SERVICE INTRODUCTION
CRAdle
Service Brochure
PSIRT-as-a-Service for EU CRA reporting — from building the process inside your company to supporting the 24-hour reporting system, with ACE LABS experts alongside.
2026 · ACE LABS Inc. · cradle.acelabs.co.kr
NAME
CRAdle — what the name carries
CRAdle joins CRA (the EU Cyber Resilience Act) with cradle.
A cradle holds what cannot yet stand on its own. The CRA has placed an unfamiliar and heavy obligation on manufacturers, and no company was ready for it from day one.
CRAdle is a promise: to hold a manufacturer's CRA response from the very beginning, and to grow with it until it can stand alone.
The regulation sits inside the name on purpose — so that what this service is for is clear before you read a word of it.
WHY NOW
Why now
On 11 September 2026, the reporting obligation under EU CRA Article 14 takes effect. From that day, any manufacturer selling digital products in the EU must:
24 hoursEarly warning, after becoming aware of an actively exploited vulnerability or a severe incident
72 hoursSubmit the detailed notification
Final report14 days after a fix is available (vulnerability) · 1 month after notification (incident)
The clock runs whether you find out at nine in the morning or three in the morning. There are dozens of fields, the destination (the ENISA SRP portal) is in English, and if nobody inside the company is authorised to review and approve, 24 hours disappear fast. This is hard to prepare for alone — which is why CRAdle exists.
WHAT WE DO
What CRAdle does — three pillars
1We build the process inside your company
- A reporting structure shaped to your organisation: who writes, who reviews, who approves. We bring the template and fit it to you.
- Internal documentation: the reporting procedure, policies and the other internal documents the regulation expects — drafted from ACE LABS' regulatory work and handed to you.
- The system then runs what you agreed: when it is someone's turn to review, they are told; when they are done, the next person is. An approval never quietly falls asleep.
Reporting workflow (R&R)
Reporting procedure (CRA incidents & vulnerabilities)
A company-specific document reflecting your R&R and logo
Download (Korean)Download (English)
2Decide whether it is reportable, then keep the 24-hour clock
- Before filing, a short questionnaire helps you decide whether it is reportable — when it is unclear, it guides you to report conservatively.
- From the moment a case is filed, the 24h, 72h and final deadlines are calculated and watched, and you are warned as each one closes in.
- A reporting wizard walks through every mandatory field step by step, in Korean, with the English submission text beside it. Fill in what is required and the early warning is complete.
- Once internal approval is done, the screen guides you through the ENISA submission — you make the final click, CRAdle does the preparation.
Question 2 · up to 8
Does this incident affect our product's security?
Affects the product's security
An internal IT incident, unrelated to the product
Back 3We turn everything into evidence
- Every decision, review, approval and submission accumulates in a sealed audit trail that cannot be rewritten — an asset that helps demonstrate to a regulator that you followed the procedure.
- The deadline alerts and the guidance we gave are recorded too, which supports the factual record of what was done and when, should responsibility ever be discussed.
Timeline — who, when, what
12:48The system created the case.
12:48Kim (Reporter) recorded the time of awareness — starting the "early warning" report, due within 24h.
12:52Park (Reviewer) completed the internal review.
DIFFERENCE
What makes this different
- Built for Korean manufacturers. Korean guidance with the ENISA source text beside it, and an approval chain that fits how Korean companies sign off.
- Designed for people doing this for the first time. No process, no prior experience — we go from the first workshop to the first report filed, together.
- We see only what you allow — backed by our access-control design, not just a policy. Unless you switch access on, ACE LABS does not access your data; only the system keeps monitoring. The switch is yours alone. We treat vulnerability information as the most sensitive asset a manufacturer holds.
MODEL
The service model
- The legal duty to report rests with the manufacturer, and the final click at ENISA is yours. CRAdle provides everything up to that moment — the structure, the drafting guidance, the deadline management, the evidence — and walks you through the submission.
- ACE LABS is an independent advisory firm, not a certification body. We issue no certificates; we support and advise.
- Extended support through an EU authorised representative is available; please ask us.
ROADMAP
Roadmap — the cradle grows
SRP reporting · Live→Continuous vulnerability monitoring→SBOM and VEX management→Tracking standards as they change
NextThe foundation for everything — CRA evidence management
One goal: a service a manufacturer can hand its entire product-security response to.