24-hour early warning, 72-hour notification, final report. Through the Single Reporting Platform.
CRA reporting obligations are now in force.
Most of the proof the CRA asks for is already in your repository - the lockfile, the CI job, the SECURITY.md, the release notes. ConformOps collects it, tells you what is missing, and keeps the file current as you ship.
Essential requirements, technical documentation, conformity route, CE marking, support period.
Four deadlines, not two.
The 24-hour and 72-hour submissions are only the start. Article 14 keeps running until a final report closes the case - and the clock that matters most starts when your fix is ready, not when the incident began.
Early warning
Once you become aware of an actively exploited vulnerability or a severe incident affecting your product’s security, an early warning goes into the EU Single Reporting Platform operated by ENISA.
Notification
A second submission updates the picture: whether exploitation is malicious and ongoing, which Member States are likely affected, and an initial assessment of severity and impacts.
Final report · vulnerability
For an actively exploited vulnerability, the final report is due no later than 14 days after you make corrective or mitigating measures available to affected customers - or, where none are needed, after concluding the 72-hour notification.
Final report · severe incident
For a severe incident, the final report follows within one month of the notification. Exceptional circumstances can justify more time, but the reasons must be ready when the coordinating CSIRT asks.
- Product name, type, and every version affected
- Manufacturer details and the name and role of each person authorised to submit
- The vulnerability or incident itself: how it was discovered and whether it is being exploited
- Which Member States’ products are affected
- An initial severity and impact assessment
- Corrective or mitigating measures, and when they reach customers
ENISA forwards submissions to the designated CSIRTs, who coordinate the case and can request additional information.
Which of these is you today?
Pick one. We will show you the shortest honest path from there - including the parts we cannot do for you.
Get a baseline in an afternoon
Create the product, answer six questions, drop in your manifests, CI files and any security docs. You get a readiness picture and the three gaps that matter most.
Fix the cheap gaps first
Most first assessments are missing a stated support period, a reporting escalation path, and a release-bound SBOM. Each is writing, not engineering.
Name who is accountable
One person for the manufacturer record, one for evidence, one group for reporting decisions. We record the decision; we cannot make it.
A file a reviewer can follow, line by line.
Not a score out of a hundred. A register of requirements, each one either evidenced by something in your source, or listed as a gap with the work it needs.
- evidencedSecure default configurationsrc/Aurora/appsettings.json L4–L28
Annex I I(2)(a) - evidencedVulnerability intake and disclosureSECURITY.md L8–L24
Annex I II(5) - partialComponent identification and SBOMpackages.lock.json · top level only
Annex I II(1) - gapReporting escalation within 24h / 72hno source evidence located
Art. 14(1) - needs reviewSecurity update distributionrelease.yml L52–L60 · proposed
Annex I II(8)
Then the documents
Annex V declaration draft, Annex II information, an Annex VII-oriented technical record, SBOM, traceability CSVs, and a workbook for people who do not read JSON.
Then the clock
If something is actively exploited, the 24h / 72h / final-report deadlines run inside the product, against a real case record.
Then it stays true
Ship a release and it re-runs, shows the delta, and invalidates only the conclusions your change actually affected.
We will not pretend to be your lawyer.
ConformOps prepares and maintains evidence. It does not give legal advice, decide your final classification, act as a notified body, issue a declaration, or affix CE marking. Those stay with a named human - and the product shows you which ones are still open.
Buy the file once, or keep it true.
I need the file once
One product, one complete assessment, the whole package downloaded, 14 days to remediate and re-verify. Free preview first if you want to look before paying.
I still ship this product
Continuous: every future release, daily dependency monitoring, assessment history and deltas, refreshed artifacts. €790/year, and a €99 assessment credits toward the first annual term.