Set up your vulnerability disclosure portal before the CRA deadline.
From 11 September 2026, manufacturers selling products with digital elements into the EU must handle vulnerability disclosures and notify authorities on fixed deadlines. CVD Portal gives you a branded, audit-ready disclosure portal today.
Free CRA exposure scan
Is your domain exposed under the CRA?
Enter your domain to check whether it meets the Article 13 baseline disclosure expectation: a working security.txt and a discoverable coordinated vulnerability disclosure policy. Results in a few seconds, no signup.
Probes /.well-known/security.txt + 5 CVD policy paths. No data is shared with third parties. Up to 5 scans per hour.
The price of doing nothing is written into the law.
Up to €15 million or 2.5% of worldwide turnover
Breaching the essential cybersecurity obligations carries administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher (Art. 64(2)).
Products can be restricted or pulled from the EU market
Market surveillance authorities can require corrective action, restrict availability, or prohibit a non-compliant product on the EU market.
Enterprise buyers ask for a published CVD process
Procurement and security teams increasingly require a documented coordinated vulnerability disclosure process before they sign.
The free plan receives and tracks disclosures. Article 14 filing is on Reporting. Here is what it includes.
Beyond disclosure
Disclosure is one obligation. The CRA asks manufacturers for the whole conformity journey.
Receiving, acknowledging, and tracking vulnerability disclosures is free and covers the Article 13(2) handling side. Filing Article 14 notifications with the SRP-ready package is on Reporting. Classifying your products, assessing cybersecurity risk, meeting the Annex I requirements, and drawing up the EU Declaration of Conformity is the full self-assessment, and it runs in the same workspace on the Compliance plan. Module A self-assessment is the route for default-class products. For important and critical products the same workspace produces the technical file a notified body assesses.
One journey, from first disclosure to CE marking.
Receive disclosures
A branded disclosure portal on your own subdomain with a published CVD policy and 48-hour acknowledgment tracking. Covers the Article 13(2) handling obligation, free.
File on the clock
When a vulnerability is actively exploited, the 24-hour, 72-hour, and 14-day Article 14 timers start. The SRP-ready filing package is prepared for manual submission, on Reporting.
Classify and assess
Classify each product under Annex III and IV, pick the Article 32 conformity route, and run the cybersecurity risk assessment.
Declare conformity
Close the Annex I gaps, assemble the technical file, and draw up the EU Declaration of Conformity for CE marking.
A working portal you can click through.
Researchers submit through a branded intake form with PGP support. Your team triages disclosures, tracks acknowledgment deadlines, and exports the evidence trail. Every submission is logged from the moment it arrives. Try it on the portal of Aurelia Devices B.V., a fictional manufacturer running on CVD Portal.

Everything the Cyber Resilience Act asks of a manufacturer
One workspace covering all five CRA obligation areas, from product classification and risk assessment through documentation, vulnerability handling, and authority reporting.
Disclosure intake and acknowledgment are free. The self-assessment suite is on the Compliance plan, covering Module A for default-class products and the technical file for products that need a notified body.
Product Classification and Conformity Route
Answer the Annex III and IV questions for each product. The engine determines whether the product is default, important, or critical and which Article 32 conformity assessment route applies.
STRIDE Risk Assessment
A structured threat model per product with likelihood and impact scoring across 33 security objectives, feeding directly into the Annex I requirements work.
Essential Requirements and Gap Analysis
Work through the 22-row Annex I essential requirements checklist. Gap analysis shows what is open and remediation guidance shows how to close it.
Technical File and Declaration of Conformity
Draft artifacts clause by clause with AI assistance across 88 CRA clause artifacts, then generate the EU Declaration of Conformity, the Annex VII documentation index, and the Annex II user information sheet, with CE marking guidance.
Disclosure Portal and Article 14 Reporting
A branded intake portal on your own subdomain with structured submissions, PGP, security.txt, and a full audit trail. Article 14 milestones to ENISA/CSIRT run on fixed deadlines with SRP-ready packages.
Partners, Trust Portal, and Integrations
Assess supply chain partners with CVD scanning, VEX, and SBOM matching. Share conformity documents with approved external viewers through a trust portal, with API access and SAML SSO.
Are You CRA Ready?
Industry context
“Organisations increasingly recognise that software development nowadays requires an active, positive response to vulnerability reports, which strengthens security and is becoming a strong selling point when handled properly.”
EU buyers and market surveillance authorities increasingly expect manufacturers to show a documented CRA position. CVD Portal gives you a structured assessment, the technical file to back it, and a published disclosure process.
CRA Published
Regulation (EU) 2024/2847 enters into force
Article 14 Reporting Begins
Vulnerability notification obligations apply to products in scope
Full Conformity Deadline
Annex I essential requirements, technical documentation, and CE marking apply
Simple, transparent pricing
See full pricing →Receive, track, and acknowledge disclosures
Article 14 authority filing + full CVD compliance
CRA self-assessment through to the EU Declaration of Conformity
Every module at scale, 25 CRA product assessments included, integrations, EUDI identity
The ETSI EN 304 Series: One CRA Standard Per Annex III Product Category
Everyone tracking CRA standardisation is watching the horizontal prEN 40000 series. The other half of standardisation request M/606 is 18 vertical standards, EN 304 617 to EN 304 642, one per Annex III product category, and ETSI has public drafts out for most of them. Here is the full mapping, the categories ETSI is not covering, and why none of it changes your Article 32 route yet.
11 min readCRA ComplianceEvery Worked Example in the Commission's CRA Guidance, and What Changed From the Draft
C(2026) 5252 carries 67 numbered examples and 5 remote data processing use cases. Fourteen of them are new since the consultation draft and one was deleted. Here is what the additions tell you about where the Commission thinks manufacturers are getting it wrong.
9 min readCRA ComplianceThe Commission's CRA Guidance: Reading the Four-Factor Test and the Support Period Rules
C(2026) 5252 gives manufacturers two things they have been working without. A four-factor test for whether a software update is a substantial modification, and a clear statement that five years of support is a floor rather than a default. This walks through both using the Commission's own worked examples.
12 min readSet up your disclosure portal before September 2026
A branded, audit-ready portal for manufacturers selling products with digital elements into the EU. Free to receive and track disclosures. Article 14 filing is on Reporting. Still mapping your obligations? Start with the EU Cyber Resilience Act guide.