CRA-Portal.eu   ← back to website
Self-service · no login needed

CRA Incident Response builder & tabletop drill

The Cyber Resilience Act reporting obligations (Article 14) start applying 11 September 2026. This tool turns those requirements into a working process you can actually run under pressure — a RACI, the 24h/72h/final-report workflow, an incident-intake template, escalation & approval steps, a standard operating procedure and an evidence checklist. Then rehearse it with a built-in tabletop drill. Fill it in, generate, print — all in your browser.

operational, not legal advice This produces an operational template. It is not legal or security advice; verify against the current CRA text and delegated/implementing acts. Provisional items are marked.

1 · Your setup

CRA-Portal · Cyber Resilience Act (EU) 2024/2847. This operational template supports Article 14 incident/vulnerability reporting. Deadlines: early warning ≤ 24h, notification ≤ 72h, final report ≤ 14 days after a corrective or mitigating measure is available (vulnerabilities) or ≤ 1 month after the 72h notification (severe incidents). Source: ENISA SRP FAQ, updated 8 September 2026. Contact: info@cra-portal.eu