SME Cyber Resilience Maturity Assessment
Rate your product security practice across 25 questions in 5 domains. Get a maturity score, a RAG breakdown and a tailored CRA improvement checklist. Nothing stored on our servers.
Interactive tools to calculate CVSS scores, generate security.txt, track Article 14 deadlines, and assess your CRA readiness.
Rate your product security practice across 25 questions in 5 domains. Get a maturity score, a RAG breakdown and a tailored CRA improvement checklist. Nothing stored on our servers.
Work out which CRA role you hold for an open-source project. Applies the Article 3(48) test, the monetisation tests from Commission guidance C(2026) 5252, and the graduated Article 24(3) reporting duties. Nothing stored on our servers.
Enter the date and time you became aware of an actively exploited vulnerability or severe security incident. Get your exact Article 14 notification deadlines for ENISA reporting.
A 20-question check of your readiness to handle and report vulnerabilities under CRA Articles 13 and 14. Focused on coordinated disclosure, 48-hour acknowledgment, ENISA reporting and advisories. For a whole-programme view across all five CRA domains, use the CRA Maturity Assessment.
Paste your CSAF 2.0 JSON advisory and instantly validate the structure against the OASIS CSAF 2.0 schema. Identifies missing mandatory fields, invalid values, and flags common issues that would cause rejection by automated consumers and ENISA tooling.
Build a complete, publication-ready CVD policy document using a guided five-step wizard. Configure your response timelines, CRA Article 13 and 14 obligations, and product scope, then export a finished Markdown policy you can publish immediately.
Score a vulnerability with CVSS v4.0. Base, Threat and Environmental metrics are all supported, and the MacroVector equivalence class the score derives from is displayed alongside the vector so the result can be verified against the specification. A vector can be supplied in the URL to share or re-check a score.
Calculate CVSS 3.1 base scores for vulnerability severity assessment. Includes guidance on whether the score triggers Article 14 notification obligations under the EU Cyber Resilience Act.
Enter a vulnerability report date and instantly see every critical deadline: Article 14 early warning, full notification, final report to ENISA, researcher 90-day embargo, and your internal acknowledgment SLA. Colour-coded status keeps you on track.
Build a complete Article 14 early-warning notification based on the fields required by CRA Article 14(2). Fill in your product details, exploitation status, and mitigation actions, then copy the finished notification text ready for submission to ENISA or your national CSIRT.
Paste a list of software components (package@version, one per line) and instantly generate NVD CVE Database search links for each one. Quickly identify which components need vulnerability triage. Supports npm, pip, Maven, Go modules, and free-form package names.
Upload or paste a CycloneDX or SPDX JSON SBOM and check it against BSI TR-03183-2 v2.1.0, the German federal guideline that concretises the CRA SBOM requirement. The validator verifies the minimum specification version (CycloneDX 1.6 or SPDX 3.0.1) and every required data field for the SBOM itself and for each component, including creator, timestamp, dependencies, licences and hashes. Validation runs entirely in your browser.
Generate a standards-compliant security.txt file (RFC 9116) for your product or website. Required by the EU Cyber Resilience Act to make your vulnerability reporting contact discoverable.
CVD Portal integrates all these tools into a complete vulnerability disclosure programme — public submission portal, 48-hour acknowledgment tracking, audit trail, and CSAF advisory generation. Receiving and tracking reports is free. Article 14 filing is on Reporting (the September 2026 requirement).
Set up your free portal