Article 14 of the Cyber Resilience Act gives you 24 hours to raise an early warning once you know about an actively exploited vulnerability or severe incident. KONFORMA watches for the trigger and prepares the draft before you even open your inbox.
A first, minimal notification the moment an actively exploited vulnerability or severe incident is confirmed in a product you support.
A more complete report with the details known so far: assessment, impact, and any corrective action already taken.
A closing report after a fix is available, or one month after the incident if a fix takes longer.
KONFORMA detects actively exploited vulnerabilities via CISA’s Known Exploited Vulnerabilities (KEV) catalog. The moment one applies to a component in an active release, a pre-filled draft is prepared with the product, the affected release and the known facts, so you start the clock with a head start, not a blank page.
KONFORMA prepares a pre-filled draft with the facts it knows; you review and submit it. Responsibility for the notification stays with the manufacturer.
Confirmation that a product you support has an actively exploited vulnerability, or a severe incident affecting its security.
No. KONFORMA provides structure and a timely draft. It is not a substitute for your own legal or regulatory judgment.