Does Article 14 apply to products already on the market?
Yes. Reporting obligations apply to all products with digital elements falling within the CRA scope, including products placed on the market before 11 December 2027. If your product is still on the market and within its support lifecycle, you must notify actively exploited vulnerabilities from 11 September 2026.
Why is Free really free?
CVD Portal is free for receiving and tracking vulnerability disclosures because we want to be the disclosure layer for thousands of EU manufacturers. We make money when companies upgrade to file under Article 14 and run the full CRA workflow, with the SRP-ready submission package, SBOM management, security testing and CSAF advisories. That is the entire model. We do not sell data, run ads, or harvest vulnerability disclosures.
Who owns the disclosure data?
You do. You own every disclosure your portal receives. Full export in CSV and JSON is available on every plan, including Free, so you can take your data with you at any time.
What happens if I cancel?
Your portal stays read-only and your export stays available. You keep access to your submission history and audit trail, and you can download everything before you go.
Can I file under Article 14 on the Free tier?
The Free tier receives and tracks disclosures with the submission portal, SLA tracking and an audit trail. Filing under Article 14 is on Reporting, which adds the SRP-ready submission package for the 24h, 72h and final notifications plus the full CRA vulnerability handling for the December 2027 deadline.
What payment methods do you accept?
We accept all major credit cards. Enterprise customers can pay by invoice. You can upgrade, downgrade, or cancel at any time.