CYBER RESILIENCE ACT · ARTICLE 14
CRA IncidentOps guides the manufacturer's team from the first signal to submitting the Early Warning, Notification and Final Report through the ENISA Single Reporting Platform — with tasks, escalations, approvals and an evidence trail.
The Article 14 obligation applies from 11 September 2026. An authorised employee submits in SRP; the service prepares, checks and documents every step.
24 hours, 72 hours and the final report: 14 days after a measure for AEV, one month after the notification for a severe incident. A signal never starts the clock — a person records the decision.
Early Warning, Notification and Final Report fields per Glossary version, completeness checks, approval, a snapshot of submitted data and the SRP receipt.
Dependent tasks for Product, Security, Legal and the Assigned Representative. Escalations by e-mail, Slack, Teams, PagerDuty, Opsgenie and SMS, and an on-call schedule.
Audit log with a hash chain, files with SHA-256 and access levels, decisions with version history, a ZIP dossier per case for auditors or supervisors.
Jira, GitHub, GitLab, Sentry, PagerDuty and your own sources. SBOM monitoring against CISA KEV and EPSS. Deduplication and a retrying queue.
SSO (OpenID Connect), MFA, roles with permissions down to individual fields, restricted cases for embargoed vulnerabilities, a separate database for every organisation.
On request
Small manufacturer: Article 14 process, e-mail/Slack/Teams, drills and dossiers.
On request
PSIRT teams: SSO, paging and SMS, API and webhooks, SBOM monitoring, CSAF/VEX.
On request
No limits, dedicated instance, external audit log anchoring, contractual SLA.
Prices exclude VAT. The reverse charge applies to EU companies with a VAT ID. Non-payment never interrupts work on an open incident: 30 days to finish and export.