Set up your vulnerability disclosure portal before the CRA deadline.
From 11 September 2026, manufacturers selling products with digital elements into the EU must handle vulnerability disclosures and notify authorities on fixed deadlines. CVD Portal gives you a branded, audit-ready disclosure portal today.
Free CRA exposure scan
Is your domain exposed under the CRA?
Enter your domain to check whether it meets the Article 13 baseline disclosure expectation: a working security.txt and a discoverable coordinated vulnerability disclosure policy. Results in a few seconds, no signup.
Probes /.well-known/security.txt + 5 CVD policy paths. No data is shared with third parties. Up to 5 scans per hour.
The price of doing nothing is written into the law.
Up to €15 million or 2.5% of worldwide turnover
Breaching the essential cybersecurity obligations carries administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher (Art. 64(2)).
Products can be restricted or pulled from the EU market
Market surveillance authorities can require corrective action, restrict availability, or prohibit a non-compliant product on the EU market.
Enterprise buyers ask for a published CVD process
Procurement and security teams increasingly require a documented coordinated vulnerability disclosure process before they sign.
The free plan receives and tracks disclosures. Article 14 filing is on Reporting. Here is what it includes.
Beyond disclosure
Disclosure is one obligation. The CRA asks manufacturers for the whole conformity journey.
Receiving, acknowledging, and tracking vulnerability disclosures is free and covers the Article 13(2) handling side. Filing Article 14 notifications with the SRP-ready package is on Reporting. Classifying your products, assessing cybersecurity risk, meeting the Annex I requirements, and drawing up the EU Declaration of Conformity is the full self-assessment, and it runs in the same workspace on the Compliance plan. Module A self-assessment is the route for default-class products. For important and critical products the same workspace produces the technical file a notified body assesses.
One journey, from first disclosure to CE marking.
Receive disclosures
A branded disclosure portal on your own subdomain with a published CVD policy and 48-hour acknowledgment tracking. Covers the Article 13(2) handling obligation, free.
File on the clock
When a vulnerability is actively exploited, the 24-hour, 72-hour, and 14-day Article 14 timers start. The SRP-ready filing package is prepared for manual submission, on Reporting.
Classify and assess
Classify each product under Annex III and IV, pick the Article 32 conformity route, and run the cybersecurity risk assessment.
Declare conformity
Close the Annex I gaps, assemble the technical file, and draw up the EU Declaration of Conformity for CE marking.
A working portal you can click through.
Researchers submit through a branded intake form with PGP support. Your team triages disclosures, tracks acknowledgment deadlines, and exports the evidence trail. Every submission is logged from the moment it arrives. Try it on the portal of Aurelia Devices B.V., a fictional manufacturer running on CVD Portal. We email you a single-use link, no account needed.

Everything the Cyber Resilience Act asks of a manufacturer
One workspace covering all five CRA obligation areas, from product classification and risk assessment through documentation, vulnerability handling, and authority reporting.
Disclosure intake and acknowledgment are free. The self-assessment suite is on the Compliance plan, covering Module A for default-class products and the technical file for products that need a notified body.
Product Classification and Conformity Route
Answer the Annex III and IV questions for each product. The engine determines whether the product is default, important, or critical and which Article 32 conformity assessment route applies.
STRIDE Risk Assessment
A structured threat model per product with likelihood and impact scoring across 33 security objectives, feeding directly into the Annex I requirements work.
Essential Requirements and Gap Analysis
Work through the 22-row Annex I essential requirements checklist. Gap analysis shows what is open and remediation guidance shows how to close it.
Technical File and Declaration of Conformity
Draft artifacts clause by clause with AI assistance across 88 CRA clause artifacts, then generate the EU Declaration of Conformity, the Annex VII documentation index, and the Annex II user information sheet, with CE marking guidance.
Disclosure Portal and Article 14 Reporting
A branded intake portal on your own subdomain with structured submissions, PGP, security.txt, and a full audit trail. Article 14 milestones to ENISA/CSIRT run on fixed deadlines with SRP-ready packages.
Partners, Trust Portal, and Integrations
Assess supply chain partners with CVD scanning, VEX, and SBOM matching. Share conformity documents with approved external viewers through a trust portal, with API access and SAML SSO.
Are You CRA Ready?
Industry context
“Organisations increasingly recognise that software development nowadays requires an active, positive response to vulnerability reports, which strengthens security and is becoming a strong selling point when handled properly.”
EU buyers and market surveillance authorities increasingly expect manufacturers to show a documented CRA position. CVD Portal gives you a structured assessment, the technical file to back it, and a published disclosure process.
CRA Entered Into Force
Regulation (EU) 2024/2847, published in the Official Journal on 20 November 2024
Article 14 Reporting Begins
Vulnerability notification obligations apply to products in scope
Full Conformity Deadline
Annex I essential requirements, technical documentation, and CE marking apply
Simple, transparent pricing
See full pricing →Receive, track, and acknowledge disclosures
Article 14 authority filing + full CVD compliance
CRA self-assessment through to the EU Declaration of Conformity
Every module at scale, 25 CRA product assessments included, integrations, EUDI identity
Germany's BSI Measured security.txt Adoption at 1.8 Percent. We Measured Manufacturers and Found the Same Hole
The BSI and the Allianz für Cyber-Sicherheit published a measurement of German website operators on 6 August 2026. Two independent scans of two different populations now point the same way, five weeks before Article 14 applies.
6 min readCRA ComplianceWhat a CRA Maturity Score Actually Predicts
ENISA published its SME Cyber Resilience Maturity Assessment Model on 13 July 2026, and it is explicit that an advanced score is not evidence of CRA compliance. So what is the score for? Maturity measures how consistently your organisation works. Conformity measures whether one product has the evidence behind it. Why an Advanced organisation can still ship a non-conforming product, why a Level 2 team can ship a conforming one, and how to use the score for the thing it is genuinely good at, which is sequencing the work.
8 min readCRA ComplianceArticle 14 Applies in Five Weeks. Run This Drill Before It Does.
On 11 September 2026 the CRA's reporting duties become binding, and the first clock that matters runs for 24 hours from the moment you become aware. Most manufacturers can recite the deadlines and still miss them, because the gap is never knowledge, it is not knowing who files, from which account, to which CSIRT. Here is a walk-through drill that surfaces the gaps while they are still cheap.
10 min readSet up your disclosure portal before September 2026
A branded, audit-ready portal for manufacturers selling products with digital elements into the EU. Free to receive and track disclosures. Article 14 filing is on Reporting. Still mapping your obligations? Start with the EU Cyber Resilience Act guide.