EU CRA ARTICLE 14 — REPORTING BEGINS 11 SEPTEMBER 2026

The reporting obligation is coming.
You do not have to face it alone.

From building the process inside your company to supporting the 24-hour reporting system — one route.
Nothing in place yet? That is exactly where we start.

One routeBuild the process, then run it24h · 72h · 14d/1moRegulatory deadlines tracked for youExperts alongsideACE LABS stays with you to the end
Inside the deadline
From the moment you become aware, through preparation, to submission
Reporting wizard
Guides every required field and carries it through internal approval
Evidence and audit trail
Every decision, hand-off and submission on the record
11 SEPTEMBER 2026

The date is fixed.
The time to prepare is not.

From that day, any manufacturer selling digital products in the EU must report an actively exploited vulnerability or a severe incident within 24 hours of becoming aware of it. The clock runs whether you find out at nine in the morning or three in the morning. There are dozens of fields to complete, the submission is in English, and someone inside your company has to be authorised to approve it.

24hEarly warning
72hNotification
FinalVulnerability: 14 days after a fix is available · Incident: 1 month after notification
How it works

One flow, instead of a scramble.

1

We build the process inside your company

We design the reporting roles around your organisation and produce the internal documents the regulation asks for. Review and approval pass to the next person automatically.

2

We keep the 24-hour clock

The moment a case is filed, the deadlines are calculated and watched, and every required field is guided step by step. Once internal approval is done, we walk you through the ENISA submission.

3

We turn everything into evidence

Decisions, reviews, approvals and submissions are sealed into a record that cannot be altered — an asset that helps demonstrate to a regulator that you followed the procedure.

PRODUCT PREVIEW

See it in action

From triage to the 24-hour deadline to the audit record — these are the actual screens.

Why CRAdle

Not a tool. A partner.

Experts, not just softwareA pure tool hands you a screen. Behind CRAdle are ACE LABS consultants who have taken manufacturers through CRA, automotive and OT regulation.
We see only what you allowUnless you switch access on, ACE LABS does not access your data — backed by our access-control design, not just a policy.
Built for Korean manufacturersKorean guidance alongside the ENISA source text, and an approval chain that fits how Korean companies actually sign off.
First time is fineNo process, no experience — we stay with you from the first workshop to the first report filed.

You do not have to face it alone.

Tell us where you stand and we will map out what you need — free of charge.

Service brochure