ENISA Article 14 report field generator

Already know about an actively-exploited vulnerability affecting something you ship into the EU market? Fill this in once and get the exact fields an ENISA early-warning report needs, plus your 24h / 72h / 14-day deadlines computed from when you became aware. Free, no signup, nothing stored.

If your CVE isn't in CISA's KEV catalog (or you don't have one yet), fill these in so we can still generate your report fields:

Why this exists

EU CRA Article 14 gives you 24 hours from becoming aware of an actively-exploited vulnerability to send ENISA an early-warning report, a follow-up within 72 hours, and a final report within 14 days. Under time pressure, staring at a blank government form costs minutes you don't have. This computes the clock and drafts the fields for you instantly. If you'd rather have this run automatically the moment a new CVE hits one of your dependencies — ExploitWatch checks CISA's KEV catalog daily and alerts you, no manual lookup needed. $19/mo.

Not legal advice. This tool drafts a starting-point field block from what you enter or from CISA's public KEV catalog — it does not determine whether Article 14 applies to you, whether you are legally "aware" under the Regulation, or whether this vulnerability affects your specific deployment. Verify against ENISA's own guidance and your counsel before filing. Nothing you enter here is stored.

← ExploitWatch · Privacy · Terms