← Product
Product · 03 Incident Readiness

Never miss the CRA’s reporting clock.

Article 14 of the Cyber Resilience Act gives you 24 hours to raise an early warning once you know about an actively exploited vulnerability or severe incident. KONFORMA watches for the trigger and prepares the draft before you even open your inbox.

The reporting timeline

24 hours
Early warning

A first, minimal notification the moment an actively exploited vulnerability or severe incident is confirmed in a product you support.

72 hours
Full notification

A more complete report with the details known so far: assessment, impact, and any corrective action already taken.

14 days
Final report

A closing report after a fix is available, or one month after the incident if a fix takes longer.

How it starts

Detection triggers the draft, automatically.

KONFORMA detects actively exploited vulnerabilities via CISA’s Known Exploited Vulnerabilities (KEV) catalog. The moment one applies to a component in an active release, a pre-filled draft is prepared with the product, the affected release and the known facts, so you start the clock with a head start, not a blank page.

INCIDENT COCKPIT
Gateway X · OpenSSL 3.0.1124h warning due
Sensor HubNo open incidents
Incident #17Closed

Frequently asked

Does KONFORMA submit the report for me?+

KONFORMA prepares a pre-filled draft with the facts it knows; you review and submit it. Responsibility for the notification stays with the manufacturer.

What triggers the 24-hour clock?+

Confirmation that a product you support has an actively exploited vulnerability, or a severe incident affecting its security.

Does this replace legal advice?+

No. KONFORMA provides structure and a timely draft. It is not a substitute for your own legal or regulatory judgment.

Know the moment the clock starts.