← All tools
Free Tool

CVSS Calculator

Calculate CVSS 3.1 base scores for vulnerability severity assessment. Includes guidance on whether the score triggers Article 14 notification obligations under the EU Cyber Resilience Act.

Last updated 29 August 2026

Key takeaways

  1. CVSS 3.1 rates vulnerability severity on a scale from 0 to 10 across None, Low, Medium, High, and Critical bands.
  2. Article 14 mandatory notifications require active exploitation or severe security incidents rather than a standalone CVSS severity score.
  3. High and Critical severity vulnerabilities without exploitation evidence require standard coordinated vulnerability disclosure handling rather than statutory ENISA filings.
  4. Machine-readable CSAF 2.0 security advisories require recorded CVSS scores to document vulnerability severity ratings.
0.0
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Article 14 threshold
Below critical threshold

Art. 14 is triggered by active exploitation — not CVSS alone.

0.0None
0.1 – 3.9Low
4.0 – 6.9Medium
7.0 – 8.9High
9.0 – 10.0Critical

Frequently asked

What is CVSS?+

CVSS (Common Vulnerability Scoring System) is the industry-standard framework for assessing the severity of security vulnerabilities. Version 3.1 is the most widely used. Scores range from 0 to 10: None (0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), Critical (9.0–10.0).

Does CVSS score determine Article 14 obligations?+

Not directly. Article 14 is triggered by active exploitation or a severe security incident - not by CVSS score alone. However, a Critical CVSS score combined with evidence of exploitation is strong grounds for Article 14 notification. A High or Critical score without exploitation evidence still requires standard CVD handling but not mandatory ENISA notification.

Should I use CVSS 3.1 or 4.0?+

CVSS 4.0 was released in 2023 and offers more granular scoring. Most current tools and databases still use CVSS 3.1. CVD Portal records both - this calculator uses CVSS 3.1 as it remains the most widely supported.

Is the CVSS score included in CSAF advisories?+

Yes - CVSS scores are a required field in CSAF 2.0 advisories. CVD Portal pre-populates your CSAF advisory with the CVSS score recorded during triage.

Other free CRA tools

Article 14 Deadline CalculatorEnter the date and time you became aware of an actively exploited vulnerability or severe security incident. Get your exact Article 14 notification deadlines for ENISA reporting.CRA Vulnerability Disclosure Readiness CheckA 20-question check of your readiness to handle and report vulnerabilities under CRA Articles 13 and 14. Focused on coordinated disclosure, acknowledgment turnaround, ENISA reporting and advisories. For a whole-programme view across all five CRA domains, use the CRA Maturity Assessment.CSAF 2.0 Advisory ValidatorPaste your CSAF 2.0 JSON advisory and instantly validate the structure against the OASIS CSAF 2.0 schema. Identifies missing mandatory fields, invalid values, and flags common issues that would cause rejection by automated consumers and ENISA tooling.CVD Policy GeneratorBuild a complete, publication-ready CVD policy document using a guided five-step wizard. Configure your response timelines, CRA Article 13 and 14 obligations, and product scope, then export a finished Markdown policy you can publish immediately.CVSS 4.0 CalculatorScore a vulnerability with CVSS v4.0 using Base, Threat, and Environmental metrics. The MacroVector equivalence class displays alongside the vector so the result can be verified against the specification. A vector can be supplied in the URL to share or re-check a score.Disclosure Deadline TrackerEnter a vulnerability report date and instantly see every critical deadline: Article 14 early warning, full notification, final report to ENISA, researcher 90-day embargo, and your internal acknowledgment SLA. Colour-coded status keeps you on track.

Ready to automate your CVD programme?

CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.

Start your free portal →