SME Cyber Resilience Maturity Assessment
Rate your product security practice across 25 questions in 5 domains. Get a maturity score, a RAG breakdown and a tailored CRA improvement checklist. Nothing stored on our servers.
Free Developer & Compliance Tools
CVD Portal offers free Cyber Resilience Act tools for manufacturers, including an Article 14 deadline calculator, a CVD policy generator, a security.txt generator, SBOM validators and a CSAF 2.0 advisory validator.
Rate your product security practice across 25 questions in 5 domains. Get a maturity score, a RAG breakdown and a tailored CRA improvement checklist. Nothing stored on our servers.
Work out which CRA role you hold for an open-source project. Applies the Article 3(48) test, the monetisation tests from Commission guidance C(2026) 5252, and the graduated Article 24(3) reporting duties. Nothing stored on our servers.
Enter the date and time you became aware of an actively exploited vulnerability or severe security incident. Get your exact Article 14 notification deadlines for ENISA reporting.
Article 64 of Regulation (EU) 2024/2847 establishes administrative fines up to €15,000,000 or 2.5% of worldwide turnover. Regulatory liability falls as conformity artifacts are completed and maintained.
A 20-question check of your readiness to handle and report vulnerabilities under CRA Articles 13 and 14. Focused on coordinated disclosure, acknowledgment turnaround, ENISA reporting and advisories. For a whole-programme view across all five CRA domains, use the CRA Maturity Assessment.
Paste your CSAF 2.0 JSON advisory and instantly validate the structure against the OASIS CSAF 2.0 schema. Identifies missing mandatory fields, invalid values, and flags common issues that would cause rejection by automated consumers and ENISA tooling.
Build a complete, publication-ready CVD policy document using a guided five-step wizard. Configure your response timelines, CRA Article 13 and 14 obligations, and product scope, then export a finished Markdown policy you can publish immediately.
Score a vulnerability with CVSS v4.0 using Base, Threat, and Environmental metrics. The MacroVector equivalence class displays alongside the vector so the result can be verified against the specification. A vector can be supplied in the URL to share or re-check a score.
Calculate CVSS 3.1 base scores for vulnerability severity assessment. Includes guidance on whether the score triggers Article 14 notification obligations under the EU Cyber Resilience Act.
Enter a vulnerability report date and instantly see every critical deadline: Article 14 early warning, full notification, final report to ENISA, researcher 90-day embargo, and your internal acknowledgment SLA. Colour-coded status keeps you on track.
Build a complete Article 14 early-warning notification based on the fields required by CRA Article 14(2). Fill in your product details, exploitation status, and mitigation actions, then copy the finished notification text ready for submission to ENISA or your national CSIRT.
Article 14 of Regulation (EU) 2024/2847 obliges manufacturers to report actively exploited vulnerabilities and severe security incidents to ENISA and designated CSIRTs within 24 hours. Vulnerabilities without active exploitation do not trigger statutory reporting.
The SBOM checker matches software components against the NVD CVE database. Paste a component list in package@version form and the tool returns one NVD search link for each component, with no upload and no account.
Upload or paste a CycloneDX, SPDX JSON document or dependency manifest to scan all declared components against the OSV.dev open vulnerability database. The scanner identifies known CVEs and security advisories with precise version matching, returning an immediate severity breakdown across Critical, High, Medium, and Low vulnerabilities alongside top exposed components. The live interactive scanner is available at /sbom-exposure with no registration required. The tool operates in-request and does not store your SBOM data on our servers. For continuous vulnerability monitoring and full CRA Annex I Part II(1) due diligence, CVD Portal integrates SBOM ingestion with automated alerting and CSAF 2.0 advisory generation.
Upload or paste a CycloneDX or SPDX JSON SBOM and check it against BSI TR-03183-2 v2.1.0, the German federal guideline that concretises the CRA SBOM requirement. The validator verifies the minimum specification version of CycloneDX 1.6 or SPDX 3.0.1. It checks every required data field for the SBOM and for each component, including creator, timestamp, dependencies, licences, and hashes. Validation runs entirely in your browser. The same document is also assessed against the 2026 Minimum Elements for a Software Bill of Materials, version 2.1. CISA published this specification with seventeen partner agencies, including seven EU national cybersecurity authorities. That document replaced the 2021 NTIA minimum elements and expanded the field count from seven to seventeen. It is not EU law and creates no CRA obligation, but it is increasingly what procurement asks for. The two verdicts are reported separately and never blended because the frameworks disagree on key requirements. TR-03183-2 sets minimum format versions that the 2026 elements do not. In addition, the 2026 elements require transitive dependency coverage that CRA Annex I Part II(1) does not.
Generate a standards-compliant security.txt file (RFC 9116) for your product or website. The EU Cyber Resilience Act names no file format, and Annex I Part II point 6 requires a contact address for reporting vulnerabilities. security.txt is the machine-readable way to publish it.
CVD Portal unites these tools into a coordinated vulnerability disclosure workflow. Get a public portal, 48-hour acknowledgment tracking, audit logs, and CSAF generation. Receiving reports is free.
Create my free CVD portalCreate your free CVD portal