Article 14 reporting runbook
Who opens the process, what gets attached in the first 24 hours, what changes by 72 hours, and where final-report evidence comes from.
For software and connected-product manufacturers selling into the EU
Answer product-security questions, attest every fact, and get a Cyber Resilience Act Article 14 reporting runbook, notification drafts, evidence register, vulnerability-intake policy, and tabletop drill — built only from answers you confirm. Flat $3,999, one time. Not legal advice, not certification, not a conformity assessment.
Once an actively exploited vulnerability or severe incident is known, CRA Article 14 sets a fixed cadence. VulnBrief turns that cadence into a named owner and a prepared evidence step for each stage.
Notify your CSIRT within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident.
A fuller report within 72 hours — severity, affected versions, and the corrective measures taken or planned.
No later than 14 days after a corrective measure is available for an actively exploited vulnerability.
Severe security incidents get their final report within one month, with the same evidence trail.
Cadence per the official CRA reporting-obligations page. VulnBrief prepares the process; it does not file reports for you.
Five Markdown documents plus a JSON bundle, delivered to a private order page and your inbox. Every artifact is grounded in the facts you attest — missing practices become a clearly-labelled gap register, never a claim.
Who opens the process, what gets attached in the first 24 hours, what changes by 72 hours, and where final-report evidence comes from.
Early-warning, full-notification, and final-report templates that keep unknown facts as unknown instead of inventing legal conclusions.
A product-specific map of SBOMs, scanner alerts, tickets, versions, releases, advisories, and submission records — including what is missing.
How reports arrive, who triages, how severity is decided, and where the work is tracked — grounded in the channels and tools you actually use.
A rehearsal for one actively exploited vulnerability and one severe incident, so the runbook is tested by people, not just written down.
Scope one product, your vulnerability channels, SBOM status, evidence locations, release process, and reporting owners. Mark anything not in place as “not yet.”
Before checkout you see the exact statements the documents will be built from — nothing else. Edit anything that isn’t true today.
The pack generates right after checkout, typically in minutes. Run the tabletop drill with engineering and turn the gap register into tickets.
VulnBrief produces manufacturer-attested operational documentation. It does not file reports, provide legal advice, certify CRA compliance, perform a conformity assessment, or guarantee regulator acceptance. That restraint is part of the product: the pack is useful because it says what is known, what is unknown, and who owns the next action. No scoping call, no retainer — answer the questions, attest the facts, get the pack.
Generated for Northwind Ledger — a fictional B2B SaaS manufacturer preparing for CRA Article 14 reporting. This is representative output from the same artifact shape your order uses.
Based on answers provided by Northwind Ledger on 2026-06-20. Self-attested by the manufacturer; not audited, certified, a conformity assessment, or legal advice.
This runbook covers Northwind Ledger Cloud, a B2B SaaS web application available to customers in Germany and the Netherlands. It is not legal advice and does not certify CRA compliance. It is an operational draft for handling actively exploited vulnerabilities and severe security incidents.
Open a Jira Security ticket labeled cra-review. The product security lead starts triage, records the awareness timestamp, affected version range, exploitation signal, customer impact, and evidence locations. If reporting is required, prepare the 24-hour early-warning draft without waiting for full root cause analysis.