ExploitWatch

The moment a CVE affecting a dependency you ship goes onto CISA's Known Exploited Vulnerabilities list, you get an email with the EU CRA Article 14 24-hour clock already started and the ENISA report fields pre-filled.

EU Cyber Resilience Act Article 14 went into force 2026-09-11. Any company selling software (or a connected product) into the EU must now report an actively-exploited vulnerability to ENISA within 24 hours of becoming aware of it, a follow-up within 72 hours, and a final report within 14 days. This applies to products you already shipped, not just new releases. Penalties run up to €15M or 2.5% of global turnover.

Free instant check

Paste your key dependencies, comma-separated. Checks them right now against the live CISA KEV catalog — no account, no card.

Already know you have one to report? Generate your ENISA report fields free — no signup.

$19/mo · cancel anytime · no contract, no sales call, no login required to sign up

Start daily monitoring →

Why this exists

Article 14 is brand new — it took effect yesterday for anyone reading this on launch day — and it applies to a huge base of small SaaS and software vendors who have no compliance team and no existing process for watching a government vulnerability feed. CRA Kit and similar tools sell one-time document generators (policies, ENISA templates); real continuous SBOM-vs-vulnerability monitoring exists but is enterprise DevSecOps tooling built and priced for engineering teams running CI/CD pipelines, not a solo founder. Nobody sells "tell me the moment one of my listed dependencies is being actively exploited" cheaply and instantly, self-serve. Read the full plain-language Article 14 explainer if you're still figuring out whether this applies to you.

How it works

Who this is for

Solo founders and small software vendors with EU customers who now have a real, unfamiliar legal obligation and no compliance team to hand it to.

This is not legal advice. ExploitWatch is a monitoring aid that flags CISA KEV catalog matches against dependencies you tell us about — it does not determine whether Article 14 applies to your product, whether you are legally "aware" under the Regulation, or whether a given CVE's exploitation affects your specific deployment. You are solely responsible for evaluating any alert and for actually filing with ENISA and/or your national CSIRT if your obligations require it. We make no guarantee of catching every relevant vulnerability. Consult qualified legal counsel for your specific situation.

Privacy · Terms

Other tools from the same builder: KDPCheck (KDP AI-disclosure checker) · Edge Thirteen (value-investing newsletter) · StripeCheckup (Stripe integration audit) · TriageShield (AI-slop vuln-report checker) · BrewClear (TTB label clearance) · MarkRadar (trademark + domain-squat alerts) · FilingCheck (SEC-grounded stock reports) · AuditFlag (SEC going-concern alerts) · RenewalMatrix (click-to-cancel compliance) · SlopCheck (YouTube demonetization-risk checker) · VercelPyCheck (Vercel Python deploy bug scanner)